Fix help resolution and Win32 ownership soundness - #15
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
taskmgr.hlp/WinHelpWlookup with a fixed HTTPS project documentation target, explicit Shell/COM failure handling, and localized user feedbackfrom_rawboundaries and RAII owners for handles, WTS memory, icons, interface tables, and copied SIDsWM_NOTIFY, callback-buffer, crash, and secure-directory parsing contracts explicit, validated, and narrowly scopedunsafefrom ordinary process/network operations and keep FFI inside local unsafe blocksRoot causes addressed
Issue #13 was caused by delegating a bare filename from an elevated UI to legacy WinHelp search behavior. The help target is now application-owned, deterministic, HTTPS-only, and independent of PATH or legacy file lookup.
Issue #14 was caused by safe APIs claiming ownership of arbitrary raw values or dereferencing caller-provided raw pointers, while unrelated operations were marked unsafe merely because their implementations used FFI. Raw ownership and pointer/message contracts are now represented by types where possible and by documented unsafe boundaries otherwise.
Validation
GitHub Actions CI run #7 passed on all supported architectures:
TextKeyvariantsFixes #13
Fixes #14