Repository navigation
Conversation
The "Security options" page is only shown when Mandatory ASLR is enabled system-wide, i.e. exactly when Git Bash, SSH and the other MSYS2 programs cannot fork without the exceptions. Yet its checkbox defaults to unchecked, so silent installs (e.g. `winget install Git.Git`) on such systems leave a Git Bash that fails with fork: child -1 - forked process ... died unexpectedly, retry 0, exit code 0xC0000142 Check it by default instead. An explicit choice, recorded or passed via `/o:AddmandatoryASLRsecurityexceptions=Disabled`, is still honored. Signed-off-by: Ali Robertson <[email protected]> Co-Authored-By: Claude Opus 5.5 <[email protected]>
Mandatory ASRR is designed to increase security of a system. Exceptions should not be made automatically. They have to be a conscious choice. So I don't think that merging this PR would be a good idea. |
|
Fair enough. Please leave this open and I'll see if I can come up with a better compromise in the next day. |
|
Closing in favour of a diagnostic in the runtime: msys2/msys2-runtime#380 makes fork() print one line naming Mandatory ASLR and the affected executable when it is the cause, so silent installs on such systems fail with an actionable message rather than a bare 0xC0000142. I am also chasing up whether this bug even needs to exist in msys2, when it doesn't appear to exist upstream in cygwin. Would be better to get rid of this entirely, and we can remove the whole workaround from this project. Update: they're checking if it is needed here msys2/msys2-runtime#381 |
On systems with Mandatory ASLR enabled, the installer offers the ASLR exceptions (#513), but the checkbox defaults to unchecked. Silent installs (
winget install Git.Git) therefore produce a Git Bash that cannot fork (0xC0000142).The page is only created when Mandatory ASLR is detected, so defaulting it to checked only affects exactly those systems. An explicit choice (recorded, or
/o:AddmandatoryASLRsecurityexceptions=Disabled) still wins.Related: git-for-windows/git#1412, git-for-windows/git#6349