mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 19:18:25 +00:00
The service still reads peers.allow and peers.deny from \etc\fips on the system drive when they are missing from C:\ProgramData\fips, and any local user can create files there, so a planted list was enforced. install-service.ps1 now creates both files in C:\ProgramData\fips, empty, which allows every peer, so the service no longer falls back to the old location. It stops when either file exists under \etc\fips and is missing from C:\ProgramData\fips, which is exactly when the service would enforce the old file, so an upgrader's list is neither enforced nor dropped without an administrator reviewing it. The check runs after the directory is restricted and before the binaries are copied or the service is registered, and every refusal is decided before any file is created; an existing file is never truncated. The zip README says the installer creates the files, that a list is cleared by emptying its file rather than deleting it, and what to do when the installer stops on an old file. A structural test pins the conditions and their order in the script.