intellicrack.core.elevation

Windows UAC self-elevation for Intellicrack.

Detects whether the current process holds an elevated (administrative) token and, when it does not, relaunches the application through the Windows runas verb so the user is presented with a User Account Control (UAC) prompt.

Elevation is what allows SeDebugPrivilege to be enabled on the process token (see intellicrack.bridges.process), which in turn grants the process bridge full access to protected, elevated, and cross-user target processes. Without it those operations fail with access- denied even though the rest of the application runs normally.

The relaunch is guarded against prompt loops: the elevated child is started with the internal ELEVATED_FLAG argument, and a child that is still not elevated (for example because the user dismissed the UAC dialog) continues unprivileged instead of prompting again.

is_windows()[source]

Return whether the current platform is Windows.

Returns:

True on Windows, False on every other platform.

Return type:

bool

is_elevated()[source]

Return whether the current process token is elevated.

Uses shell32.IsUserAnAdmin to test for membership in the local Administrators group on the process token, which is only present when the process is running with an elevated token.

Returns:

True when the process holds an elevated token; False on non-Windows platforms or on any Win32 error.

Return type:

bool

maybe_elevate(*, disabled, already_attempted, original_args, working_dir, relauncher=<function _relaunch_elevated>)[source]

Relaunch the application elevated when required and possible.

Decision order:

  • Non-Windows platforms never elevate.

  • --no-elevate disables elevation entirely.

  • A child started with ELEVATED_FLAG never re-prompts; if it is still unprivileged the user declined the prompt and the app continues with limited rights.

  • An already-elevated process needs nothing further.

  • Otherwise a UAC relaunch is attempted via relauncher.

Parameters:
  • disabled (bool) – True when elevation was disabled via --no-elevate.

  • already_attempted (bool) – True when this process was started with ELEVATED_FLAG by a prior relaunch.

  • original_args (list[str]) – Original command-line arguments to forward when relaunching.

  • working_dir (str) – Working directory to assign to the elevated process.

  • relauncher (Callable[[list[str], str], bool]) – Callable that performs the actual UAC relaunch; defaults to _relaunch_elevated(). Inject a recording callable in tests to verify decision logic without spawning a real elevated process.

Returns:

True when an elevated instance was started and the current process should exit immediately; False when the current process should continue running as-is.

Return type:

bool