fix(auth): remove Windows claims by retained handle
This commit is contained in:
@@ -123,41 +123,24 @@ func readCanonicalPrivateClaim(source, claim string, maximum int64) ([]byte, boo
|
||||
return contents, true, nil
|
||||
}
|
||||
|
||||
func removeCanonicalPrivateClaim(source, claim string) (bool, error) {
|
||||
sourceFile, err := openWindowsPrivateRegular(source, 2)
|
||||
if err != nil {
|
||||
if isWindowsNotFound(err) && windowsPrivateClaimAbsentOrOrphan(claim) {
|
||||
return false, nil
|
||||
func removeCanonicalPrivateClaim(source, claim string) (removed bool, resultErr error) {
|
||||
parentPath := filepath.Dir(source)
|
||||
sourceName := filepath.Base(source)
|
||||
claimName := filepath.Base(claim)
|
||||
if parentPath != filepath.Dir(claim) || !validPrivateLeafName(sourceName) || !validPrivateLeafName(claimName) {
|
||||
return false, ErrUnsafeFile
|
||||
}
|
||||
directory, found, err := OpenPrivateDirectory(parentPath, false)
|
||||
if err != nil || !found {
|
||||
return false, ErrUnsafeFile
|
||||
}
|
||||
defer func() {
|
||||
if closeErr := directory.Close(); closeErr != nil && resultErr == nil {
|
||||
resultErr = ErrUnsafeFile
|
||||
}
|
||||
return false, ErrUnsafeFile
|
||||
}
|
||||
claimFile, err := openWindowsPrivateRegular(claim, 2)
|
||||
if err != nil {
|
||||
sourceFile.Close()
|
||||
if isWindowsNotFound(err) {
|
||||
return false, nil
|
||||
}
|
||||
return false, ErrUnsafeFile
|
||||
}
|
||||
if !sameWindowsPrivateFile(sourceFile.info, claimFile.info) {
|
||||
sourceFile.Close()
|
||||
claimFile.Close()
|
||||
return false, ErrUnsafeFile
|
||||
}
|
||||
sourceFile.Close()
|
||||
claimFile.Close()
|
||||
if err := windows.DeleteFile(windows.StringToUTF16Ptr(source)); err != nil {
|
||||
return false, ErrUnsafeFile
|
||||
}
|
||||
remaining, err := openWindowsPrivateRegular(claim, 1)
|
||||
if err != nil {
|
||||
return false, ErrUnsafeFile
|
||||
}
|
||||
remaining.Close()
|
||||
if err := windows.DeleteFile(windows.StringToUTF16Ptr(claim)); err != nil {
|
||||
return false, ErrUnsafeFile
|
||||
}
|
||||
return true, nil
|
||||
}()
|
||||
NotifyPrivateDirectoryTestHookForTest("after-canonical-private-claim-parent-open")
|
||||
return directory.RemoveClaim(sourceName, claimName)
|
||||
}
|
||||
|
||||
func openWindowsPrivateRegularWithAllowedLinks(path string, allowed ...uint32) (*windowsPrivateRegular, error) {
|
||||
|
||||
Reference in New Issue
Block a user