fix(auth): remove Windows claims by retained handle

This commit is contained in:
2026-08-18 11:04:21 +02:00
parent 5f9a3ae066
commit 0d8e707533
2 changed files with 154 additions and 34 deletions
+17 -34
View File
@@ -123,41 +123,24 @@ func readCanonicalPrivateClaim(source, claim string, maximum int64) ([]byte, boo
return contents, true, nil
}
func removeCanonicalPrivateClaim(source, claim string) (bool, error) {
sourceFile, err := openWindowsPrivateRegular(source, 2)
if err != nil {
if isWindowsNotFound(err) && windowsPrivateClaimAbsentOrOrphan(claim) {
return false, nil
func removeCanonicalPrivateClaim(source, claim string) (removed bool, resultErr error) {
parentPath := filepath.Dir(source)
sourceName := filepath.Base(source)
claimName := filepath.Base(claim)
if parentPath != filepath.Dir(claim) || !validPrivateLeafName(sourceName) || !validPrivateLeafName(claimName) {
return false, ErrUnsafeFile
}
directory, found, err := OpenPrivateDirectory(parentPath, false)
if err != nil || !found {
return false, ErrUnsafeFile
}
defer func() {
if closeErr := directory.Close(); closeErr != nil && resultErr == nil {
resultErr = ErrUnsafeFile
}
return false, ErrUnsafeFile
}
claimFile, err := openWindowsPrivateRegular(claim, 2)
if err != nil {
sourceFile.Close()
if isWindowsNotFound(err) {
return false, nil
}
return false, ErrUnsafeFile
}
if !sameWindowsPrivateFile(sourceFile.info, claimFile.info) {
sourceFile.Close()
claimFile.Close()
return false, ErrUnsafeFile
}
sourceFile.Close()
claimFile.Close()
if err := windows.DeleteFile(windows.StringToUTF16Ptr(source)); err != nil {
return false, ErrUnsafeFile
}
remaining, err := openWindowsPrivateRegular(claim, 1)
if err != nil {
return false, ErrUnsafeFile
}
remaining.Close()
if err := windows.DeleteFile(windows.StringToUTF16Ptr(claim)); err != nil {
return false, ErrUnsafeFile
}
return true, nil
}()
NotifyPrivateDirectoryTestHookForTest("after-canonical-private-claim-parent-open")
return directory.RemoveClaim(sourceName, claimName)
}
func openWindowsPrivateRegularWithAllowedLinks(path string, allowed ...uint32) (*windowsPrivateRegular, error) {