fix(windows): complete concurrent auth consumption

This commit is contained in:
2026-08-18 14:30:33 +02:00
parent 455fffb299
commit 2d1670e390
2 changed files with 80 additions and 9 deletions
@@ -955,14 +955,14 @@ func windowsRelativeClaimAbsentOrOrphan(directory *windowsPrivateDirectory, sour
const windowsClaimSharingRetries = 100
func openWindowsPrivateClaimSource(directory windows.Handle, source string) (*windowsPrivateRegularAt, error) {
func openWindowsPrivateClaimRegular(
directory windows.Handle,
name string,
access uint32,
allowedLinks uint32,
) (*windowsPrivateRegularAt, error) {
for attempt := 0; ; attempt++ {
value, err := openWindowsPrivateRegularAt(
directory,
source,
windows.FILE_GENERIC_READ|windows.FILE_GENERIC_WRITE|windows.DELETE,
1,
)
value, err := openWindowsPrivateRegularAt(directory, name, access, allowedLinks)
if !errors.Is(err, windows.ERROR_SHARING_VIOLATION) &&
!errors.Is(err, windows.STATUS_SHARING_VIOLATION) {
return value, err
@@ -981,7 +981,12 @@ func (directory *windowsPrivateDirectory) ClaimRegular(source, claim string) (bo
// A concurrent winner temporarily holds the source with DELETE access and deliberately
// without FILE_SHARE_DELETE. Wait only for that specific, bounded contention before
// observing the resulting pair or absence below. Persistent sharing remains unsafe.
value, err := openWindowsPrivateClaimSource(directory.handle, source)
value, err := openWindowsPrivateClaimRegular(
directory.handle,
source,
windows.FILE_GENERIC_READ|windows.FILE_GENERIC_WRITE|windows.DELETE,
1,
)
if err != nil {
pair, pairErr := windowsRelativeClaimPairExists(directory, source, claim)
if pairErr == nil && pair {
@@ -1058,7 +1063,14 @@ func (directory *windowsPrivateDirectory) RemoveClaim(source, claim string) (boo
if directory.Validate() != nil || !validPrivateLeafName(source) || !validPrivateLeafName(claim) {
return false, ErrUnsafeFile
}
value, err := openWindowsPrivateRegularAt(directory.handle, source, windows.FILE_GENERIC_READ|windows.DELETE, 2)
// A losing claimer can still be closing its no-delete source handle after observing the
// existing hard-link pair. Treat only that bounded sharing window as contention.
value, err := openWindowsPrivateClaimRegular(
directory.handle,
source,
windows.FILE_GENERIC_READ|windows.DELETE,
2,
)
if err != nil {
orphan, orphanErr := windowsRelativeClaimAbsentOrOrphan(directory, source, claim)
if orphanErr == nil && orphan {