fix(backup): privately stage restore archive

This commit is contained in:
2026-08-18 08:13:13 +02:00
parent df00f6bfa8
commit 54698e7340
8 changed files with 178 additions and 23 deletions
+8 -4
View File
@@ -96,14 +96,18 @@ func ProtectPrivateRegular(path string) error {
// createCanonicalNewPrivateFile installs the owner-only protected DACL in the CreateFile call, so
// another mutation can never observe a newly-created lock with an inherited/default DACL.
func createCanonicalNewPrivateFile(path string, mode os.FileMode) (*os.File, error) {
return createCanonicalNewFile(path, mode, false)
return createCanonicalNewFile(path, mode, false, windows.GENERIC_WRITE)
}
func createCanonicalNewPrivateParentFile(path string, mode os.FileMode) (*os.File, error) {
return createCanonicalNewFile(path, mode, true)
return createCanonicalNewFile(path, mode, true, windows.GENERIC_WRITE)
}
func createCanonicalNewFile(path string, mode os.FileMode, requirePrivateParent bool) (*os.File, error) {
func createCanonicalNewPrivateParentReadWriteFile(path string, mode os.FileMode) (*os.File, error) {
return createCanonicalNewFile(path, mode, true, windows.GENERIC_READ|windows.GENERIC_WRITE)
}
func createCanonicalNewFile(path string, mode os.FileMode, requirePrivateParent bool, access uint32) (*os.File, error) {
parents, target, err := openCanonicalWindowsParent(path)
if err != nil || len(parents.handles) == 0 || (requirePrivateParent && validateOwnerOnlyDACL(parents.handles[len(parents.handles)-1]) != nil) {
if parents != nil {
@@ -123,7 +127,7 @@ func createCanonicalNewFile(path string, mode os.FileMode, requirePrivateParent
}
handle, err := windows.CreateFile(
windows.StringToUTF16Ptr(filepath.Join(parents.directory, target)),
windows.GENERIC_WRITE,
access,
windowsRetainedHandleShareMode,
attributes,
windows.CREATE_NEW,