fix(safeio): retain writable Windows parent handles

This commit is contained in:
2026-08-18 09:05:42 +02:00
parent e7a7f4f066
commit 74b062f1a7
3 changed files with 41 additions and 25 deletions
@@ -48,26 +48,22 @@ func openPrivateDirectory(path string, ensure bool) (PrivateDirectoryHandle, boo
// The final root is absent. The retained canonical parent must prove that the same
// ensure operation could create it; validation itself must remain side-effect free.
// FILE_APPEND_DATA is the Win32 spelling of directory FILE_ADD_SUBDIRECTORY.
probe, probeErr := openWindowsComponentWithAccess(anchors.directory, true, windows.FILE_APPEND_DATA)
if probeErr != nil {
anchors.Close()
anchors.Close()
writableAnchors, writableTarget, probeErr := openCanonicalWindowsParentWithFinalAccess(path, windows.FILE_APPEND_DATA)
if probeErr != nil || writableAnchors == nil || len(writableAnchors.handles) == 0 {
if writableAnchors != nil {
writableAnchors.Close()
}
return nil, false, ErrUnsafeFile
}
_ = windows.CloseHandle(probe)
if !ensure {
anchors.Close()
writableAnchors.Close()
return nil, false, nil
}
// The canonical parent chain remains pinned by anchors; this extra handle supplies
// FILE_ADD_SUBDIRECTORY for the one initial root creation without reopening a child
// beneath the private root lexically.
writableParent, writableErr := openWindowsComponentWithAccess(anchors.directory, true, windows.FILE_APPEND_DATA)
if writableErr != nil {
anchors.Close()
return nil, false, ErrUnsafeFile
}
handle, found, err = openWindowsPrivateDirectoryAt(writableParent, target, true)
_ = windows.CloseHandle(writableParent)
anchors = writableAnchors
target = writableTarget
parent = anchors.handles[len(anchors.handles)-1]
handle, found, err = openWindowsPrivateDirectoryAt(parent, target, true)
if err != nil || !found {
anchors.Close()
return nil, false, ErrUnsafeFile