From 835b2982126abd29a5c160bbdf547545f2cb5a86 Mon Sep 17 00:00:00 2001 From: mptyl Date: Tue, 18 Aug 2026 13:26:34 +0200 Subject: [PATCH] fix(safeio): retain attribute inspection on private create --- tools/tht/internal/safeio/private_root_windows.go | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/tools/tht/internal/safeio/private_root_windows.go b/tools/tht/internal/safeio/private_root_windows.go index 0a6f11e6..c5ffabf1 100644 --- a/tools/tht/internal/safeio/private_root_windows.go +++ b/tools/tht/internal/safeio/private_root_windows.go @@ -461,6 +461,11 @@ func createWindowsPrivateRegularAtWithAccess(parent windows.Handle, name string, return nil, ErrUnsafeFile } defer security.Close() + // The caller's data authority is intentionally preserved (GENERIC_WRITE is used for + // streaming creates), but privateWindowsRegularInfo must inspect attributes and links + // before returning the handle. FILE_READ_ATTRIBUTES grants that inspection without + // adding read-data authority to a write-only create. + access |= windows.FILE_READ_ATTRIBUTES handle, err := openWindowsRelativeObject( parent, name,