diff --git a/tools/tht/internal/safeio/private_windows.go b/tools/tht/internal/safeio/private_windows.go index dad9f809..ee614da7 100644 --- a/tools/tht/internal/safeio/private_windows.go +++ b/tools/tht/internal/safeio/private_windows.go @@ -329,10 +329,11 @@ func validateOwnerOnlyDACL(handle windows.Handle) error { func isOwnerOnlyFullControlMask(mask uint32) bool { // Windows may persist GENERIC_ALL in the ACE or expand it to the file-object - // full-control mask (including FILE_DELETE_CHILD). Both are the same semantic - // authority; any additional bit remains unsafe. - const fileDeleteChild = uint32(0x40) - effective := uint32(windows.FILE_GENERIC_READ|windows.FILE_GENERIC_WRITE|windows.FILE_GENERIC_EXECUTE|windows.DELETE) | fileDeleteChild + // full-control mask. FILE_ALL_ACCESS is the standard-rights set, synchronize, + // and all file-specific rights. Both are the same semantic authority; any + // additional or missing bit remains unsafe. + const fileSpecificAll = uint32(0x1ff) + effective := uint32(windows.STANDARD_RIGHTS_REQUIRED|windows.SYNCHRONIZE) | fileSpecificAll return mask == uint32(windows.GENERIC_ALL) || mask == effective } diff --git a/tools/tht/internal/safeio/private_windows_test.go b/tools/tht/internal/safeio/private_windows_test.go index a208fd42..6d45525f 100644 --- a/tools/tht/internal/safeio/private_windows_test.go +++ b/tools/tht/internal/safeio/private_windows_test.go @@ -55,8 +55,8 @@ func TestPrivateWindowsDACLRejectsPermissiveDirectoryAndRegularFile(t *testing.T } func TestOwnerOnlyDACLAcceptsWindowsFullControlMask(t *testing.T) { - const fileDeleteChild = uint32(0x40) - effectiveFullControl := uint32(windows.FILE_GENERIC_READ|windows.FILE_GENERIC_WRITE|windows.FILE_GENERIC_EXECUTE|windows.DELETE) | fileDeleteChild + const fileSpecificAll = uint32(0x1ff) + effectiveFullControl := uint32(windows.STANDARD_RIGHTS_REQUIRED|windows.SYNCHRONIZE) | fileSpecificAll if !isOwnerOnlyFullControlMask(effectiveFullControl) { t.Fatalf("effective Windows full-control mask %#x was rejected", effectiveFullControl) }