From a0e05ad392f188f6cacc226f0885ae2e117173fa Mon Sep 17 00:00:00 2001 From: mptyl Date: Tue, 18 Aug 2026 12:52:37 +0200 Subject: [PATCH] fix(safeio): accept Windows effective full-control ACL --- tools/tht/internal/safeio/private_windows.go | 9 +++++---- tools/tht/internal/safeio/private_windows_test.go | 4 ++-- 2 files changed, 7 insertions(+), 6 deletions(-) diff --git a/tools/tht/internal/safeio/private_windows.go b/tools/tht/internal/safeio/private_windows.go index dad9f809..ee614da7 100644 --- a/tools/tht/internal/safeio/private_windows.go +++ b/tools/tht/internal/safeio/private_windows.go @@ -329,10 +329,11 @@ func validateOwnerOnlyDACL(handle windows.Handle) error { func isOwnerOnlyFullControlMask(mask uint32) bool { // Windows may persist GENERIC_ALL in the ACE or expand it to the file-object - // full-control mask (including FILE_DELETE_CHILD). Both are the same semantic - // authority; any additional bit remains unsafe. - const fileDeleteChild = uint32(0x40) - effective := uint32(windows.FILE_GENERIC_READ|windows.FILE_GENERIC_WRITE|windows.FILE_GENERIC_EXECUTE|windows.DELETE) | fileDeleteChild + // full-control mask. FILE_ALL_ACCESS is the standard-rights set, synchronize, + // and all file-specific rights. Both are the same semantic authority; any + // additional or missing bit remains unsafe. + const fileSpecificAll = uint32(0x1ff) + effective := uint32(windows.STANDARD_RIGHTS_REQUIRED|windows.SYNCHRONIZE) | fileSpecificAll return mask == uint32(windows.GENERIC_ALL) || mask == effective } diff --git a/tools/tht/internal/safeio/private_windows_test.go b/tools/tht/internal/safeio/private_windows_test.go index a208fd42..6d45525f 100644 --- a/tools/tht/internal/safeio/private_windows_test.go +++ b/tools/tht/internal/safeio/private_windows_test.go @@ -55,8 +55,8 @@ func TestPrivateWindowsDACLRejectsPermissiveDirectoryAndRegularFile(t *testing.T } func TestOwnerOnlyDACLAcceptsWindowsFullControlMask(t *testing.T) { - const fileDeleteChild = uint32(0x40) - effectiveFullControl := uint32(windows.FILE_GENERIC_READ|windows.FILE_GENERIC_WRITE|windows.FILE_GENERIC_EXECUTE|windows.DELETE) | fileDeleteChild + const fileSpecificAll = uint32(0x1ff) + effectiveFullControl := uint32(windows.STANDARD_RIGHTS_REQUIRED|windows.SYNCHRONIZE) | fileSpecificAll if !isOwnerOnlyFullControlMask(effectiveFullControl) { t.Fatalf("effective Windows full-control mask %#x was rejected", effectiveFullControl) }