From b31b27e5845ffd3adf311429367319beaba263c7 Mon Sep 17 00:00:00 2001 From: mptyl Date: Tue, 18 Aug 2026 11:18:57 +0200 Subject: [PATCH] fix(auth): allow Windows claim verification to share delete --- .../internal/safeio/private_root_windows.go | 49 +++++++++++++++++-- 1 file changed, 46 insertions(+), 3 deletions(-) diff --git a/tools/tht/internal/safeio/private_root_windows.go b/tools/tht/internal/safeio/private_root_windows.go index f3424adb..a5007d0b 100644 --- a/tools/tht/internal/safeio/private_root_windows.go +++ b/tools/tht/internal/safeio/private_root_windows.go @@ -154,6 +154,26 @@ func openWindowsRelativeObject( disposition uint32, options uint32, security *ownerOnlySecurityDescriptor, +) (windows.Handle, error) { + return openWindowsRelativeObjectWithShareMode( + parent, + name, + access, + disposition, + options, + security, + windowsRetainedHandleShareMode, + ) +} + +func openWindowsRelativeObjectWithShareMode( + parent windows.Handle, + name string, + access uint32, + disposition uint32, + options uint32, + security *ownerOnlySecurityDescriptor, + shareMode uint32, ) (windows.Handle, error) { if parent == 0 || !validPrivateLeafName(name) { return 0, ErrUnsafeFile @@ -184,7 +204,7 @@ func openWindowsRelativeObject( &status, &allocationSize, windows.FILE_ATTRIBUTE_NORMAL, - windowsRetainedHandleShareMode, + shareMode, disposition, options, 0, @@ -345,13 +365,30 @@ func openWindowsPrivateRegularAt( access uint32, allowedLinks ...uint32, ) (*windowsPrivateRegularAt, error) { - handle, err := openWindowsRelativeObject( + return openWindowsPrivateRegularAtWithShareMode( + parent, + name, + access, + windowsRetainedHandleShareMode, + allowedLinks..., + ) +} + +func openWindowsPrivateRegularAtWithShareMode( + parent windows.Handle, + name string, + access uint32, + shareMode uint32, + allowedLinks ...uint32, +) (*windowsPrivateRegularAt, error) { + handle, err := openWindowsRelativeObjectWithShareMode( parent, name, access, windows.FILE_OPEN, windows.FILE_NON_DIRECTORY_FILE|windows.FILE_SYNCHRONOUS_IO_NONALERT|windows.FILE_OPEN_REPARSE_POINT, nil, + shareMode, ) if err != nil { return nil, err @@ -936,7 +973,13 @@ func (directory *windowsPrivateDirectory) RemoveClaim(source, claim string) (boo } return false, ErrUnsafeFile } - claimed, err := openWindowsPrivateRegularAt(directory.handle, claim, windows.FILE_GENERIC_READ, 2) + claimed, err := openWindowsPrivateRegularAtWithShareMode( + directory.handle, + claim, + windows.FILE_GENERIC_READ, + windowsRetainedHandleShareMode|windows.FILE_SHARE_DELETE, + 2, + ) if isWindowsRelativeNotFound(err) { _ = value.Close() return false, nil