fix(auth): allow Windows claim verification to share delete

This commit is contained in:
2026-08-18 11:18:57 +02:00
parent 0d8e707533
commit b31b27e584
@@ -154,6 +154,26 @@ func openWindowsRelativeObject(
disposition uint32, disposition uint32,
options uint32, options uint32,
security *ownerOnlySecurityDescriptor, security *ownerOnlySecurityDescriptor,
) (windows.Handle, error) {
return openWindowsRelativeObjectWithShareMode(
parent,
name,
access,
disposition,
options,
security,
windowsRetainedHandleShareMode,
)
}
func openWindowsRelativeObjectWithShareMode(
parent windows.Handle,
name string,
access uint32,
disposition uint32,
options uint32,
security *ownerOnlySecurityDescriptor,
shareMode uint32,
) (windows.Handle, error) { ) (windows.Handle, error) {
if parent == 0 || !validPrivateLeafName(name) { if parent == 0 || !validPrivateLeafName(name) {
return 0, ErrUnsafeFile return 0, ErrUnsafeFile
@@ -184,7 +204,7 @@ func openWindowsRelativeObject(
&status, &status,
&allocationSize, &allocationSize,
windows.FILE_ATTRIBUTE_NORMAL, windows.FILE_ATTRIBUTE_NORMAL,
windowsRetainedHandleShareMode, shareMode,
disposition, disposition,
options, options,
0, 0,
@@ -345,13 +365,30 @@ func openWindowsPrivateRegularAt(
access uint32, access uint32,
allowedLinks ...uint32, allowedLinks ...uint32,
) (*windowsPrivateRegularAt, error) { ) (*windowsPrivateRegularAt, error) {
handle, err := openWindowsRelativeObject( return openWindowsPrivateRegularAtWithShareMode(
parent,
name,
access,
windowsRetainedHandleShareMode,
allowedLinks...,
)
}
func openWindowsPrivateRegularAtWithShareMode(
parent windows.Handle,
name string,
access uint32,
shareMode uint32,
allowedLinks ...uint32,
) (*windowsPrivateRegularAt, error) {
handle, err := openWindowsRelativeObjectWithShareMode(
parent, parent,
name, name,
access, access,
windows.FILE_OPEN, windows.FILE_OPEN,
windows.FILE_NON_DIRECTORY_FILE|windows.FILE_SYNCHRONOUS_IO_NONALERT|windows.FILE_OPEN_REPARSE_POINT, windows.FILE_NON_DIRECTORY_FILE|windows.FILE_SYNCHRONOUS_IO_NONALERT|windows.FILE_OPEN_REPARSE_POINT,
nil, nil,
shareMode,
) )
if err != nil { if err != nil {
return nil, err return nil, err
@@ -936,7 +973,13 @@ func (directory *windowsPrivateDirectory) RemoveClaim(source, claim string) (boo
} }
return false, ErrUnsafeFile return false, ErrUnsafeFile
} }
claimed, err := openWindowsPrivateRegularAt(directory.handle, claim, windows.FILE_GENERIC_READ, 2) claimed, err := openWindowsPrivateRegularAtWithShareMode(
directory.handle,
claim,
windows.FILE_GENERIC_READ,
windowsRetainedHandleShareMode|windows.FILE_SHARE_DELETE,
2,
)
if isWindowsRelativeNotFound(err) { if isWindowsRelativeNotFound(err) {
_ = value.Close() _ = value.Close()
return false, nil return false, nil