fix(auth): make diagnostics bounded and portable
This commit is contained in:
@@ -6,16 +6,35 @@ import (
|
||||
"errors"
|
||||
"os"
|
||||
"path/filepath"
|
||||
|
||||
"golang.org/x/sys/unix"
|
||||
)
|
||||
|
||||
func createPrivateDirectory(path string) error {
|
||||
if err := os.Mkdir(path, 0o700); err != nil {
|
||||
if errors.Is(err, os.ErrExist) {
|
||||
parents, err := openCanonicalUnixParent(path)
|
||||
if err != nil {
|
||||
return ErrUnsafeFile
|
||||
}
|
||||
defer parents.Close()
|
||||
if err := unix.Mkdirat(parents.parent, parents.target, 0o700); err != nil {
|
||||
if errors.Is(err, unix.EEXIST) {
|
||||
return os.ErrExist
|
||||
}
|
||||
return err
|
||||
return ErrUnsafeFile
|
||||
}
|
||||
return ProtectPrivateDirectory(path)
|
||||
descriptor, err := unix.Openat(parents.parent, parents.target, unix.O_RDONLY|unix.O_CLOEXEC|unix.O_DIRECTORY|unix.O_NOFOLLOW, 0)
|
||||
if err != nil {
|
||||
return ErrUnsafeFile
|
||||
}
|
||||
defer unix.Close(descriptor)
|
||||
if unix.Fchmod(descriptor, 0o700) != nil {
|
||||
return ErrUnsafeFile
|
||||
}
|
||||
var stat unix.Stat_t
|
||||
if unix.Fstat(descriptor, &stat) != nil || !privateUnixDirectoryStat(&stat) {
|
||||
return ErrUnsafeFile
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
// ProtectPrivateDirectory sets the private directory mode used for local authentication state.
|
||||
|
||||
Reference in New Issue
Block a user