fix(safeio): use self-relative create descriptors

This commit is contained in:
2026-08-18 13:16:28 +02:00
parent 81077e59d3
commit c863244a86
2 changed files with 49 additions and 1 deletions
+6 -1
View File
@@ -279,7 +279,12 @@ func newOwnerOnlySecurityDescriptor() (*ownerOnlySecurityDescriptor, error) {
owner.Close()
return nil, ErrUnsafeFile
}
return &ownerOnlySecurityDescriptor{ownerOnlyDACL: owner, descriptor: descriptor}, nil
selfRelative, err := descriptor.ToSelfRelative()
if err != nil || selfRelative == nil || !selfRelative.IsValid() {
owner.Close()
return nil, ErrUnsafeFile
}
return &ownerOnlySecurityDescriptor{ownerOnlyDACL: owner, descriptor: selfRelative}, nil
}
func (descriptor *ownerOnlySecurityDescriptor) Close() {
@@ -40,6 +40,17 @@ func TestPrivateWindowsDACLRejectsPermissiveDirectoryAndRegularFile(t *testing.T
for name, path := range map[string]string{"directory": directory, "regular file": path} {
t.Run(name, func(t *testing.T) {
t.Cleanup(func() {
var restoreErr error
if name == "directory" {
restoreErr = ProtectPrivateDirectory(path)
} else {
restoreErr = ProtectPrivateRegular(path)
}
if restoreErr != nil {
t.Errorf("restore owner-only DACL: %v", restoreErr)
}
})
if err := setPermissiveDACL(path); err != nil {
t.Fatal(err)
}
@@ -56,6 +67,38 @@ func TestPrivateWindowsDACLRejectsPermissiveDirectoryAndRegularFile(t *testing.T
}
}
func TestOwnerOnlyDACLCanProtectInheritedRegularFile(t *testing.T) {
directory := filepath.Join(t.TempDir(), "auth")
if err := os.Mkdir(directory, 0o700); err != nil {
t.Fatal(err)
}
path := filepath.Join(directory, "operator.env")
if err := os.WriteFile(path, []byte("private"), 0o600); err != nil {
t.Fatal(err)
}
parents, target, err := openCanonicalWindowsParent(path)
if err != nil {
t.Fatalf("openCanonicalWindowsParent() error = %T %v", err, err)
}
defer parents.Close()
handle, err := openWindowsRelativeComponent(
parents.handles[len(parents.handles)-1],
target,
false,
windows.GENERIC_READ|windows.WRITE_DAC|windows.WRITE_OWNER,
)
if err != nil {
t.Fatalf("openWindowsRelativeComponent() error = %T %v", err, err)
}
defer windows.CloseHandle(handle)
if err := setOwnerOnlyDACL(handle); err != nil {
t.Fatalf("setOwnerOnlyDACL() inherited file error = %T %v", err, err)
}
if err := validateOwnerOnlyDACL(handle); err != nil {
t.Fatalf("validateOwnerOnlyDACL() inherited file error = %T %v", err, err)
}
}
func TestOwnerOnlyDACLAcceptsWindowsFullControlMask(t *testing.T) {
const fileSpecificAll = uint32(0x1ff)
effectiveFullControl := uint32(windows.STANDARD_RIGHTS_REQUIRED|windows.SYNCHRONIZE) | fileSpecificAll