fix(auth): close Windows remediation review findings

This commit is contained in:
2026-08-18 12:46:54 +02:00
parent fa499a9bdd
commit cd5f505c8a
10 changed files with 310 additions and 33 deletions
+10 -1
View File
@@ -316,7 +316,7 @@ func validateOwnerOnlyDACL(handle windows.Handle) error {
return ErrUnsafeFile
}
var ace *windows.ACCESS_ALLOWED_ACE
if err := windows.GetAce(dacl, 0, &ace); err != nil || ace == nil || ace.Header.AceType != windows.ACCESS_ALLOWED_ACE_TYPE || ace.Header.AceFlags != 0 || ace.Mask != windows.GENERIC_ALL {
if err := windows.GetAce(dacl, 0, &ace); err != nil || ace == nil || ace.Header.AceType != windows.ACCESS_ALLOWED_ACE_TYPE || ace.Header.AceFlags != 0 || !isOwnerOnlyFullControlMask(uint32(ace.Mask)) {
return ErrUnsafeFile
}
aceSID := (*windows.SID)(unsafe.Pointer(&ace.SidStart))
@@ -327,6 +327,15 @@ func validateOwnerOnlyDACL(handle windows.Handle) error {
})
}
func isOwnerOnlyFullControlMask(mask uint32) bool {
// Windows may persist GENERIC_ALL in the ACE or expand it to the file-object
// full-control mask (including FILE_DELETE_CHILD). Both are the same semantic
// authority; any additional bit remains unsafe.
const fileDeleteChild = uint32(0x40)
effective := uint32(windows.FILE_GENERIC_READ|windows.FILE_GENERIC_WRITE|windows.FILE_GENERIC_EXECUTE|windows.DELETE) | fileDeleteChild
return mask == uint32(windows.GENERIC_ALL) || mask == effective
}
// withWindowsSecurityDescriptor confines inspection to x/sys's Go-owned descriptor copy. Its
// GetSecurityInfo wrapper releases the native LocalAlloc result with LocalFree before returning.
func withWindowsSecurityDescriptor(handle windows.Handle, inspect func(*windows.SECURITY_DESCRIPTOR) error) error {