fix(auth): close Windows remediation review findings
This commit is contained in:
@@ -316,7 +316,7 @@ func validateOwnerOnlyDACL(handle windows.Handle) error {
|
||||
return ErrUnsafeFile
|
||||
}
|
||||
var ace *windows.ACCESS_ALLOWED_ACE
|
||||
if err := windows.GetAce(dacl, 0, &ace); err != nil || ace == nil || ace.Header.AceType != windows.ACCESS_ALLOWED_ACE_TYPE || ace.Header.AceFlags != 0 || ace.Mask != windows.GENERIC_ALL {
|
||||
if err := windows.GetAce(dacl, 0, &ace); err != nil || ace == nil || ace.Header.AceType != windows.ACCESS_ALLOWED_ACE_TYPE || ace.Header.AceFlags != 0 || !isOwnerOnlyFullControlMask(uint32(ace.Mask)) {
|
||||
return ErrUnsafeFile
|
||||
}
|
||||
aceSID := (*windows.SID)(unsafe.Pointer(&ace.SidStart))
|
||||
@@ -327,6 +327,15 @@ func validateOwnerOnlyDACL(handle windows.Handle) error {
|
||||
})
|
||||
}
|
||||
|
||||
func isOwnerOnlyFullControlMask(mask uint32) bool {
|
||||
// Windows may persist GENERIC_ALL in the ACE or expand it to the file-object
|
||||
// full-control mask (including FILE_DELETE_CHILD). Both are the same semantic
|
||||
// authority; any additional bit remains unsafe.
|
||||
const fileDeleteChild = uint32(0x40)
|
||||
effective := uint32(windows.FILE_GENERIC_READ|windows.FILE_GENERIC_WRITE|windows.FILE_GENERIC_EXECUTE|windows.DELETE) | fileDeleteChild
|
||||
return mask == uint32(windows.GENERIC_ALL) || mask == effective
|
||||
}
|
||||
|
||||
// withWindowsSecurityDescriptor confines inspection to x/sys's Go-owned descriptor copy. Its
|
||||
// GetSecurityInfo wrapper releases the native LocalAlloc result with LocalFree before returning.
|
||||
func withWindowsSecurityDescriptor(handle windows.Handle, inspect func(*windows.SECURITY_DESCRIPTOR) error) error {
|
||||
|
||||
Reference in New Issue
Block a user