fix(auth): close Windows remediation review findings
This commit is contained in:
@@ -7,6 +7,7 @@ import (
|
||||
"os"
|
||||
"path/filepath"
|
||||
"runtime"
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"golang.org/x/sys/windows"
|
||||
@@ -53,6 +54,68 @@ func TestPrivateWindowsDACLRejectsPermissiveDirectoryAndRegularFile(t *testing.T
|
||||
}
|
||||
}
|
||||
|
||||
func TestOwnerOnlyDACLAcceptsWindowsFullControlMask(t *testing.T) {
|
||||
const fileDeleteChild = uint32(0x40)
|
||||
effectiveFullControl := uint32(windows.FILE_GENERIC_READ|windows.FILE_GENERIC_WRITE|windows.FILE_GENERIC_EXECUTE|windows.DELETE) | fileDeleteChild
|
||||
if !isOwnerOnlyFullControlMask(effectiveFullControl) {
|
||||
t.Fatalf("effective Windows full-control mask %#x was rejected", effectiveFullControl)
|
||||
}
|
||||
if !isOwnerOnlyFullControlMask(uint32(windows.GENERIC_ALL)) {
|
||||
t.Fatal("generic full-control mask was rejected")
|
||||
}
|
||||
if isOwnerOnlyFullControlMask(effectiveFullControl | uint32(windows.ACCESS_SYSTEM_SECURITY)) {
|
||||
t.Fatal("full-control mask with an extra right was accepted")
|
||||
}
|
||||
}
|
||||
|
||||
func TestWindowsPrivateRegularCleanupClosesAfterDeleteDispositionFailure(t *testing.T) {
|
||||
var calls []string
|
||||
err := finishWindowsPrivateRegularCleanup(
|
||||
func() error {
|
||||
calls = append(calls, "delete")
|
||||
return ErrUnsafeFile
|
||||
},
|
||||
func() error {
|
||||
calls = append(calls, "close")
|
||||
return nil
|
||||
},
|
||||
)
|
||||
if !errors.Is(err, ErrUnsafeFile) {
|
||||
t.Fatalf("finishWindowsPrivateRegularCleanup() error = %v, want ErrUnsafeFile", err)
|
||||
}
|
||||
if got, want := strings.Join(calls, ","), "delete,close"; got != want {
|
||||
t.Fatalf("cleanup order = %q, want %q", got, want)
|
||||
}
|
||||
}
|
||||
|
||||
func TestWindowsClaimCleanupAttemptsLaterOperationsAfterEarlierFailure(t *testing.T) {
|
||||
var calls []string
|
||||
err := finishWindowsClaimCleanup(
|
||||
func() error {
|
||||
calls = append(calls, "claim-close")
|
||||
return ErrUnsafeFile
|
||||
},
|
||||
func() error {
|
||||
calls = append(calls, "source-delete")
|
||||
return nil
|
||||
},
|
||||
func() error {
|
||||
calls = append(calls, "claim-delete")
|
||||
return nil
|
||||
},
|
||||
func() error {
|
||||
calls = append(calls, "validate")
|
||||
return nil
|
||||
},
|
||||
)
|
||||
if !errors.Is(err, ErrUnsafeFile) {
|
||||
t.Fatalf("finishWindowsClaimCleanup() error = %v, want ErrUnsafeFile", err)
|
||||
}
|
||||
if got, want := strings.Join(calls, ","), "claim-close,source-delete,claim-delete,validate"; got != want {
|
||||
t.Fatalf("cleanup order = %q, want %q", got, want)
|
||||
}
|
||||
}
|
||||
|
||||
func TestCreateCanonicalNewPrivateFileInstallsOwnerOnlyDACLAtCreation(t *testing.T) {
|
||||
directory := filepath.Join(t.TempDir(), "auth")
|
||||
if err := os.Mkdir(directory, 0o700); err != nil {
|
||||
|
||||
Reference in New Issue
Block a user