fix(auth): atomically secure Windows lock creation

This commit is contained in:
2026-08-16 19:01:09 +02:00
parent 25ee8b87d1
commit d17ad0e95b
6 changed files with 267 additions and 51 deletions
@@ -53,6 +53,63 @@ func TestPrivateWindowsDACLRejectsPermissiveDirectoryAndRegularFile(t *testing.T
}
}
func TestCreateCanonicalNewPrivateFileInstallsOwnerOnlyDACLAtCreation(t *testing.T) {
directory := filepath.Join(t.TempDir(), "auth")
if err := os.Mkdir(directory, 0o700); err != nil {
t.Fatal(err)
}
if err := ProtectPrivateDirectory(directory); err != nil {
t.Fatal(err)
}
path := filepath.Join(directory, ".auth.lock")
file, err := createCanonicalNewPrivateFile(path, 0o600)
if err != nil {
t.Fatal(err)
}
defer file.Close()
if err := ValidatePrivateRegular(path); err != nil {
t.Fatalf("new lock DACL error = %v", err)
}
}
func TestWithWindowsSecurityDescriptorKeepsOwnedDescriptorValidDuringInspection(t *testing.T) {
directory := filepath.Join(t.TempDir(), "auth")
if err := os.Mkdir(directory, 0o700); err != nil {
t.Fatal(err)
}
if err := ProtectPrivateDirectory(directory); err != nil {
t.Fatal(err)
}
path := filepath.Join(directory, "users.yaml")
if err := os.WriteFile(path, []byte("private"), 0o600); err != nil {
t.Fatal(err)
}
if err := ProtectPrivateRegular(path); err != nil {
t.Fatal(err)
}
handle, err := openWindowsComponent(path, false)
if err != nil {
t.Fatal(err)
}
defer windows.CloseHandle(handle)
if err := withWindowsSecurityDescriptor(handle, func(descriptor *windows.SECURITY_DESCRIPTOR) error {
runtime.GC()
owner, _, err := descriptor.Owner()
if err != nil || owner == nil {
t.Fatalf("descriptor owner error = %v", err)
}
dacl, _, err := descriptor.DACL()
if err != nil || dacl == nil || dacl.AceCount != 1 {
t.Fatalf("descriptor DACL error = %v", err)
}
return nil
}); err != nil {
t.Fatalf("withWindowsSecurityDescriptor() error = %v", err)
}
}
func TestReplaceCanonicalRegularCreatesPrivateTemporaryAndReplacement(t *testing.T) {
directory := filepath.Join(t.TempDir(), "auth")
if err := os.Mkdir(directory, 0o700); err != nil {