fix(safeio): retain private file parent handles
This commit is contained in:
@@ -31,33 +31,25 @@ func (value *windowsPrivateRegular) Close() {
|
||||
|
||||
func openWindowsPrivateRegular(path string, links uint32) (*windowsPrivateRegular, error) {
|
||||
parents, target, err := openCanonicalWindowsParent(path)
|
||||
if err != nil || len(parents.handles) == 0 || validateOwnerOnlyDACL(parents.handles[len(parents.handles)-1]) != nil {
|
||||
if err != nil || parents == nil || len(parents.handles) == 0 || validateOwnerOnlyDACL(parents.handles[len(parents.handles)-1]) != nil {
|
||||
if parents != nil {
|
||||
parents.Close()
|
||||
}
|
||||
return nil, ErrUnsafeFile
|
||||
}
|
||||
fullPath := filepath.Join(parents.directory, target)
|
||||
handle, err := windows.CreateFile(
|
||||
windows.StringToUTF16Ptr(fullPath),
|
||||
windows.GENERIC_READ,
|
||||
windowsRetainedHandleShareMode,
|
||||
nil,
|
||||
windows.OPEN_EXISTING,
|
||||
windows.FILE_FLAG_OPEN_REPARSE_POINT|windows.FILE_ATTRIBUTE_NORMAL,
|
||||
0,
|
||||
)
|
||||
value, err := openWindowsPrivateRegularAt(parents.handles[len(parents.handles)-1], target, windows.GENERIC_READ, links)
|
||||
if err != nil {
|
||||
parents.Close()
|
||||
return nil, err
|
||||
}
|
||||
var info windows.ByHandleFileInformation
|
||||
if err := windows.GetFileInformationByHandle(handle, &info); err != nil || info.FileAttributes&windows.FILE_ATTRIBUTE_REPARSE_POINT != 0 || info.FileAttributes&windows.FILE_ATTRIBUTE_DIRECTORY != 0 || info.NumberOfLinks != links || validateOwnerOnlyDACL(handle) != nil {
|
||||
_ = windows.CloseHandle(handle)
|
||||
parents.Close()
|
||||
return nil, ErrUnsafeFile
|
||||
}
|
||||
return &windowsPrivateRegular{parents: parents, handle: handle, path: fullPath, info: info}, nil
|
||||
handle := value.handle
|
||||
value.handle = 0
|
||||
return &windowsPrivateRegular{
|
||||
parents: parents,
|
||||
handle: handle,
|
||||
path: filepath.Join(parents.directory, target),
|
||||
info: value.info,
|
||||
}, nil
|
||||
}
|
||||
|
||||
func claimCanonicalPrivateRegular(source, claim string) (bool, error) {
|
||||
|
||||
Reference in New Issue
Block a user