fix(safeio): retain private file parent handles

This commit is contained in:
2026-08-18 08:51:59 +02:00
parent 0b77d1e850
commit e7a7f4f066
11 changed files with 359 additions and 212 deletions
@@ -395,6 +395,13 @@ func openWindowsPrivateRegularAtAllowedLinks(
}
func createWindowsPrivateRegularAt(parent windows.Handle, name string) (*windowsPrivateRegularAt, error) {
return createWindowsPrivateRegularAtWithAccess(parent, name, windows.FILE_GENERIC_READ|windows.FILE_GENERIC_WRITE|windows.DELETE)
}
// createWindowsPrivateRegularAtWithAccess creates the final leaf beneath an already-retained
// parent with an owner-only DACL in the same NtCreateFile operation. The caller never re-resolves
// an absolute pathname after the parent is pinned.
func createWindowsPrivateRegularAtWithAccess(parent windows.Handle, name string, access uint32) (*windowsPrivateRegularAt, error) {
security, err := newOwnerOnlySecurityDescriptor()
if err != nil {
return nil, ErrUnsafeFile
@@ -403,7 +410,7 @@ func createWindowsPrivateRegularAt(parent windows.Handle, name string) (*windows
handle, err := openWindowsRelativeObject(
parent,
name,
windows.FILE_GENERIC_READ|windows.FILE_GENERIC_WRITE|windows.DELETE,
access|windows.DELETE,
windows.FILE_CREATE,
windows.FILE_NON_DIRECTORY_FILE|windows.FILE_SYNCHRONOUS_IO_NONALERT|windows.FILE_OPEN_REPARSE_POINT,
security,