fix(safeio): retain private file parent handles
This commit is contained in:
@@ -216,6 +216,47 @@ func TestOpenCanonicalWindowsParentBlocksParentRename(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestCreateCanonicalNewPrivateFilePinsWindowsParentBeforeCreate(t *testing.T) {
|
||||
root := t.TempDir()
|
||||
parent := filepath.Join(root, "auth")
|
||||
if err := os.Mkdir(parent, 0o700); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err := ProtectPrivateDirectory(parent); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
path := filepath.Join(parent, "archive.zip")
|
||||
attemptedSwap := false
|
||||
restoreHook := SetPrivateDirectoryTestHookForTest(func(stage string) {
|
||||
if stage != "after-canonical-private-file-parent-open" || attemptedSwap {
|
||||
return
|
||||
}
|
||||
attemptedSwap = true
|
||||
if err := os.Rename(parent, parent+"-renamed"); err == nil {
|
||||
t.Fatal("parent rename succeeded while private file creation retained its handle")
|
||||
}
|
||||
})
|
||||
t.Cleanup(restoreHook)
|
||||
|
||||
file, err := CreateCanonicalNewPrivateFile(path)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if _, err := file.Write([]byte("staged")); err != nil {
|
||||
_ = file.Close()
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err := file.Close(); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if !attemptedSwap {
|
||||
t.Fatal("private file creator did not retain the parent before creation")
|
||||
}
|
||||
if err := ValidatePrivateRegular(path); err != nil {
|
||||
t.Fatalf("ValidatePrivateRegular() = %v, want owner-private staged file", err)
|
||||
}
|
||||
}
|
||||
|
||||
func setPermissiveDACL(path string) error {
|
||||
world, err := windows.StringToSid("S-1-1-0")
|
||||
if err != nil {
|
||||
|
||||
Reference in New Issue
Block a user