|
2 | 2 |
|
3 | 3 | package daemon |
4 | 4 |
|
5 | | -import "os" |
| 5 | +import ( |
| 6 | + "errors" |
| 7 | + "fmt" |
| 8 | + "os" |
| 9 | + "unsafe" |
6 | 10 |
|
7 | | -// Windows has no portable uid to compare. os.Root still binds every operation |
8 | | -// to one directory handle and rejects reparse-point traversal, while the normal |
9 | | -// daemon directory lives below the current user's profile. |
10 | | -func checkStatusDirOwner(os.FileInfo) error { |
| 11 | + "golang.org/x/sys/windows" |
| 12 | +) |
| 13 | + |
| 14 | +const statusDirectoryWriteAccess = windows.ACCESS_MASK( |
| 15 | + windows.GENERIC_ALL | |
| 16 | + windows.GENERIC_WRITE | |
| 17 | + windows.DELETE | |
| 18 | + windows.WRITE_DAC | |
| 19 | + windows.WRITE_OWNER | |
| 20 | + windows.FILE_WRITE_DATA | |
| 21 | + windows.FILE_APPEND_DATA | |
| 22 | + windows.FILE_WRITE_ATTRIBUTES | |
| 23 | + windows.FILE_WRITE_EA | |
| 24 | + 0x40, // FILE_DELETE_CHILD |
| 25 | +) |
| 26 | + |
| 27 | +// checkStatusDirOwner validates ownership and write access through a handle |
| 28 | +// opened beneath root. Path-based ACL inspection would recreate the ancestor |
| 29 | +// swap race that Root is intended to close. |
| 30 | +func checkStatusDirOwner(root *os.Root, _ os.FileInfo) (returnErr error) { |
| 31 | + directory, err := root.Open(".") |
| 32 | + if err != nil { |
| 33 | + return fmt.Errorf("open status directory for access validation: %w", err) |
| 34 | + } |
| 35 | + defer func() { |
| 36 | + if err := directory.Close(); err != nil { |
| 37 | + returnErr = errors.Join(returnErr, fmt.Errorf("close status directory access handle: %w", err)) |
| 38 | + } |
| 39 | + }() |
| 40 | + |
| 41 | + raw, err := directory.SyscallConn() |
| 42 | + if err != nil { |
| 43 | + return fmt.Errorf("access status directory handle: %w", err) |
| 44 | + } |
| 45 | + var descriptor *windows.SECURITY_DESCRIPTOR |
| 46 | + var queryErr error |
| 47 | + if err := raw.Control(func(handle uintptr) { |
| 48 | + descriptor, queryErr = windows.GetSecurityInfo( |
| 49 | + windows.Handle(handle), |
| 50 | + windows.SE_FILE_OBJECT, |
| 51 | + windows.OWNER_SECURITY_INFORMATION|windows.DACL_SECURITY_INFORMATION, |
| 52 | + ) |
| 53 | + }); err != nil { |
| 54 | + return fmt.Errorf("inspect status directory access: %w", err) |
| 55 | + } |
| 56 | + if queryErr != nil { |
| 57 | + return fmt.Errorf("inspect status directory owner and DACL: %w", queryErr) |
| 58 | + } |
| 59 | + if descriptor == nil { |
| 60 | + return fmt.Errorf("status directory security descriptor is unavailable") |
| 61 | + } |
| 62 | + |
| 63 | + user, err := windows.GetCurrentProcessToken().GetTokenUser() |
| 64 | + if err != nil { |
| 65 | + return fmt.Errorf("resolve current Windows user: %w", err) |
| 66 | + } |
| 67 | + owner, _, err := descriptor.Owner() |
| 68 | + if err != nil { |
| 69 | + return fmt.Errorf("read status directory owner: %w", err) |
| 70 | + } |
| 71 | + if owner == nil || !owner.Equals(user.User.Sid) { |
| 72 | + return fmt.Errorf("status directory is not owned by the current Windows user") |
| 73 | + } |
| 74 | + |
| 75 | + dacl, _, err := descriptor.DACL() |
| 76 | + if err != nil { |
| 77 | + return fmt.Errorf("read status directory DACL: %w", err) |
| 78 | + } |
| 79 | + if dacl == nil { |
| 80 | + return fmt.Errorf("status directory has an unrestricted Windows DACL") |
| 81 | + } |
| 82 | + for index := uint16(0); index < dacl.AceCount; index++ { |
| 83 | + var ace *windows.ACCESS_ALLOWED_ACE |
| 84 | + if err := windows.GetAce(dacl, uint32(index), &ace); err != nil { |
| 85 | + return fmt.Errorf("read status directory DACL entry %d: %w", index, err) |
| 86 | + } |
| 87 | + switch ace.Header.AceType { |
| 88 | + case windows.ACCESS_DENIED_ACE_TYPE: |
| 89 | + continue |
| 90 | + case windows.ACCESS_ALLOWED_ACE_TYPE: |
| 91 | + default: |
| 92 | + return fmt.Errorf("status directory DACL entry %d has unsupported type %d", index, ace.Header.AceType) |
| 93 | + } |
| 94 | + if ace.Mask&statusDirectoryWriteAccess == 0 { |
| 95 | + continue |
| 96 | + } |
| 97 | + trustee := (*windows.SID)(unsafe.Pointer(&ace.SidStart)) |
| 98 | + if !allowedStatusDirectoryTrustee(trustee, user.User.Sid) { |
| 99 | + return fmt.Errorf("status directory DACL grants write access to unexpected trustee %s", trustee.String()) |
| 100 | + } |
| 101 | + } |
11 | 102 | return nil |
12 | 103 | } |
| 104 | + |
| 105 | +func allowedStatusDirectoryTrustee(trustee, user *windows.SID) bool { |
| 106 | + return trustee != nil && (trustee.Equals(user) || |
| 107 | + trustee.IsWellKnown(windows.WinLocalSystemSid) || |
| 108 | + trustee.IsWellKnown(windows.WinBuiltinAdministratorsSid) || |
| 109 | + trustee.IsWellKnown(windows.WinCreatorOwnerSid) || |
| 110 | + trustee.IsWellKnown(windows.WinCreatorOwnerRightsSid)) |
| 111 | +} |
0 commit comments