| 1377 | } |
| 1378 | |
| 1379 | static bool posix_directory_parent_secure(int directory_fd) { |
| 1380 | struct stat status; |
| 1381 | if (directory_fd < 0 || fstat(directory_fd, &status) != 0 || !S_ISDIR(status.st_mode) || |
| 1382 | !posix_directory_owner_trusted(status.st_uid) || |
| 1383 | !cbm_macos_extended_acl_fd_is_deny_only(directory_fd)) { |
| 1384 | return false; |
| 1385 | } |
| 1386 | return (status.st_mode & 0022) == 0 || |
| 1387 | (status.st_uid == (uid_t)0 && (status.st_mode & S_ISVTX) != 0); |
| 1388 | } |
| 1389 | |
| 1390 | /* Validate a path transition only through the two already-open directory |
| 1391 | * handles. A group/other-writable parent is unsafe unless it is the standard |
no test coverage detected