| 3912 | } |
| 3913 | |
| 3914 | static bool win_bounded_sid_trusted(win_security_t *security, const uint8_t *sid, |
| 3915 | size_t sid_capacity, bool creator_owner_inherit_only) { |
| 3916 | if (!security || !sid || sid_capacity < 8U || sid[1] > 15U) { |
| 3917 | return false; |
| 3918 | } |
| 3919 | size_t sid_length = 8U + (size_t)sid[1] * 4U; |
| 3920 | return sid_length <= sid_capacity && windows_sid_valid(sid, sid_length) && |
| 3921 | security->is_valid_sid((PSID)sid) && |
| 3922 | security->get_length_sid((PSID)sid) == (DWORD)sid_length && |
| 3923 | (win_sid_trusted(security, (PSID)sid) || |
| 3924 | (creator_owner_inherit_only && |
| 3925 | security->is_well_known_sid((PSID)sid, WinCreatorOwnerSid)) || |
| 3926 | /* OWNER RIGHTS (S-1-3-4) modulates the rights of whoever OWNS the |
| 3927 | * object; the owner is separately validated as the exact current |
| 3928 | * user, so such an ACE only ever grants to us. Default Windows |
| 3929 | * profile/temp ACLs (and GitHub runner profiles) carry it, and |
| 3930 | * rejecting it locked real current-user directories out. */ |
| 3931 | security->is_well_known_sid((PSID)sid, WinCreatorOwnerRightsSid)); |
| 3932 | } |
| 3933 | |
| 3934 | static bool win_file_owner_secure(win_security_t *security, HANDLE file, |
| 3935 | bool require_current_user) { |
no test coverage detected