MCPcopy Create free account
hub / github.com/DeusData/codebase-memory-mcp / win_bounded_sid_trusted

Function win_bounded_sid_trusted

src/daemon/ipc.c:3914–3932  ·  view source on GitHub ↗

Source from the content-addressed store, hash-verified

3912}
3913
3914static bool win_bounded_sid_trusted(win_security_t *security, const uint8_t *sid,
3915 size_t sid_capacity, bool creator_owner_inherit_only) {
3916 if (!security || !sid || sid_capacity < 8U || sid[1] > 15U) {
3917 return false;
3918 }
3919 size_t sid_length = 8U + (size_t)sid[1] * 4U;
3920 return sid_length <= sid_capacity && windows_sid_valid(sid, sid_length) &&
3921 security->is_valid_sid((PSID)sid) &&
3922 security->get_length_sid((PSID)sid) == (DWORD)sid_length &&
3923 (win_sid_trusted(security, (PSID)sid) ||
3924 (creator_owner_inherit_only &&
3925 security->is_well_known_sid((PSID)sid, WinCreatorOwnerSid)) ||
3926 /* OWNER RIGHTS (S-1-3-4) modulates the rights of whoever OWNS the
3927 * object; the owner is separately validated as the exact current
3928 * user, so such an ACE only ever grants to us. Default Windows
3929 * profile/temp ACLs (and GitHub runner profiles) carry it, and
3930 * rejecting it locked real current-user directories out. */
3931 security->is_well_known_sid((PSID)sid, WinCreatorOwnerRightsSid));
3932}
3933
3934static bool win_file_owner_secure(win_security_t *security, HANDLE file,
3935 bool require_current_user) {

Callers 1

win_file_acl_secureFunction · 0.85

Calls 2

windows_sid_validFunction · 0.85
win_sid_trustedFunction · 0.85

Tested by

no test coverage detected