| 4238 | } |
| 4239 | |
| 4240 | static bool win_directory_component_secure(win_security_t *security, const wchar_t *path) { |
| 4241 | HANDLE directory = |
| 4242 | CreateFileW(path, FILE_READ_ATTRIBUTES | READ_CONTROL, |
| 4243 | FILE_SHARE_READ | FILE_SHARE_WRITE | FILE_SHARE_DELETE, NULL, OPEN_EXISTING, |
| 4244 | FILE_FLAG_BACKUP_SEMANTICS | FILE_FLAG_OPEN_REPARSE_POINT, NULL); |
| 4245 | if (directory == INVALID_HANDLE_VALUE) { |
| 4246 | return false; |
| 4247 | } |
| 4248 | BY_HANDLE_FILE_INFORMATION info; |
| 4249 | /* Default Windows profile ancestors grant cross-account add-subdirectory. |
| 4250 | * That permits siblings but cannot replace the existing next path |
| 4251 | * component. Keep every other mutation right forbidden; the final runtime |
| 4252 | * directory is separately owner-validated and given a protected DACL. */ |
| 4253 | DWORD mutation = win_private_mutation_rights() & ~((DWORD)FILE_ADD_SUBDIRECTORY); |
| 4254 | bool valid = GetFileInformationByHandle(directory, &info) != 0 && |
| 4255 | (info.dwFileAttributes & FILE_ATTRIBUTE_DIRECTORY) != 0 && |
| 4256 | (info.dwFileAttributes & FILE_ATTRIBUTE_REPARSE_POINT) == 0 && |
| 4257 | win_file_security_secure(security, directory, false, mutation, true); |
| 4258 | (void)CloseHandle(directory); |
| 4259 | return valid; |
| 4260 | } |
| 4261 | |
| 4262 | static bool win_private_directory_tree_secure(const wchar_t *directory_path) { |
| 4263 | if (!directory_path) { |
no test coverage detected