| 4041 | } |
| 4042 | |
| 4043 | static bool win_bounded_sid_trusted(win_security_t *security, const uint8_t *sid, |
| 4044 | size_t sid_capacity, bool creator_owner_inherit_only, |
| 4045 | bool ancestor) { |
| 4046 | if (!security || !sid || sid_capacity < 8U || sid[1] > 15U) { |
| 4047 | return false; |
| 4048 | } |
| 4049 | size_t sid_length = 8U + (size_t)sid[1] * 4U; |
| 4050 | return sid_length <= sid_capacity && windows_sid_valid(sid, sid_length) && |
| 4051 | security->is_valid_sid((PSID)sid) && |
| 4052 | security->get_length_sid((PSID)sid) == (DWORD)sid_length && |
| 4053 | (win_sid_trusted(security, (PSID)sid) || |
| 4054 | (creator_owner_inherit_only && |
| 4055 | security->is_well_known_sid((PSID)sid, WinCreatorOwnerSid)) || |
| 4056 | /* OWNER RIGHTS (S-1-3-4) modulates the rights of whoever OWNS the |
| 4057 | * object; the owner is separately validated as the exact current |
| 4058 | * user, so such an ACE only ever grants to us. Default Windows |
| 4059 | * profile/temp ACLs (and GitHub runner profiles) carry it, and |
| 4060 | * rejecting it locked real current-user directories out. */ |
| 4061 | security->is_well_known_sid((PSID)sid, WinCreatorOwnerRightsSid) || |
| 4062 | (ancestor && win_sid_is_app_container(sid, sid_length))); |
| 4063 | } |
| 4064 | |
| 4065 | static bool win_file_owner_secure(win_security_t *security, HANDLE file, |
| 4066 | bool require_current_user) { |
no test coverage detected