MCPcopy Create free account
hub / github.com/DeusData/codebase-memory-mcp / win_mkdtemp_private_create

Function win_mkdtemp_private_create

src/foundation/compat.c:87–129  ·  view source on GitHub ↗

Create `path` with an explicit private security descriptor: owner stamped * to the token user and a protected, inheritable, user-only DACL. A plain * _mkdir takes the token's DEFAULT owner and the parent's inheritable DACL; * under an Administrators-default-owner policy (standard on Windows Server * and GitHub's elevated runners) the directory is then born owned by * BUILTIN\Administrators wi

Source from the content-addressed store, hash-verified

85 * back to plain _mkdir so degraded environments (Wine) keep working —
86 * downstream validation still gates security there. */
87static bool win_mkdtemp_private_create(const char *path) {
88 bool created = false;
89 HANDLE token = NULL;
90 TOKEN_USER *user = NULL;
91 PACL acl = NULL;
92 DWORD needed = 0;
93 wchar_t *wide = cbm_path_to_wide(path);
94 if (wide && OpenProcessToken(GetCurrentProcess(), TOKEN_QUERY, &token) &&
95 !GetTokenInformation(token, TokenUser, NULL, 0, &needed) &&
96 GetLastError() == ERROR_INSUFFICIENT_BUFFER && (user = malloc(needed)) != NULL &&
97 GetTokenInformation(token, TokenUser, user, needed, &needed) && user->User.Sid &&
98 IsValidSid(user->User.Sid)) {
99 EXPLICIT_ACCESSW access;
100 memset(&access, 0, sizeof(access));
101 access.grfAccessPermissions = GENERIC_ALL;
102 access.grfAccessMode = SET_ACCESS;
103 access.grfInheritance = SUB_CONTAINERS_AND_OBJECTS_INHERIT;
104 access.Trustee.TrusteeForm = TRUSTEE_IS_SID;
105 access.Trustee.TrusteeType = TRUSTEE_IS_USER;
106 access.Trustee.ptstrName = (LPWSTR)user->User.Sid;
107 SECURITY_DESCRIPTOR descriptor;
108 if (SetEntriesInAclW(1, &access, NULL, &acl) == ERROR_SUCCESS &&
109 InitializeSecurityDescriptor(&descriptor, SECURITY_DESCRIPTOR_REVISION) &&
110 SetSecurityDescriptorDacl(&descriptor, TRUE, acl, FALSE) &&
111 SetSecurityDescriptorOwner(&descriptor, user->User.Sid, FALSE) &&
112 SetSecurityDescriptorControl(&descriptor, SE_DACL_PROTECTED, SE_DACL_PROTECTED)) {
113 SECURITY_ATTRIBUTES attributes;
114 attributes.nLength = sizeof(attributes);
115 attributes.lpSecurityDescriptor = &descriptor;
116 attributes.bInheritHandle = FALSE;
117 created = CreateDirectoryW(wide, &attributes) != 0;
118 }
119 }
120 if (acl) {
121 (void)LocalFree(acl);
122 }
123 free(user);
124 if (token) {
125 (void)CloseHandle(token);
126 }
127 free(wide);
128 return created;
129}
130
131char *cbm_mkdtemp(char *tmpl) {
132 /* Per-call storage is required: daemon sessions invoke mkdtemp concurrently.

Callers 1

cbm_mkdtempFunction · 0.85

Calls 1

cbm_path_to_wideFunction · 0.85

Tested by

no test coverage detected