Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 4 additions & 2 deletions crates/tinybus/src/module/cache.rs
Original file line number Diff line number Diff line change
Expand Up @@ -403,7 +403,9 @@ fn create_private_dir_all(path: &Path) -> std::io::Result<()> {
}
#[cfg(not(unix))]
{
std::fs::create_dir_all(path)
// Windows: an owner-only, inheritance-protected DACL; elsewhere a
// plain `create_dir_all`.
super::windows_acl::create_private_dir_all(path)
}
}

Expand Down Expand Up @@ -433,7 +435,7 @@ pub(crate) fn secure_release_cache(install_root: &Path, dir: &Path) {
}
#[cfg(not(unix))]
{
let _ = (install_root, dir);
super::windows_acl::secure_release_cache(install_root, dir);
}
}

Expand Down
31 changes: 15 additions & 16 deletions crates/tinybus/src/module/host.rs
Original file line number Diff line number Diff line change
Expand Up @@ -2348,7 +2348,7 @@ fn trusted_installer_sid() -> Vec<u32> {
}

#[cfg(windows)]
fn windows_path_grants_untrusted_write(path: &Path) -> Result<bool> {
pub(super) fn windows_path_grants_untrusted_write(path: &Path) -> Result<bool> {
use std::ffi::c_void;
use std::os::windows::ffi::OsStrExt;

Expand Down Expand Up @@ -2417,15 +2417,11 @@ fn windows_path_grants_untrusted_write(path: &Path) -> Result<bool> {
const SE_FILE_OBJECT: u32 = 1;
const OWNER_SECURITY_INFORMATION: u32 = 0x1;
const DACL_SECURITY_INFORMATION: u32 = 0x4;
const ACCESS_ALLOWED_ACE_TYPE: u8 = 0;
const INHERIT_ONLY_ACE: u8 = 0x08;
const WIN_CREATOR_OWNER_SID: u32 = 3;
const WIN_LOCAL_SYSTEM_SID: u32 = 22;
const WIN_BUILTIN_ADMINISTRATORS_SID: u32 = 26;
const TOKEN_QUERY: u32 = 0x8;
const TOKEN_USER: u32 = 1;
const WRITE_MASK: u32 =
0x2 | 0x4 | 0x10 | 0x100 | 0x1_0000 | 0x4_0000 | 0x8_0000 | 0x1000_0000 | 0x4000_0000;

let mut wide = path
.as_os_str()
Expand Down Expand Up @@ -2546,25 +2542,28 @@ fn windows_path_grants_untrusted_write(path: &Path) -> Result<bool> {
return true;
}
let ace = ace.cast::<AccessAllowedAce>();
// An inherit-only ACE grants nothing on this object; it only
// seeds the ACL of children created later, and every module file
// is checked against its own ACL before it is loaded.
if unsafe { (*ace).header.ace_type } != ACCESS_ALLOWED_ACE_TYPE
|| unsafe { (*ace).header.ace_flags } & INHERIT_ONLY_ACE != 0
|| unsafe { (*ace).mask } & WRITE_MASK == 0
{
continue;
}
let ace_type = unsafe { (*ace).header.ace_type };
let ace_flags = unsafe { (*ace).header.ace_flags };
let mask = unsafe { (*ace).mask };
// Whether an ACE counts is `windows_acl::ace_grants_untrusted_write`:
// inherit-only entries seed children (each module file is checked
// against its own ACL), and entries without a write right or that
// are not allow-ACEs grant nothing here.
let sid = unsafe { std::ptr::addr_of!((*ace).sid_start) }.cast();
let trusted = unsafe { EqualSid(sid, user_sid) } != 0
let principal_trusted = unsafe { EqualSid(sid, user_sid) } != 0
|| unsafe { EqualSid(sid, admin_sid.as_ptr().cast()) } != 0
|| unsafe { EqualSid(sid, system_sid.as_ptr().cast()) } != 0
|| unsafe { EqualSid(sid, trusted_installer) } != 0
// CREATOR OWNER is an inheritable placeholder for the owner
// of each child. Check each module file's actual owner and
// ACL too, before accepting this ACE on its parent directory.
|| unsafe { EqualSid(sid, creator_owner_sid.as_ptr().cast()) } != 0;
if !trusted {
if super::windows_acl::ace_grants_untrusted_write(
ace_type,
ace_flags,
mask,
principal_trusted,
) {
return true;
}
}
Expand Down
2 changes: 2 additions & 0 deletions crates/tinybus/src/module/mod.rs
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,8 @@ mod remembered_hash;
mod resolve;
#[cfg(feature = "modules")]
mod transport;
#[cfg(feature = "modules")]
mod windows_acl;

#[cfg(feature = "modules")]
pub use cache::{artifact_dir, is_safe_path_component, prune_stale_versions};
Expand Down
Loading
Loading