cosmopolitan/libc/calls/ntaccesscheck.c

89 lines
4.3 KiB
C
Raw Normal View History

2020-06-15 14:18:57 +00:00
/*-*- mode:c;indent-tabs-mode:nil;c-basic-offset:2;tab-width:8;coding:utf-8 -*-│
vi: set net ft=c ts=2 sts=2 sw=2 fenc=utf-8 :vi
Copyright 2020 Justine Alexandra Roberts Tunney
This program is free software; you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation; version 2 of the License.
This program is distributed in the hope that it will be useful, but
WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program; if not, write to the Free Software
Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
02110-1301 USA
*/
2020-09-03 12:44:37 +00:00
#include "libc/calls/calls.h"
#include "libc/calls/internal.h"
2020-06-15 14:18:57 +00:00
#include "libc/nt/enum/accessmask.h"
#include "libc/nt/enum/securityinformation.h"
#include "libc/nt/errors.h"
#include "libc/nt/files.h"
#include "libc/nt/runtime.h"
#include "libc/nt/struct/genericmapping.h"
#include "libc/nt/struct/privilegeset.h"
#include "libc/nt/struct/securitydescriptor.h"
#include "libc/runtime/runtime.h"
#include "libc/str/str.h"
#include "libc/sysv/consts/ok.h"
/**
2020-09-03 12:44:37 +00:00
* Asks Microsoft if we're authorized to use a folder or file.
*
* Implementation Details: MSDN documentation imposes no limit on the
* internal size of SECURITY_DESCRIPTOR, which we are responsible for
* allocating. We've selected 1024 which shall hopefully be adequate.
2020-06-15 14:18:57 +00:00
*
* @param flags can have R_OK, W_OK, X_OK, etc.
* @return 0 if authorized, or -1 w/ errno
2020-09-03 12:44:37 +00:00
* @kudos Aaron Ballman for teaching this
2020-06-15 14:18:57 +00:00
* @see libc/sysv/consts.sh
*/
textwindows int ntaccesscheck(const char16_t *pathname, uint32_t flags) {
int rc;
bool32 result;
2020-09-03 12:44:37 +00:00
struct NtGenericMapping mapping;
struct NtPrivilegeSet privileges;
2020-06-15 14:18:57 +00:00
int64_t hToken, hImpersonatedToken;
uint32_t secsize, granted, privsize;
2020-09-03 12:44:37 +00:00
union NtSecurityDescriptorLol {
struct NtSecurityDescriptor s;
char b[1024];
} security;
2020-06-15 14:18:57 +00:00
granted = 0;
result = false;
secsize = sizeof(security);
privsize = sizeof(privileges);
memset(&privileges, 0, sizeof(privileges));
mapping.GenericRead = kNtFileGenericRead;
mapping.GenericWrite = kNtFileGenericWrite;
mapping.GenericExecute = kNtFileGenericExecute;
mapping.GenericAll = kNtFileAllAccess;
MapGenericMask(&flags, &mapping);
hImpersonatedToken = hToken = -1;
2020-09-03 12:44:37 +00:00
if (GetFileSecurity(pathname,
kNtOwnerSecurityInformation |
kNtGroupSecurityInformation |
kNtDaclSecurityInformation,
&security.s, 0, &secsize) &&
2020-06-15 14:18:57 +00:00
OpenProcessToken(GetCurrentProcess(),
kNtTokenImpersonate | kNtTokenQuery | kNtTokenDuplicate |
kNtStandardRightsRead,
&hToken) &&
DuplicateToken(hToken, kNtSecurityImpersonation, &hImpersonatedToken) &&
2020-09-03 12:44:37 +00:00
AccessCheck(&security.s, hImpersonatedToken, flags, &mapping, &privileges,
2020-06-15 14:18:57 +00:00
&privsize, &granted, &result) &&
(result || flags == F_OK)) {
rc = 0;
} else {
rc = winerr();
}
close(hImpersonatedToken);
close(hToken);
return rc;
}