fix: harden generated Windows wrapper ACLs

This commit is contained in:
2026-09-06 14:04:51 +00:00
parent 4e75524efa
commit 09e8a9df9e
2 changed files with 60 additions and 7 deletions
@@ -252,7 +252,7 @@ func (process *execProcess) startReaders(maxChunk uint64, remove func()) {
}()
}
func materializeWrapper(directory string, wrapper Wrapper, now time.Time) (string, func(), error) {
func materializeWrapper(directory string, wrapper Wrapper, now time.Time, secure func(string) error) (string, func(), error) {
if directory == "" {
return "", nil, ErrInvalidWorkingDirectory
}
@@ -272,6 +272,12 @@ func materializeWrapper(directory string, wrapper Wrapper, now time.Time) (strin
cleanup()
return "", nil, err
}
if secure != nil {
if err := secure(temporaryName); err != nil {
cleanup()
return "", nil, err
}
}
if _, err := temporary.Write(wrapper.Bytes); err != nil {
cleanup()
return "", nil, err
@@ -379,7 +385,7 @@ func (manager *execSupervisor) startPortable(ctx context.Context, spec superviso
if err != nil {
return nil, err
}
wrapperPath, cleanup, err = materializeWrapper(spec.WorkingDirectory, wrapper, manager.options.Now())
wrapperPath, cleanup, err = materializeWrapper(spec.WorkingDirectory, wrapper, manager.options.Now(), nil)
if err != nil {
return nil, err
}