Measure AppContainer file quota ownership
This commit is contained in:
@@ -379,6 +379,36 @@ static bool IsSmokeResult(const std::wstring& path) {
|
||||
return valid && sawDot;
|
||||
}
|
||||
|
||||
static bool FileOwnerMatchesSid(const std::wstring& path, PSID expectedSid) {
|
||||
PSID ownerSid = nullptr;
|
||||
PSECURITY_DESCRIPTOR descriptor = nullptr;
|
||||
DWORD error = GetNamedSecurityInfoW(
|
||||
const_cast<LPWSTR>(path.c_str()), SE_FILE_OBJECT, OWNER_SECURITY_INFORMATION,
|
||||
&ownerSid, nullptr, nullptr, nullptr, &descriptor);
|
||||
const bool matches = error == ERROR_SUCCESS && ownerSid && expectedSid &&
|
||||
EqualSid(ownerSid, expectedSid);
|
||||
if (descriptor) LocalFree(descriptor);
|
||||
return matches;
|
||||
}
|
||||
|
||||
static bool FileOwnerMatchesCurrentUser(const std::wstring& path) {
|
||||
HANDLE token = nullptr;
|
||||
if (!OpenProcessToken(GetCurrentProcess(), TOKEN_QUERY, &token)) return false;
|
||||
DWORD required = 0;
|
||||
GetTokenInformation(token, TokenUser, nullptr, 0, &required);
|
||||
if (GetLastError() != ERROR_INSUFFICIENT_BUFFER || required == 0) {
|
||||
CloseHandle(token);
|
||||
return false;
|
||||
}
|
||||
std::vector<unsigned char> storage(required);
|
||||
const bool read = GetTokenInformation(
|
||||
token, TokenUser, storage.data(), required, &required) != FALSE;
|
||||
CloseHandle(token);
|
||||
if (!read) return false;
|
||||
auto* user = reinterpret_cast<TOKEN_USER*>(storage.data());
|
||||
return FileOwnerMatchesSid(path, user->User.Sid);
|
||||
}
|
||||
|
||||
static constexpr ULONGLONG kMaxAppContainerDataBytes = 128ull * 1024 * 1024;
|
||||
|
||||
static bool MeasureDirectoryBytes(
|
||||
@@ -876,6 +906,11 @@ int wmain() {
|
||||
bool stagedInputRoundTripMatches = stagedInputCopied && FilesMatch(
|
||||
L"README.md", stagedCopyPath);
|
||||
bool pythonVersionVisible = IsSmokeResult(pythonVersionPath);
|
||||
const std::wstring pythonResultPath = projectSnapshotPath +
|
||||
L"\\scripts\\execution-result.txt";
|
||||
const bool pythonResultOwnedByAppContainer =
|
||||
FileOwnerMatchesSid(pythonResultPath, appContainerSid);
|
||||
const bool pythonResultOwnedByHostUser = FileOwnerMatchesCurrentUser(pythonResultPath);
|
||||
|
||||
if (job) CloseHandle(job);
|
||||
if (appContainerFolder) CoTaskMemFree(appContainerFolder);
|
||||
@@ -905,6 +940,9 @@ int wmain() {
|
||||
pythonRuntimeCopied ? L"true" : L"false", pythonRuntimeBytes,
|
||||
pythonRuntimeFiles, entryScriptReady ? L"true" : L"false",
|
||||
pythonRunResult, pythonVersionVisible ? L"true" : L"false");
|
||||
wprintf(L"python_result_owner_is_appcontainer_sid=%s\npython_result_owner_is_host_user_sid=%s\n",
|
||||
pythonResultOwnedByAppContainer ? L"true" : L"false",
|
||||
pythonResultOwnedByHostUser ? L"true" : L"false");
|
||||
std::vector<wchar_t> pythonOutputWide(pythonOutput.size() + 1);
|
||||
bool pythonOutputValidUtf8 = true;
|
||||
if (!pythonOutput.empty()) {
|
||||
|
||||
Reference in New Issue
Block a user