fix(win32): try to set ACLs without propagating them#9157
Merged
Conversation
Member
Author
|
/backport to stable-4.0 |
apparently `SetFileSecurity` did not do that, unlike its "new" (since Windows 2000) replacement `SetSecurityInfo`/`SetNamedSecurityInfo`. [`SetSecurityInfo` should not perform the propagation if the handle is opened with an access mask value of `MAXIMUM_ALLOWED`][0], so let's give that a try. also removed the restriction on the FILE_WRITE_ATTRIBUTES permission so that `FileSystem::setFileReadOnly` has an easier time modifying the basic attribute [0]: https://learn.microsoft.com/en-us/windows/win32/api/aclapi/nf-aclapi-setsecurityinfo#:~:text=MAXIMUM_ALLOWED Fixes #9136 Signed-off-by: Jyrki Gadinger <nilsding@nilsding.org>
Signed-off-by: Jyrki Gadinger <nilsding@nilsding.org>
65f1e6f to
102238d
Compare
mgallien
approved these changes
Dec 1, 2025
|
Artifact containing the AppImage: nextcloud-appimage-pr-9157.zip Digest: To test this change/fix you can download the above artifact file, unzip it, and run it. Please make sure to quit your existing Nextcloud app and backup your data. |
|
8 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.




apparently
SetFileSecuritydid not propagate ACLs, unlike its "new" replacementSetSecurityInfo/SetNamedSecurityInfo.SetSecurityInfoshould not perform the propagation if the handle is opened with an access mask value ofMAXIMUM_ALLOWED, so let's give that a try.also removed the restriction on the FILE_WRITE_ATTRIBUTES permission so that
FileSystem::setFileReadOnlyhas an easier time modifying the basic attribute