Skip to content

cap-primitives: Keep a NUL after the name CreateFileAtW passes to NtCreateFile. - #430

Open
dongs0104 wants to merge 1 commit into
sunfishcode:mainfrom
dongs0104:windows-nul-terminate-name
Open

dongs0104 wants to merge 1 commit into
sunfishcode:mainfrom
dongs0104:windows-nul-terminate-name

Conversation

@dongs0104

@dongs0104 dongs0104 commented Oct 3, 2026 •

Copy link
Copy Markdown

CreateFileAtW passes NtCreateFile a UNICODE_STRING built from an unterminated slice. That is valid, but Win32 paths (RtlInitUnicodeString, RtlDosPathNameToNtPathName_U) always leave a NUL right after the name, and some third-party endpoint-security products hook NtCreateFile and copy ObjectName->Buffer up to a NUL instead of Length bytes. With cap-std's directory-relative opens such a hook reads past the allocation, and the process crashes when the next page is inaccessible. We hit this in production on Windows machines with such a product installed, and carrying this change as a patch fixed it.

Make CreateFileAtW take a NUL-terminated slice, with Length excluding the terminator and MaximumLength including it, as RtlInitUnicodeString does. open_at, its only caller, now appends the NUL once for both the CreateFileW and CreateFileAtW branches. The name the kernel sees is unchanged.

…NtCreateFile`.

`CreateFileAtW` passes `NtCreateFile` a `UNICODE_STRING` built from an unterminated slice. That is valid, but Win32 paths (`RtlInitUnicodeString`, `RtlDosPathNameToNtPathName_U`) always leave a NUL right after the name, and some third-party endpoint-security products hook `NtCreateFile` and copy `ObjectName->Buffer` up to a NUL instead of `Length` bytes. With cap-std's directory-relative opens such a hook reads past the allocation, and the process crashes when the next page is inaccessible. We hit this in production on Windows machines with such a product installed, and carrying this change as a patch fixed it.

Make `CreateFileAtW` take a NUL-terminated slice, with `Length` excluding the terminator and `MaximumLength` including it, as `RtlInitUnicodeString` does. `open_at`, its only caller, now appends the NUL once for both the `CreateFileW` and `CreateFileAtW` branches. The name the kernel sees is unchanged.
@dongs0104
dongs0104 force-pushed the windows-nul-terminate-name branch from 6826a97 to d73b15f Compare October 3, 2026 08:11
@dongs0104 dongs0104 changed the title windows: keep a NUL after the name CreateFileAtW passes to NtCreateFile cap-primitives: Keep a NUL after the name CreateFileAtW passes to NtCreateFile. Oct 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant