Skip to content

Conversation

@iceweasel-oai
Copy link
Contributor

Fix world-writable audit false positives by expanding generic permissions with MapGenericMask and then checking only concrete write bits. The earlier check looked for FILE_GENERIC_WRITE/generic masks directly, which shares bits with read permissions and could flag an Everyone read ACE as writable.

@iceweasel-oai iceweasel-oai merged commit 2fde03b into main Nov 19, 2025
44 of 46 checks passed
@iceweasel-oai iceweasel-oai deleted the dev/iceweasel/world-writable-over-reporting branch November 19, 2025 21:59
@github-actions github-actions bot locked and limited conversation to collaborators Nov 19, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants