Commit a67bbb0
Resolve the name a write lands on, not only the directory above it (#74)
* Resolve the name a write lands on, not only the directory above it
`resolvePath` resolved `dirname(target)` for a write and handed back the lexical
target, so a symlink at the last component was followed by `writeFile`. A read
through the identical link was already refused; the write side was the asymmetry.
A link at `notes.txt` pointing outside has no `..`, is not absolute, and sits
directly in the workspace, so it passed all three layers and the bytes landed
outside the volume.
The walk uses `lstat` and `readlink` rather than `realpath`, because `realpath`
throws on a dangling link while `writeFile` creates its destination regardless,
so that shape escaped through the failure path rather than the success one. Hops
are bounded, so a cycle is refused instead of surfacing an `ELOOP` from the write.
Confining rather than forbidding, as on the read side: a link pointing back
inside the workspace keeps working.
The escape is not the main cost, because a Bot holding `run_command` can write
outside directly. The cost is that the gateway decides and writes the audit row
in another process, from the path as it was asked for, so a rule written for
`credentials/` never sees the file that is written and the trail names a file
nothing touched.
* Resolve where the link lands before checking it, not after
Reapplying this after a rebase dropped it.
The leaf walk checked the raw destination first and canonicalised the directory
holding it second. `root` is itself a real path, so a destination that still runs
through a symlinked ancestor fails the lexical comparison even when it points
straight back into the workspace. Anywhere /tmp is a link to /private/tmp, which
is every macOS machine and no Linux CI runner, a legitimate in-workspace link is
refused, and that asymmetry is why this branch's own "points back inside still
works" test passes in CI and fails on a developer's machine.
Resolving the holder first fixes it, and the destination is rebuilt from the
resolved directory so what the function returns is the path that will actually be
written rather than the one that was asked for. It failed safe either way, so this
was a correctness bug rather than a hole.
---------
Co-authored-by: David McKay <davidmckayv@users.noreply.github.com>1 parent 0a55adc commit a67bbb0
3 files changed
Lines changed: 178 additions & 8 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
159 | 159 | | |
160 | 160 | | |
161 | 161 | | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
162 | 169 | | |
163 | 170 | | |
164 | 171 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
14 | 14 | | |
15 | 15 | | |
16 | 16 | | |
17 | | - | |
18 | | - | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
19 | 20 | | |
20 | 21 | | |
21 | 22 | | |
22 | 23 | | |
23 | 24 | | |
| 25 | + | |
24 | 26 | | |
25 | 27 | | |
26 | 28 | | |
| 29 | + | |
27 | 30 | | |
28 | 31 | | |
29 | 32 | | |
30 | 33 | | |
31 | | - | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
32 | 43 | | |
33 | 44 | | |
34 | 45 | | |
| |||
131 | 142 | | |
132 | 143 | | |
133 | 144 | | |
134 | | - | |
135 | | - | |
136 | | - | |
137 | | - | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
| 157 | + | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
| 185 | + | |
| 186 | + | |
138 | 187 | | |
139 | 188 | | |
140 | 189 | | |
| |||
277 | 326 | | |
278 | 327 | | |
279 | 328 | | |
| 329 | + | |
| 330 | + | |
| 331 | + | |
| 332 | + | |
| 333 | + | |
| 334 | + | |
| 335 | + | |
| 336 | + | |
| 337 | + | |
| 338 | + | |
| 339 | + | |
| 340 | + | |
| 341 | + | |
| 342 | + | |
| 343 | + | |
| 344 | + | |
| 345 | + | |
| 346 | + | |
| 347 | + | |
| 348 | + | |
| 349 | + | |
| 350 | + | |
| 351 | + | |
| 352 | + | |
| 353 | + | |
| 354 | + | |
| 355 | + | |
| 356 | + | |
| 357 | + | |
| 358 | + | |
| 359 | + | |
| 360 | + | |
| 361 | + | |
| 362 | + | |
| 363 | + | |
| 364 | + | |
| 365 | + | |
| 366 | + | |
| 367 | + | |
280 | 368 | | |
281 | 369 | | |
282 | 370 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | | - | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
3 | 10 | | |
4 | 11 | | |
5 | 12 | | |
| |||
206 | 213 | | |
207 | 214 | | |
208 | 215 | | |
| 216 | + | |
| 217 | + | |
| 218 | + | |
| 219 | + | |
| 220 | + | |
| 221 | + | |
| 222 | + | |
| 223 | + | |
| 224 | + | |
| 225 | + | |
| 226 | + | |
| 227 | + | |
| 228 | + | |
| 229 | + | |
| 230 | + | |
| 231 | + | |
| 232 | + | |
| 233 | + | |
| 234 | + | |
| 235 | + | |
| 236 | + | |
| 237 | + | |
| 238 | + | |
| 239 | + | |
| 240 | + | |
| 241 | + | |
| 242 | + | |
| 243 | + | |
| 244 | + | |
| 245 | + | |
| 246 | + | |
| 247 | + | |
| 248 | + | |
| 249 | + | |
| 250 | + | |
| 251 | + | |
| 252 | + | |
| 253 | + | |
| 254 | + | |
| 255 | + | |
| 256 | + | |
| 257 | + | |
| 258 | + | |
| 259 | + | |
| 260 | + | |
| 261 | + | |
| 262 | + | |
| 263 | + | |
| 264 | + | |
| 265 | + | |
| 266 | + | |
| 267 | + | |
| 268 | + | |
| 269 | + | |
| 270 | + | |
| 271 | + | |
| 272 | + | |
| 273 | + | |
| 274 | + | |
| 275 | + | |
| 276 | + | |
| 277 | + | |
| 278 | + | |
| 279 | + | |
| 280 | + | |
| 281 | + | |
| 282 | + | |
| 283 | + | |
209 | 284 | | |
210 | 285 | | |
211 | 286 | | |
| |||
0 commit comments