Refuse fetch writes through a symlink in the destination (closes #86)
check / check (push) Successful in 1m10s
check / check (push) Successful in 1m10s
sanitizePath checks manifest paths only as text, so a symlink already inside the destination directory could send fetch's writes outside it. checkNoSymlinks now looks at each existing part of a path with os.Lstat and refuses the path if any part is a symlink, wherever it points. fetch runs it immediately before each write: creating the parent directories, creating the temp file, and renaming it into place. The new test puts such a symlink at each of those three places, and once inside a plain directory, and checks that the fetch fails and nothing outside changes. The G304 comment now states what holds. A symlink swapped in between a check and its write is not caught; os.Root closes that once the Go version is raised. Model: opus-5-5
This commit was merged in pull request #114.
This commit is contained in:
@@ -24,6 +24,10 @@ only thing left of the `chore/align-repo-policies` branch is the list below.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-03: `fetch` refuses any manifest path that runs through a symlink
|
||||
already in the destination directory, checked before each of its writes
|
||||
(directories, temp file, rename), so such a symlink cannot send a write
|
||||
outside it (#86)
|
||||
- 2026-10-02: a plain `docker build .` of a clone now stamps the tag or short
|
||||
commit into `mfer version` instead of nothing: `.dockerignore` sends `.git`
|
||||
(not `.git/config`), and the build stage takes the `VERSION` build argument,
|
||||
|
||||
Reference in New Issue
Block a user