mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
fix(agent/agentcontext): canonicalize scan root in symlink boundary check (#26175)
This commit is contained in:
@@ -368,7 +368,16 @@ func resolveReadTarget(path string, info fs.FileInfo, scanRoot string) (readPath
|
||||
if err != nil {
|
||||
return "", nil, false, StatusUnreadable, fmt.Sprintf("symlink resolve: %v", err)
|
||||
}
|
||||
// Canonicalize scanRoot symmetrically with the target so the
|
||||
// boundary check survives platform-level symlinks in the scan
|
||||
// root prefix. macOS, for example, exposes /var as a symlink
|
||||
// to /private/var; EvalSymlinks on the target produces a
|
||||
// /private/var path while the caller's scanRoot may still be
|
||||
// /var, which would incorrectly trip the prefix check.
|
||||
rootClean := filepath.Clean(scanRoot)
|
||||
if resolved, err := filepath.EvalSymlinks(rootClean); err == nil {
|
||||
rootClean = resolved
|
||||
}
|
||||
if !pathHasPrefix(target, rootClean) {
|
||||
return "", nil, false, StatusInvalid, fmt.Sprintf("symlink target %q escapes scan root %q", target, scanRoot)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user