Repository navigation
fix(posixfs): refuse paths outside the configured posixfs root - #3664
Open
NickWalters wants to merge 1 commit into
Open
NickWalters wants to merge 1 commit into
NickWalters wants to merge 1 commit into
Conversation
Up to standards ✅🟢 Issues
|
| Metric | Results |
|---|---|
| Complexity | 15 |
NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.
`posixfs consistency` and `posixfs scan` take a path, find the storage it belongs to, and then build their ignore rules (and for scan, the driver) from the configured root. The ignore rules compare plain path strings. When the path is in another storage, reaches the storage through a symlink, or (for consistency) is relative, the internal directories .Trash, .oc-nodes and .oc-tmp are not recognised, and consistency writes node attributes onto them. Make consistency's paths absolute like scan already does, and check that every path is under the configured root as spelled in the configuration.
NickWalters
force-pushed
the
fix/posixfs-check-storage-root
branch
from
October 6, 2026 06:13
c15f0be to
8fc132e
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #3663.
posixfs consistencyandposixfs scantake a path, find the storage it is in, and then build their ignore rules (and forscan, the driver) from the configured root. The ignore rules compare plain path strings. So when a path is in another storage, reaches the storage through a symlink, or (forconsistency) is relative, the internal directories.Trash,.oc-nodesand.oc-tmparen't recognised, andconsistencywrites node attributes onto them.The relative case hits even with the right root configured. On 8.1.0,
cd /tmp/ocA && STORAGE_USERS_POSIX_ROOT=/tmp/ocA opencloud posixfs consistency users/space1writesuser.oc.parentidanduser.oc.nameonto.Trash.This change:
consistency's paths absolute, asscanalready doescheckStorageRoot, which both commands call before they do anything. It refuses a path that isn't under the configured root as spelled in the configuration, for example (real output):Paths outside any storage go on to the existing error handling, as before.
posixfs indextakes an explicit--rootand doesn't need the check.Tests
TestCheckStorageRoothas 10 cases. They cover the configured storage and its root, a path outside any storage, another storage, a later bad path in a list, a storage nested inside the configured one, a symlink on either side, a relative path, and a configured root that doesn't exist.I also built the binary and ran it in a scratch storage with a symlink to it. A symlinked root or path is refused and nothing is written. A relative path is made absolute and checked without writing to the internal directories. 8.1.0 writes onto
.Trashin the relative case.The branch is based on an older main, because my token can't sync the fork (an upstream workflow file changed in between). It cherry-picks cleanly onto current main, and the test and
go vetpass there.