Skip to content

fix(posixfs): refuse paths outside the configured posixfs root - #3664

Open
NickWalters wants to merge 1 commit into
opencloud-eu:mainfrom
NickWalters:fix/posixfs-check-storage-root
Open

NickWalters wants to merge 1 commit into
opencloud-eu:mainfrom
NickWalters:fix/posixfs-check-storage-root

Conversation

@NickWalters

@NickWalters NickWalters commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Fixes #3663.

posixfs consistency and posixfs scan take a path, find the storage it is in, and then build their ignore rules (and for scan, the driver) from the configured root. The ignore rules compare plain path strings. So when a path is in another storage, reaches the storage through a symlink, or (for consistency) is relative, the internal directories .Trash, .oc-nodes and .oc-tmp aren't recognised, and consistency writes node attributes onto them.

The relative case hits even with the right root configured. On 8.1.0, cd /tmp/ocA && STORAGE_USERS_POSIX_ROOT=/tmp/ocA opencloud posixfs consistency users/space1 writes user.oc.parentid and user.oc.name onto .Trash.

This change:

  • makes consistency's paths absolute, as scan already does
  • adds checkStorageRoot, which both commands call before they do anything. It refuses a path that isn't under the configured root as spelled in the configuration, for example (real output):
'/tmp/ocL/users/space1' is not under the configured posixfs root '/tmp/ocA' (it looks like part of a storage at '/tmp/ocL'). Pass a path under '/tmp/ocA', or set STORAGE_USERS_POSIX_ROOT to the storage you mean

Paths outside any storage go on to the existing error handling, as before. posixfs index takes an explicit --root and doesn't need the check.

Tests

TestCheckStorageRoot has 10 cases. They cover the configured storage and its root, a path outside any storage, another storage, a later bad path in a list, a storage nested inside the configured one, a symlink on either side, a relative path, and a configured root that doesn't exist.

I also built the binary and ran it in a scratch storage with a symlink to it. A symlinked root or path is refused and nothing is written. A relative path is made absolute and checked without writing to the internal directories. 8.1.0 writes onto .Trash in the relative case.

The branch is based on an older main, because my token can't sync the fork (an upstream workflow file changed in between). It cherry-picks cleanly onto current main, and the test and go vet pass there.

@codacy-production

codacy-production Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 15 complexity

Metric Results
Complexity 15

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

`posixfs consistency` and `posixfs scan` take a path, find the storage it
belongs to, and then build their ignore rules (and for scan, the driver)
from the configured root. The ignore rules compare plain path strings.
When the path is in another storage, reaches the storage through a
symlink, or (for consistency) is relative, the internal directories
.Trash, .oc-nodes and .oc-tmp are not recognised, and consistency writes
node attributes onto them.

Make consistency's paths absolute like scan already does, and check that
every path is under the configured root as spelled in the configuration.
@NickWalters
NickWalters force-pushed the fix/posixfs-check-storage-root branch from c15f0be to 8fc132e Compare October 6, 2026 06:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

posixfs consistency writes attributes onto .Trash, .oc-nodes and .oc-tmp when the posix root isn't configured

1 participant