fix: harden workspace preprocessing contract

This commit is contained in:
2026-08-11 00:59:15 +02:00
parent 9df7c38069
commit 05a6e8cc2d
11 changed files with 494 additions and 32 deletions
+4 -4
View File
@@ -90,7 +90,7 @@ func writeCanonicalExclusive(path string, contents []byte, mode fs.FileMode) err
if err != nil {
return ErrUnsafeFile
}
defer unix.Close(dir)
defer func() { unix.Close(dir) }()
for _, component := range components[:len(components)-1] {
next, err := unix.Openat(dir, component, unix.O_RDONLY|unix.O_DIRECTORY|unix.O_CLOEXEC|unix.O_NOFOLLOW, 0)
if err != nil {
@@ -147,7 +147,7 @@ func validateCanonicalOutputPath(path string) error {
if err != nil {
return ErrUnsafeFile
}
defer unix.Close(dir)
defer func() { unix.Close(dir) }()
for _, component := range components[:len(components)-1] {
next, err := unix.Openat(dir, component, unix.O_RDONLY|unix.O_DIRECTORY|unix.O_CLOEXEC|unix.O_NOFOLLOW, 0)
if err != nil {
@@ -173,7 +173,7 @@ func recheckUnixParents(components []string, retained []int) bool {
if err != nil {
return false
}
defer unix.Close(dir)
defer func() { unix.Close(dir) }()
for i, component := range components[:len(components)-1] {
next, e := unix.Openat(dir, component, unix.O_RDONLY|unix.O_DIRECTORY|unix.O_CLOEXEC|unix.O_NOFOLLOW, 0)
if e != nil {
@@ -195,7 +195,7 @@ func recheckUnixParentPath(components []string, retained int) bool {
if err != nil {
return false
}
defer unix.Close(dir)
defer func() { unix.Close(dir) }()
for _, component := range components {
next, e := unix.Openat(dir, component, unix.O_RDONLY|unix.O_DIRECTORY|unix.O_CLOEXEC|unix.O_NOFOLLOW, 0)
if e != nil {