fix(thothctl): fail closed on partial secret loads
This commit is contained in:
@@ -18,10 +18,6 @@ var ErrUnsafeFile = errors.New("unsafe file")
|
||||
// private stages before retrying; it is never a blind-retry-safe failure.
|
||||
var ErrIndeterminateFile = errors.New("indeterminate file state")
|
||||
|
||||
// beforeBoundedRead is an internal test seam used to deterministically suspend
|
||||
// a read between opening the file and resolving its final pathname.
|
||||
var beforeBoundedRead func()
|
||||
|
||||
// ValidateCanonicalPath rejects relative or lexically non-canonical paths before they are opened.
|
||||
func ValidateCanonicalPath(path string) error {
|
||||
if !filepath.IsAbs(path) || filepath.Clean(path) != path || strings.Contains(path, string(filepath.Separator)+".."+string(filepath.Separator)) {
|
||||
@@ -33,7 +29,7 @@ func ValidateCanonicalPath(path string) error {
|
||||
return nil
|
||||
}
|
||||
|
||||
func readBoundedRegularFile(file *os.File, maximum int64) ([]byte, error) {
|
||||
func readBoundedRegularFile(file *os.File, maximum int64, before func()) ([]byte, error) {
|
||||
if maximum < 0 || maximum == int64(^uint64(0)>>1) {
|
||||
return nil, ErrUnsafeFile
|
||||
}
|
||||
@@ -41,8 +37,8 @@ func readBoundedRegularFile(file *os.File, maximum int64) ([]byte, error) {
|
||||
if err != nil || !info.Mode().IsRegular() {
|
||||
return nil, ErrUnsafeFile
|
||||
}
|
||||
if beforeBoundedRead != nil {
|
||||
beforeBoundedRead()
|
||||
if before != nil {
|
||||
before()
|
||||
}
|
||||
contents, err := io.ReadAll(io.LimitReader(file, maximum+1))
|
||||
if err != nil || int64(len(contents)) > maximum {
|
||||
|
||||
Reference in New Issue
Block a user