fix(auth): make diagnostics bounded and portable
This commit is contained in:
@@ -23,11 +23,12 @@ const maximumPrivateDirectoryPageScanEntries = 16384
|
||||
// EnsurePrivateDirectory creates only the final canonical directory with the platform's
|
||||
// owner-only protection, or validates an existing directory has that protection.
|
||||
func EnsurePrivateDirectory(path string) error {
|
||||
if err := ValidateCanonicalPath(path); err != nil {
|
||||
exists, err := PreflightPrivateDirectory(path)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
if err := requireCanonicalDirectory(filepath.Dir(path)); err != nil {
|
||||
return err
|
||||
if exists {
|
||||
return ValidatePrivateDirectory(path)
|
||||
}
|
||||
if err := createPrivateDirectory(path); err != nil && !errors.Is(err, os.ErrExist) {
|
||||
return ErrUnsafeFile
|
||||
@@ -35,6 +36,20 @@ func EnsurePrivateDirectory(path string) error {
|
||||
return ValidatePrivateDirectory(path)
|
||||
}
|
||||
|
||||
// PreflightPrivateDirectory validates every existing path component without following links or
|
||||
// reparse points. A missing final component is safe to create later; missing intermediates are not.
|
||||
// This function never creates, removes, chmods, or changes an ACL.
|
||||
func PreflightPrivateDirectory(path string) (bool, error) {
|
||||
if err := ValidateCanonicalPath(path); err != nil {
|
||||
return false, ErrUnsafeFile
|
||||
}
|
||||
exists, err := preflightPrivateDirectory(path)
|
||||
if err != nil {
|
||||
return false, ErrUnsafeFile
|
||||
}
|
||||
return exists, nil
|
||||
}
|
||||
|
||||
// ValidateCanonicalPath rejects relative or lexically non-canonical paths before they are opened.
|
||||
func ValidateCanonicalPath(path string) error {
|
||||
if !filepath.IsAbs(path) || filepath.Clean(path) != path || strings.Contains(path, string(filepath.Separator)+".."+string(filepath.Separator)) {
|
||||
|
||||
Reference in New Issue
Block a user