fix(auth): make diagnostics bounded and portable

This commit is contained in:
2026-08-17 12:19:19 +02:00
parent 7cfbee36fa
commit be1724890a
23 changed files with 1088 additions and 116 deletions
+18 -3
View File
@@ -23,11 +23,12 @@ const maximumPrivateDirectoryPageScanEntries = 16384
// EnsurePrivateDirectory creates only the final canonical directory with the platform's
// owner-only protection, or validates an existing directory has that protection.
func EnsurePrivateDirectory(path string) error {
if err := ValidateCanonicalPath(path); err != nil {
exists, err := PreflightPrivateDirectory(path)
if err != nil {
return err
}
if err := requireCanonicalDirectory(filepath.Dir(path)); err != nil {
return err
if exists {
return ValidatePrivateDirectory(path)
}
if err := createPrivateDirectory(path); err != nil && !errors.Is(err, os.ErrExist) {
return ErrUnsafeFile
@@ -35,6 +36,20 @@ func EnsurePrivateDirectory(path string) error {
return ValidatePrivateDirectory(path)
}
// PreflightPrivateDirectory validates every existing path component without following links or
// reparse points. A missing final component is safe to create later; missing intermediates are not.
// This function never creates, removes, chmods, or changes an ACL.
func PreflightPrivateDirectory(path string) (bool, error) {
if err := ValidateCanonicalPath(path); err != nil {
return false, ErrUnsafeFile
}
exists, err := preflightPrivateDirectory(path)
if err != nil {
return false, ErrUnsafeFile
}
return exists, nil
}
// ValidateCanonicalPath rejects relative or lexically non-canonical paths before they are opened.
func ValidateCanonicalPath(path string) error {
if !filepath.IsAbs(path) || filepath.Clean(path) != path || strings.Contains(path, string(filepath.Separator)+".."+string(filepath.Separator)) {