mirror of
https://github.com/usestrix/strix.git
synced 2026-10-08 03:08:08 +00:00
fix: use strict child check in path containment — reject clone_path == temp_dir
The previous startswith check accepted clone_path equal to temp_dir itself (a string starts with itself), so '..git' deriving '.' would still resolve to temp_dir and pass through to shutil.rmtree. Now requires clone_path to be a strict descendant: adds equality rejection and uses os.sep-terminated prefix to also prevent sibling directory prefix collisions.
This commit is contained in:
parent
85e1e1b6f2
commit
c82b4f17f7
1 changed files with 7 additions and 3 deletions
|
|
@ -1565,10 +1565,14 @@ def clone_repository(repo_url: str, run_name: str, dest_name: str | None = None)
|
|||
else:
|
||||
repo_name = derive_repo_base_name(repo_url)
|
||||
|
||||
# Guard against path traversal: the derived name must not resolve
|
||||
# outside the temp directory (e.g. ".." or ".").
|
||||
# Guard against path traversal: the derived name must resolve to a
|
||||
# strict child of the temp directory — not temp_dir itself, and not
|
||||
# any path outside it (e.g. "." or "..").
|
||||
clone_path = (temp_dir / repo_name).resolve()
|
||||
if not str(clone_path).startswith(str(temp_dir.resolve())):
|
||||
temp_dir_resolved = temp_dir.resolve()
|
||||
if clone_path == temp_dir_resolved or not str(clone_path).startswith(
|
||||
str(temp_dir_resolved) + os.sep
|
||||
):
|
||||
raise ValueError(
|
||||
f"Refusing to clone: derived directory name '{repo_name}' "
|
||||
f"escapes the temporary directory"
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue