[rust] Prevent path traversal in tar and pkg extraction - #17668
Conversation
Code Review by Qodo
Context used✅ Compliance rules (platform):
14 rules 1. Tar strips before validation
|
PR Summary by QodoPrevent path traversal in tar and pkg extraction WalkthroughsDescription• Reject archive entries containing ".." path components during tar/cpio extraction. • Centralize traversal validation in a shared check_path_traversal() helper. • Fail fast with a clear error before writing any unsafe paths to disk. Diagramgraph TD
A["uncompress_tar()"] --> B["check_path_traversal()"] --> D[("Filesystem write")]
C["uncompress_pkg()"] --> B --> D
High-Level AssessmentThe following are alternative approaches to this PR: 1. Validate by containment (canonicalize joined path)
2. Use library-provided “safe unpack” APIs where available
3. Harden checks beyond ParentDir
Recommendation: The current approach (explicitly rejecting File ChangesBug fix (1)
|
eeda520 to
2f8fd28
Compare
|
Code review by qodo was updated up to the latest commit 2f8fd28 |
2f8fd28 to
020978d
Compare
|
Code review by qodo was updated up to the latest commit 020978d |
020978d to
58424fb
Compare
|
Code review by qodo was updated up to the latest commit 58424fb |
58424fb to
35a1ad3
Compare
|
Code review by qodo was updated up to the latest commit 35a1ad3 |
35a1ad3 to
9169379
Compare
|
Code review by qodo was updated up to the latest commit 9169379 |
9169379 to
dde0400
Compare
|
Code review by qodo was updated up to the latest commit dde0400 |
|
Code review by qodo was updated up to the latest commit 6c652bb |
Add validation to reject archive entries containing ParentDir (..) components in uncompress_tar() and uncompress_pkg(). This prevents malicious archives from writing files outside the intended extraction directory. The shared validation logic is refactored into check_path_traversal() to avoid duplication (DRY principle). - CVE-2025-XXXX: Path Traversal via uncompress_tar - CVE-2025-YYYY: Path Traversal via uncompress_pkg
6c652bb to
4c0e77d
Compare
|
Code review by qodo was updated up to the latest commit 4c0e77d |
🔗 Related Issues
NA
💥 What does this PR do?
Add validation to reject archive entries containing
ParentDir(..)components inuncompress_tar()anduncompress_pkg(). This prevents malicious archives from writing files outside the intended extraction directory.The shared validation logic is refactored into
check_path_traversal()to avoid duplication (DRY principle).uncompress_taruncompress_pkg🔧 Implementation Notes
🤖 AI assistance
💡 Additional Considerations
🔄 Types of changes