Prevent terminal symlink traversal via recursive grep
This commit is contained in:
@@ -80,6 +80,8 @@ class AthenaTerminalTests(unittest.TestCase):
|
|||||||
self.module.validate_arguments("rg", ["--pre", "sh", "x"], self.workspace)
|
self.module.validate_arguments("rg", ["--pre", "sh", "x"], self.workspace)
|
||||||
with self.assertRaises(PermissionError):
|
with self.assertRaises(PermissionError):
|
||||||
self.module.validate_arguments("find", ["."], self.workspace)
|
self.module.validate_arguments("find", ["."], self.workspace)
|
||||||
|
with self.assertRaises(ValueError):
|
||||||
|
self.module.validate_arguments("grep", ["-R", "Athena", "."], self.workspace)
|
||||||
|
|
||||||
def test_validation_parses_without_execution(self):
|
def test_validation_parses_without_execution(self):
|
||||||
result = self.module.validate_source({"path": "valid.json", "kind": "auto"})
|
result = self.module.validate_source({"path": "valid.json", "kind": "auto"})
|
||||||
|
|||||||
@@ -256,7 +256,9 @@ def validate_arguments(program: str, arguments: list[str], cwd: Path) -> list[st
|
|||||||
return ["-n", args[1], *[path_argument(value, cwd) for value in args[2:]]]
|
return ["-n", args[1], *[path_argument(value, cwd) for value in args[2:]]]
|
||||||
|
|
||||||
if program == "grep":
|
if program == "grep":
|
||||||
allowed = {"-c", "-E", "-F", "-i", "-l", "-n", "-r", "-R"}
|
# GNU grep -R follows symlinks. Only -r is permitted because it skips
|
||||||
|
# directory symlinks and therefore preserves the visible-root boundary.
|
||||||
|
allowed = {"-c", "-E", "-F", "-i", "-l", "-n", "-r"}
|
||||||
result = []
|
result = []
|
||||||
index = 0
|
index = 0
|
||||||
while index < len(args) and args[index].startswith("-"):
|
while index < len(args) and args[index].startswith("-"):
|
||||||
|
|||||||
Reference in New Issue
Block a user