Prevent terminal symlink traversal via recursive grep
This commit is contained in:
@@ -80,6 +80,8 @@ class AthenaTerminalTests(unittest.TestCase):
|
||||
self.module.validate_arguments("rg", ["--pre", "sh", "x"], self.workspace)
|
||||
with self.assertRaises(PermissionError):
|
||||
self.module.validate_arguments("find", ["."], self.workspace)
|
||||
with self.assertRaises(ValueError):
|
||||
self.module.validate_arguments("grep", ["-R", "Athena", "."], self.workspace)
|
||||
|
||||
def test_validation_parses_without_execution(self):
|
||||
result = self.module.validate_source({"path": "valid.json", "kind": "auto"})
|
||||
|
||||
@@ -256,7 +256,9 @@ def validate_arguments(program: str, arguments: list[str], cwd: Path) -> list[st
|
||||
return ["-n", args[1], *[path_argument(value, cwd) for value in args[2:]]]
|
||||
|
||||
if program == "grep":
|
||||
allowed = {"-c", "-E", "-F", "-i", "-l", "-n", "-r", "-R"}
|
||||
# GNU grep -R follows symlinks. Only -r is permitted because it skips
|
||||
# directory symlinks and therefore preserves the visible-root boundary.
|
||||
allowed = {"-c", "-E", "-F", "-i", "-l", "-n", "-r"}
|
||||
result = []
|
||||
index = 0
|
||||
while index < len(args) and args[index].startswith("-"):
|
||||
|
||||
Reference in New Issue
Block a user