chmod: re-check --preserve-root during the recursive descent - #13621
Open
sylvestre wants to merge 1 commit into
Open
chmod: re-check --preserve-root during the recursive descent#13621sylvestre wants to merge 1 commit into
sylvestre wants to merge 1 commit into
Conversation
--preserve-root was only enforced for the paths named on the command line (the operand loop in Chmoder::chmod). With -R -L, a symlink encountered *inside* the tree that resolves to / was followed, and the recursion walked into the real root, defeating the failsafe. Reproduced in a sandboxed root: a tree containing `link -> /` with `chmod -R -L --preserve-root 777 tree` took an unrelated 0700 directory to 0777. GNU coreutils 9.10 refuses the same case. Re-check the guard at every descent, in both walk_dir_with_context variants so unix, non-unix and redox are all covered. Only symlinks are canonicalized, so ordinary recursive trees are unaffected. Behaviour now matches GNU: diagnose with the "(same as '/')" wording, skip the subtree, continue, and exit 1 -- rather than aborting the whole run. chown/chgrp already did this in 5c2c38c; chmod was the outlier. PR uutils#10033 fixed only the operand-level "resolves to /" case.
|
GNU testsuite comparison: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
--preserve-root was only enforced for the paths named on the command line (the operand loop in Chmoder::chmod). With -R -L, a symlink encountered inside the tree that resolves to / was followed, and the recursion walked into the real root, defeating the failsafe.