Skip to content

Scratchpad path validation trusts pathnames it later reopens #448

Description

@Shearerbeard

validate_path decides containment from the pathname alone. It
canonicalizes existing components and lexically checks missing ones;
the actual read or write then opens the path as a separate step.
Between the check and the open, another process with write access to
memory_dir can replace a validated component with a symlink, and the
operation lands wherever the link points. The gap is documented as a
trust boundary on validate_path: every writer under memory_dir is
trusted.

That assumption matched a pod-local directory. #421 exists to put
memory_dir on shared network storage, where every pod (and anything
else on the mount) becomes a co-writer, so the boundary widens from one
process to the whole cluster.

Closing it needs the check and the open to be a single step: no-follow,
handle-relative resolution (the openat2/RESOLVE_BENEATH class on Linux,
an O_NOFOLLOW component walk as the portable fallback) instead of
pathname re-validation.

Follow-up to #421; flagged by adversarial review rounds 2-4 on the #421
branch.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions