fix(archive): recheck deferred hardlinks - #837
Merged
Merged
Conversation
Validate deferred hardlink paths against every symlink declared in the archive. This prevents a later symlink from redirecting a hardlink outside the extraction root while preserving valid hardlinks beside unrelated symlinks.
Owner
|
@rustytrees Thanks for the contribution! One small request: could you please instruct your agent to follow the PR template provided in the repository for PRs? It helps keep the PRs consistent and easier to review. Thanks! |
indaco
pushed a commit
that referenced
this pull request
Aug 18, 2026
Deferred hardlinks are revalidated against the complete set of archive symlinks before they are created, so a symlink declared after a hardlink can no longer redirect either end outside the extraction root. (cherry picked from commit 7b7b4c1)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Deferred hardlink paths are rechecked against every symlink declared by the archive. A symlink that appears later can no longer redirect the hardlink destination or source outside the extraction root.
The regression coverage includes the vulnerable ordering and a valid hardlink followed by an unrelated symlink.
Related Issue
Closes #852.
Notes for Reviewers
Verification completed:
zig build test-one: 2,425 passedzig build test: 5,060 passed, 3 skippedgit verify-commit