Repository navigation
Conversation
Resolve only the parent path before applying PAX extended attributes, preserving lsetxattr's no-follow behavior for the final archive entry. Add deterministic coverage for the xattr syscall path and retain the SELinux integration test. Fixes moby#109 Related to moby/moby#53616 Signed-off-by: thangnc <chithang.nydo@gmail.com> (cherry picked from commit e0a7b3a)
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## main #125 +/- ##
==========================================
+ Coverage 65.48% 74.66% +9.18%
==========================================
Files 46 48 +2
Lines 2393 2396 +3
==========================================
+ Hits 1567 1789 +222
Misses 605 605
+ Partials 221 2 -219 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Pin the parent directory through os.Root before applying xattrs so that Linux extraction preserves no-follow semantics without resolving the parent pathname again. Apply xattrs in an isolated filesystem context when procfs is unavailable, including direct callers without prepared chroot options. Restoring xattrs in that case requires permission to call unshare(CLONE_FS); retain an explicit error when the operation is blocked. Keep the existing xattr error policy, include logical entry names in diagnostics, and cover dangling symlinks, replaced parents, root renames, symlinked parents, and extraction without procfs. Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
d607fbf to
6c0c79c
Compare
|
@crazy-max still draft? Was something wrong with the patch? |
There was a problem hiding this comment.
🔵 Needs a closer look
Security-sensitive path resolution and per-thread filesystem isolation warrant final human validation.
0 open findings
What changed in this PR
Fixes xattr restoration for dangling symlinks while preserving extraction-root confinement.
Changes:
- Preserves final-component no-follow semantics for xattrs.
- Pins Linux parent directories, with an isolated-filesystem fallback when procfs is unavailable.
- Adds regression, confinement, and chroot coverage.
| File | Description |
|---|---|
archive.go |
Centralizes xattr application and improves diagnostics. |
xattr_supported_linux.go |
Implements pinned-parent Linux restoration. |
xattr_supported_unix.go |
Preserves final components on supported Unix systems. |
xattr_unsupported.go |
Adds the no-op unsupported-platform abstraction. |
archive_linux_test.go |
Tests dangling symlinks and path confinement. |
archive_linux_chrooted_test.go |
Tests restoration without procfs. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This applies extended attributes to the archive entry itself, so labeled dangling symlinks such as
bin -> usr/bincan be extracted before their targets exist.The Linux implementation adapts the pinned-parent approach from moby/buildkit#7034, opening the parent through
os.Rootbefore applying xattrs without following the final component. This avoids resolving the parent pathname again at the syscall boundary. When procfs is unavailable, restoration uses an isolated filesystem context, including for direct callers without prepared chroot options. This requires permission to callunshare(CLONE_FS); extraction returns an error if that operation is blocked. Existing xattr error handling is preserved, and diagnostics include the logical archive entry name.