Repository navigation
Fix issues with symlink handling - #1522
Merged
Merged
Conversation
This tests to make sure that using remove on a symlink pointing to a directory just removes the symlink, not the whole directory. Note that shutil.rmtree has used a symlink resistant version since python 3.3 so this test is purely to demonstrate that remove() uses unlink in that case.
Just in case they have already been created as symlinks, use remove instead of shutil which will raise an error.
Make sure that all the kernels returned are under the root directory. This prevents potential issues with accessing files on the host system.
If there is an existing module-info, and it is a symlink, remove it before writing the new one.
This helps catch mistakes with hardlink, symlink, copy, move trying to access paths outside of the outroot set in the template runner. Should help prevent accidentally accessing host files and paths.
This function is similar to joinpaths, except that it will evaluate the final path and raise a RuntimeError if it is outside of the first argument passed. This can be used to help prevent absolute symlinks and directory traversals from pointing outside of a directory tree. Includes tests.
This will raise a RuntimeError if the real path points outside the template runner's outroot. NOTE: This does not guarantee the safety of the template -- this is running as root, it has access to the whole system and is not safe to pass unknown templates into. This change is meant to help prevent accidentally accessing the host files.
This prevents absolute symlinks in the ostree boot path from pointing outside the image's directory tree.
This ensures that the path used for the config_files cannot point outside of the mount_dir.
This ensures that the boot directory from the image cannot be a symlink pointing outside of the root_dir
Coverage Report for CI Build 31522054266Coverage increased (+0.6%) to 42.157%Details
Uncovered Changes
Coverage RegressionsNo coverage regressions found. Coverage Stats
💛 - Coveralls |
This was referenced Aug 11, 2026
This was referenced Aug 12, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A scan of lorax identified several places where symlinks could point outside of the install root and cause problems for the host system. These commits fix these, but running lorax or livemedia-creator in an insecure way (eg. allowing unverified users to pass it kickstarts, templates, rpm files, or filesystem images) is not supported. These programs run as root (or in root-like) environments and due to the nature of installing packages, mounting filesystems, etc. have access to everything and users should take reasonable precautions not to allow unverified data to be passed to them.