Skip to content

Fix issues with symlink handling - #1522

Merged
brlane-rht merged 10 commits into
weldr:masterfrom
brlane-rht:master-symlinks
Aug 12, 2026
Merged

brlane-rht merged 10 commits into
weldr:masterfrom
brlane-rht:master-symlinks

Conversation

@brlane-rht

Copy link
Copy Markdown
Contributor

A scan of lorax identified several places where symlinks could point outside of the install root and cause problems for the host system. These commits fix these, but running lorax or livemedia-creator in an insecure way (eg. allowing unverified users to pass it kickstarts, templates, rpm files, or filesystem images) is not supported. These programs run as root (or in root-like) environments and due to the nature of installing packages, mounting filesystems, etc. have access to everything and users should take reasonable precautions not to allow unverified data to be passed to them.

This tests to make sure that using remove on a symlink pointing to a
directory just removes the symlink, not the whole directory. Note that
shutil.rmtree has used a symlink resistant version since python 3.3 so
this test is purely to demonstrate that remove() uses unlink in that
case.
Just in case they have already been created as symlinks, use remove
instead of shutil which will raise an error.
Make sure that all the kernels returned are under the root directory.
This prevents potential issues with accessing files on the host system.
If there is an existing module-info, and it is a symlink, remove it
before writing the new one.
This helps catch mistakes with hardlink, symlink, copy, move trying to
access paths outside of the outroot set in the template runner. Should
help prevent accidentally accessing host files and paths.
This function is similar to joinpaths, except that it will evaluate the
final path and raise a RuntimeError if it is outside of the first
argument passed.

This can be used to help prevent absolute symlinks and directory
traversals from pointing outside of a directory tree.

Includes tests.
This will raise a RuntimeError if the real path points outside the
template runner's outroot.

NOTE: This does not guarantee the safety of the template -- this is
running as root, it has access to the whole system and is not safe to
pass unknown templates into. This change is meant to help prevent
accidentally accessing the host files.
This prevents absolute symlinks in the ostree boot path from pointing
outside the image's directory tree.
This ensures that the path used for the config_files cannot point
outside of the mount_dir.
This ensures that the boot directory from the image cannot be a symlink
pointing outside of the root_dir
@coveralls

Copy link
Copy Markdown

Coverage Report for CI Build 31522054266

Coverage increased (+0.6%) to 42.157%

Details

  • Coverage increased (+0.6%) from the base build.
  • Patch coverage: 11 uncovered changes across 4 files (35 of 46 lines covered, 76.09%).
  • No coverage regressions found.

Uncovered Changes

File Changed Covered %
src/pylorax/creator.py 6 2 33.33%
src/pylorax/installer.py 4 1 25.0%
src/pylorax/ltmpl.py 21 18 85.71%
src/pylorax/treebuilder.py 10 9 90.0%
Total (5 files) 46 35 76.09%

Coverage Regressions

No coverage regressions found.


Coverage Stats

Coverage Status
Relevant Lines: 3947
Covered Lines: 1676
Line Coverage: 42.46%
Relevant Branches: 2135
Covered Branches: 888
Branch Coverage: 41.59%
Branches in Coverage %: Yes
Coverage Strength: 0.42 hits per line

💛 - Coveralls

@brlane-rht
brlane-rht merged commit 0e03b1f into weldr:master Aug 12, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants