-
Notifications
You must be signed in to change notification settings - Fork 56
fix: path traversal in init agent + FK cascade for event pruning #1070
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,5 +1,5 @@ | ||
| -- 026_events_trace_id.sql — Add trace_id and parent_event_id for distributed tracing (#859) | ||
|
|
||
| ALTER TABLE genie_runtime_events ADD COLUMN IF NOT EXISTS trace_id UUID; | ||
| ALTER TABLE genie_runtime_events ADD COLUMN IF NOT EXISTS parent_event_id BIGINT REFERENCES genie_runtime_events(id); | ||
| ALTER TABLE genie_runtime_events ADD COLUMN IF NOT EXISTS parent_event_id BIGINT REFERENCES genie_runtime_events(id) ON DELETE SET NULL; | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Adding a foreign key with Additionally, note that ALTER TABLE genie_runtime_events ADD COLUMN IF NOT EXISTS parent_event_id BIGINT REFERENCES genie_runtime_events(id) ON DELETE SET NULL;
CREATE INDEX IF NOT EXISTS idx_runtime_events_parent_event_id ON genie_runtime_events(parent_event_id) WHERE parent_event_id IS NOT NULL; |
||
| CREATE INDEX IF NOT EXISTS idx_runtime_events_trace_id ON genie_runtime_events(trace_id) WHERE trace_id IS NOT NULL; | ||
| Original file line number | Diff line number | Diff line change | ||||
|---|---|---|---|---|---|---|
|
|
@@ -175,6 +175,12 @@ function resolveAgentsDir(wsRoot: string, dirOption?: string): string { | |||||
|
|
||||||
| /** genie init agent <name> — scaffold agent directory */ | ||||||
| async function initAgent(name: string, options: { dir?: string }): Promise<void> { | ||||||
| // Guard against path traversal — name is CLI input and lands in join(baseDir, name) | ||||||
| if (!name || /[\/\\]/.test(name) || name === '.' || name === '..' || name.includes('..')) { | ||||||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. The path traversal check is effective, but the Also,
Suggested change
|
||||||
| console.error('Error: Agent name must not contain path separators or traversal sequences.'); | ||||||
| process.exit(1); | ||||||
| } | ||||||
|
|
||||||
| const cwd = process.cwd(); | ||||||
| const ws = findWorkspace(cwd); | ||||||
| if (!ws) { | ||||||
|
|
||||||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Changing
026_events_trace_id.sqlin place will not fix existing databases that already applied migration026, becauserunMigrationsskips applied migrations by filename (_genie_migrationsname check insrc/lib/db-migrations.ts). In those environments the FK remainsNO ACTION, sogenie db prune-eventscan still fail when deleting parent rows. This needs a follow-up migration (e.g.,027_...) that explicitly alters the existingparent_event_idconstraint toON DELETE SET NULL.Useful? React with 👍 / 👎.