Repository navigation
fix(worktree-seed): harden chained symlink boundary resolution - #17857
azooz2003-bit wants to merge 15 commits into
Conversation
…ink escapes Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…nks out of the repository Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Keep the catch-up branch on the bonsplit revision required by main's terminal sizing sources. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 46 minutes. View limit detailsLimit details: You’ve used all 10 included reviews currently available. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (2)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Note Pull Request opener @azooz2003-bit is not an author or co-author of any commit in this PR (commit identities: All contributors have signed the CLA ✍️ ✅ |
What this is
A fix-forward for #15860. A fresh security review found edge cases in the dangling-link boundary repair that needed to land separately after the original PR merged.
The defects
The resolver followed a chained symlink but dropped path components after a symlinked parent, which could classify an escaping leaf as inside the repository. The fix preserves the unresolved suffix while resolving each symlink component.
The resolver also treated a valid chain that revisited the same alias with a different suffix as a cycle. The fix keys cycle detection on the complete normalized unresolved path state, so valid chains remain allowed while genuine cycles are refused. A self-expanding symlink could otherwise grow the unresolved path indefinitely, so resolution is now bounded at 64 symlink hops and such paths are refused.
Verification
The focused command is
swift testin an extracted scratch package because CMUXAgentLaunch does not build on Linux. The chained-parent and alias-revisit regressions were red before their fixes, and the self-expanding-link regression timed out before its bound. The final run passed all 85 extracted tests.python3 scripts/verify-local.pypassed all 3 selected checks; native compilation and app tests remain unavailable on Linux.Changelog
none
🤖 Generated with Claude Code
Summary by CodeRabbit
Migrated from #15911 after correcting the PR author identity. The head branch and commit history are preserved.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by cubic
Fixes chained symlink boundary resolution in worktree seeding so escaping leaves are no longer misclassified as inside the repository. The resolver now preserves the unresolved suffix while following each symlink component, detects cycles by the full normalized unresolved path state (allowing valid alias revisits), and caps resolution at 64 hops so self-expanding links are refused rather than hanging.
Adds regression tests for chained-parent escapes, symlinked target parents, valid alias revisits, and self-expanding links. Verified with
swift teston an extracted scratch package (CMUXAgentLaunch does not build on Linux) andscripts/verify-local.py(3 checks).Written for commit 06dd0eb. Summary will update on new commits.