Skip to content

fix(node:fs): preserve symlink traversal in realpath - #42277

Closed
steipete wants to merge 1 commit into
oven-sh:mainfrom
steipete:codex/fix-posix-realpath-symlink-parent
Closed

steipete wants to merge 1 commit into
oven-sh:mainfrom
steipete:codex/fix-posix-realpath-symlink-parent

Conversation

@steipete

Copy link
Copy Markdown
Collaborator

What does this PR do?

Fixes POSIX node:fs realpath handling when .. follows a symlink. The native implementation first normalized the input to an absolute path, so link/../target could resolve to a lexical collision beside link instead of following link and then traversing to its parent.

Pass the original NUL-terminated path to the OS so component traversal keeps POSIX semantics. The explicit input-length check preserves ENAMETOOLONG behavior, and Windows remains on its existing implementation.

This was found while validating OpenClaw under Bun; the matching application workaround is tracked in openclaw/openclaw#144700.

AI assistance: This change was developed and reviewed with Codex.

How did you verify your code works?

  • The new collision regression failed on the original release binary and passed after the source change.
  • Incremental release build completed successfully with LLVM 21.1.8 and the repository's pinned Rust toolchain.
  • Focused realpath tests: 11 passed, 1 platform skip, 0 failed.
  • cargo fmt --all -- --check, configured Prettier check, and git diff --check passed.
  • Independent P0-P2 review found no actionable issues.

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude Code Review

This pull request is from a fork — automated review is disabled. A repository maintainer can comment @claude review to run a one-time review.

@coderabbitai

coderabbitai Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 38c03268-797a-477b-afe1-9b5eeae240e2

📥 Commits

Reviewing files that changed from the base of the PR and between 81f97bb and 133b7b9.

📒 Files selected for processing (2)
  • src/runtime/node/node_fs.rs
  • test/js/node/fs/fs.test.ts

Included review availability: Your plan provides up to 10 included reviews per hour; 9 remain after this review.


Walkthrough

The POSIX realpath implementation now resolves original path components directly through the OS. A regression test covers symlink resolution followed by .. traversal across all supported API variants.

Changes

POSIX realpath resolution

Layer / File(s) Summary
Direct POSIX path resolution
src/runtime/node/node_fs.rs
The POSIX implementation removes the resolver filesystem dependency, validates path length, and passes the original path directly to the OS.
Symlink traversal regression coverage
test/js/node/fs/fs.test.ts
The test verifies synchronous, native synchronous, promise, callback, and native callback realpath variants for a symlink followed by .. traversal.

Priority: ⬇️ Low

Merge Risk: ⚪ Minimal · up to 133b7

The realpath fix preserves symlink traversal semantics and is covered across the affected API forms. No merge-blocking risk remains.

🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Description check ✅ Passed The description includes both required sections. It clearly explains the POSIX realpath fix, preserves ENAMETOOLONG behavior, identifies Windows scope, and documents verification results.
Title check ✅ Passed The title clearly and concisely describes the main change: preserving symlink traversal in node:fs realpath handling.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant