review: refuse a process named ".", ".." or with a leading dash, so removing one cannot delete the mesh's own directory (hq ADR 0118)
removeProcess deletes filepath.Join(daemonRoot, name) whole; a process named ".." made that /var/lib/mesh. The declaration and the removal now hold the name to one rule.
This commit is contained in:
@@ -303,10 +303,11 @@ func unitValue(key, value string) string {
|
||||
// have all vanished is forgotten rather than reported as removed.
|
||||
func removeProcess(ctx context.Context, a store.Applied, run Runner) (string, string, error) {
|
||||
name := a.Target
|
||||
if name == "" || strings.ContainsAny(name, "/ \t") {
|
||||
// The name is a unit name and a directory under the mesh's own. One that could climb out
|
||||
// of either is refused rather than acted on, whatever wrote it into the record.
|
||||
return "", "", fmt.Errorf("a process recorded under %q cannot be removed by name", name)
|
||||
if problem := declaration.ProcessNameProblem(name); problem != "" {
|
||||
// The name is a unit name and a directory under the mesh's own, and what goes is that
|
||||
// directory, whole. One that could climb out of either — ".." is the mesh's own directory's
|
||||
// parent — is refused rather than acted on, whatever wrote it into the record.
|
||||
return "", "", fmt.Errorf("a process recorded under %q cannot be removed by name: %s", name, problem)
|
||||
}
|
||||
found := false
|
||||
for _, unit := range []string{name + ".timer", name + ".service"} {
|
||||
|
||||
Reference in New Issue
Block a user