bytecodealliance / bytecodealliance/cap-std
Improved support for changing symlink permissions
- 主要语言
- Rust
- 星标
- 821
- 派生
- 57
- 平均合并
- 1 小时 16 分钟
- 30 天内合并 PR
- 4
描述
Hello 👋,
I'm trying to implement some logic that extracts a zip file using `cap-primitives` and ran into a snag with how `fs::set_permissions` is currently implemented. In the [general UNIX implementation](https://github.com/bytecodealliance/cap-std/blob/58df14be1b80ade7464f754fa1aa06da2f5fe26d/cap-primitives/src/rustix/linux/fs/procfs.rs#LL28C41-L28C60) it says even `AT_NOFOLLOW_SYMLINK` with `fchmodat` is not enough because it would modify the symlink itself, and that it is undesirable behavior. So, because of that, its implemented as a regular `fchmod`. Its not clear to me why this is undesirable at a glance though.
In my case however, I am actually trying to change the symlink itself based on permission bits that come from the zip file and the current behavior makes that impossible as it always dereferences the symlink and changes the permissions of the linked item instead. This is an odd use case, but I have the constraint of the process `umask` set at startup being more restrictive then what the zipped file permissions are, so I need to change everything written out to disk after writing to get the correct resulting permissions.
Is this a feature that you would consider adding to `cap-primitives`, or is "weird" symlink handling something that's considered out-of-scope?
贡献指南
调研方向
从 cap-primitives/src/rustix/linux/fs/procfs.rs 开始,跟踪 fs::set_permissions 的实现,尤其是 AT_NOFOLLOW_SYMLINK 以及 issue 中描述的 fchmod 行为。调查所述的安全性理由和涉及的 Unix 平台,然后确定是否可以在不改变当前默认语义的情况下支持更改 symlink 权限。完成的标准是确定 API 和范围,并明确 zip 提取用例的行为。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- rust
- 领域
- operating-systems
- Issue 类型
- 功能
- 难度
- 5/5
- 预计耗时
- 一周以上
- 活跃度
- 停滞
- 描述清晰度
- 基本清楚
- 新手友好度
- 25/100