uutils / uutils/coreutils

bug(realpath): when using $'\xFF' no errors reported at all

Open
#12,800 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Rust
Stars
24.1k
Forks
2k
Avg merge
1d 5h
Merged PRs (30d)
365

Description

Hi, uutils mainteners

there a serious bug with the realpath uutils utility, when providing $'\xFF', the utility replace it with U+FFFD, and corrupts the path instead
of refusing, our testing confirms it

relunsec@relunsec:~/software/coreutils/target/debug$ ./realpath $'\xFF'
/home/relunsec/software/coreutils/target/debug/�

as you can see the \xFF replace it replacement char U+FFFD, and corrupting path instead of erroring like the gnu one does

relunsec@relunsec:~/software/coreutils/target/debug$ gnurealpath $'\xFF'
gnurealpath: ''$'\377': Invalid or incomplete multibyte or wide character

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the realpath utility and reproduce the reported command using a byte value such as $'\xFF', comparing its output with gnurealpath. Trace how the invalid path is handled; done means realpath reports an error instead of emitting a path containing U+FFFD.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
cli
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.