bug(realpath): when using $'\xFF' no errors reported at all
Open
Nobody has claimed this yet.
- Dominant language
- Rust
- Stars
- 24.1k
- Forks
- 2k
- Avg merge
- 1d 5h
- Merged PRs (30d)
- 365
Description
Hi, uutils mainteners
there a serious bug with the realpath uutils utility, when providing $'\xFF', the utility replace it with U+FFFD, and corrupts the path instead
of refusing, our testing confirms it
relunsec@relunsec:~/software/coreutils/target/debug$ ./realpath $'\xFF'
/home/relunsec/software/coreutils/target/debug/�
as you can see the \xFF replace it replacement char U+FFFD, and corrupting path instead of erroring like the gnu one does
relunsec@relunsec:~/software/coreutils/target/debug$ gnurealpath $'\xFF'
gnurealpath: ''$'\377': Invalid or incomplete multibyte or wide character
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the realpath utility and reproduce the reported command using a byte value such as $'\xFF', comparing its output with gnurealpath. Trace how the invalid path is handled; done means realpath reports an error instead of emitting a path containing U+FFFD.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust
- Domain
- cli
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 55/100