Create parent directories only after the containment check in InstallHelper.TryExtractToDirectory

Đang mở Phù hợp với người mới
#2,056 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
2/5
Thời gian dự kiến
1-3 giờ
Mức phù hợp với người mới
78/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
csharp
Lĩnh vực
security

Hướng nghiên cứu

Bắt đầu trong src/code/InstallHelper.cs tại InstallHelper.TryExtractToDirectory, xung quanh logic tạo thư mục và kiểm tra containment. Theo dõi cách entry.FullName trở thành destinationPath và xác minh rằng containment được kiểm tra trước mọi side effect đối với thư mục hoặc tệp. Hoàn thành nghĩa là các entry bị từ chối do kiểm tra containment không để lại thư mục nào, trong khi các entry hợp lệ vẫn được giải nén bình thường.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Summary of the new feature / enhancement

During package extraction, entry-derived parent directories are created before the path-containment decision runs. An entry whose file write the containment check would reject can still leave empty directories outside the extraction root (directory-only effect — no file content is written outside). As a user, I want each entry's extraction side effects to be all-or-nothing, so a malformed package cannot leave stray directories anywhere on disk.

Proposed technical implementation details

In src/code/InstallHelper.cs, TryExtractToDirectory (~L1299 on current main):

  • For entries containing a path separator, Directory.CreateDirectory(Path.Combine(extractPath, parentDirs)) runs first (~L1372-1377), using the raw entry prefix.
  • Only afterwards is destinationPath = Path.GetFullPath(Path.Combine(extractPath, entry.FullName)) computed and the StartsWith(extractPath) containment verified (~L1381-1386) — and that check gates only the ExtractToFile call (~L1388).

So a package containing an entry such as ../../../../empty/dir/x (this loop is reached on installs from HTTP repositories, which do not go through a BCL extraction up front) creates empty/dir relative to the extraction temp directory as empty directories, and then the file write is skipped by the containment check.

Suggested reordering, so containment gates every side effect:

  1. Compute destinationPath = Path.GetFullPath(Path.Combine(extractPath, entry.FullName)) first.
  2. Verify containment of destinationPath under extractPath.
  3. Only then create Path.GetDirectoryName(destinationPath) and call ExtractToFile.
  4. Skip entries that fail containment entirely — no partial side effects.

This also makes directory creation consistent with the resolved path rather than the raw entry string.

Ngôn ngữ chính
C#
Star
576
Fork
114
Merge trung bình
1 ngày 2 giờ
Pull request đã merge (30 ngày)
7

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của PowerShell/PSResourceGet

Tất cả issue của PowerShell/PSResourceGet

Issue tương tự

Thêm issue về C#

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.