Skip to content

safe_traversal: don't follow a symlink in open_file_at#13507

Open
Angadi56 wants to merge 1 commit into
uutils:mainfrom
Angadi56:open-file-at-nofollow
Open

safe_traversal: don't follow a symlink in open_file_at#13507
Angadi56 wants to merge 1 commit into
uutils:mainfrom
Angadi56:open-file-at-nofollow

Conversation

@Angadi56

Copy link
Copy Markdown

The safe-traversal helpers exist so recursive and privileged file operations can anchor on directory descriptors and refuse to cross a symlink, and every openat in the module passes O_NOFOLLOW to enforce that. open_file_at, the one primitive that creates a file, was missing it, so it opened O_CREAT|O_WRONLY|O_TRUNC on the final name and would follow a symlink sitting there. Its only caller is install's fd-based copy, which unlinks the destination name and then creates it through this helper; if a symlink is present at that name it gets followed and its target is truncated and filled with the source file's contents, so a link placed in the destination directory can redirect a privileged install onto a file outside the tree. The path-based copy_file already avoids this by using create_new, which never resolves a symlink, so the fd-based path was the odd one out. I noticed it while reading how the two copy paths line up. Adding O_NOFOLLOW makes open_file_at refuse the link with ELOOP instead of writing through it, matching the rest of the module. The added test plants a symlink to a sentinel outside the directory and checks the sentinel is left untouched.

@codspeed-hq

codspeed-hq Bot commented Jul 22, 2026

Copy link
Copy Markdown

Merging this PR will improve performance by 3.22%

⚠️ Different runtime environments detected

Some benchmarks with significant performance changes were compared across different runtime environments,
which may affect the accuracy of the results.

Open the report in CodSpeed to investigate

⚡ 1 improved benchmark
✅ 338 untouched benchmarks
⏩ 46 skipped benchmarks1

Performance Changes

Mode Benchmark BASE HEAD Efficiency
Simulation du_all_wide_tree[(5000, 500)] 16.8 ms 16.3 ms +3.22%

Tip

Curious why this is faster? Comment @codspeedbot explain why this is faster on this PR, or directly use the CodSpeed MCP with your agent.


Comparing Angadi56:open-file-at-nofollow (b39a9d2) with main (be96f5d)

Open in CodSpeed

Footnotes

  1. 46 benchmarks were skipped, so the baseline results were used instead. If they were deleted from the codebase, click here and archive them to remove them from the performance reports.

@github-actions

Copy link
Copy Markdown

GNU testsuite comparison:

Skip an intermittent issue tests/rm/isatty (fails in this run but passes in the 'main' branch)
Skip an intermittent issue tests/tail/tail-n0f (fails in this run but passes in the 'main' branch)
Skipping an intermittent issue tests/date/date-locale-hour (passes in this run but fails in the 'main' branch)
Congrats! The gnu test tests/tail/pid is no longer failing!
Note: The gnu test tests/seq/seq-epipe is now being skipped but was previously passing.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant