mirror of
https://github.com/openai/codex.git
synced 2026-09-20 12:47:38 +00:00
## Why An `apply_patch` path can be replaced with a symlink after verification, allowing an unsandboxed patch operation to reach a different file than the one that was approved. ## What changed - Add `follow_symlinks` options to executor filesystem reads, writes, metadata lookups, directory creation, and removal, including the corresponding `followSymlinks` protocol fields. - Implement no-follow filesystem operations on Unix and Windows that reject links in any path component and restrict file access to regular files. - Run `apply_patch` with symlink traversal disabled when an otherwise-required sandbox is bypassed, while retaining the existing follow-symlink default for standalone callers. ## Testing - Cover leaf and ancestor symlinks across patch add, update, delete, and move operations, including a path swap after verification. - Exercise local and remote no-follow filesystem behavior, concurrent directory creation, special-file rejection, and Windows reparse points. GitOrigin-RevId: 43fd479084891493ce13564fbd894b98f329c6dd
28 lines
729 B
Rust
28 lines
729 B
Rust
use codex_utils_path_uri::PathUri;
|
|
use pretty_assertions::assert_eq;
|
|
use tokio::io;
|
|
|
|
use super::*;
|
|
|
|
#[tokio::test]
|
|
async fn direct_file_system_rejects_non_native_uri_as_invalid_input() {
|
|
let error = DirectFileSystem
|
|
.read_file(&non_native_uri(), Default::default(), /*sandbox*/ None)
|
|
.await
|
|
.expect_err("non-native URI should be rejected");
|
|
|
|
assert_eq!(error.kind(), io::ErrorKind::InvalidInput);
|
|
}
|
|
|
|
fn non_native_uri() -> PathUri {
|
|
#[cfg(unix)]
|
|
let uri = "file://server/share/file.txt";
|
|
#[cfg(windows)]
|
|
let uri = "file:///usr/local/file.txt";
|
|
|
|
match PathUri::parse(uri) {
|
|
Ok(uri) => uri,
|
|
Err(err) => panic!("valid non-native URI should parse: {err}"),
|
|
}
|
|
}
|