fix: restrict path traversal check to file scheme in DEnumerator buildUrl - #379
Conversation
…dUrl 1. DEnumeratorPrivate::buildUrl() 对所有 scheme 的文件名做路径遍历检查,导致 gio trash:/// 后端使用反斜杠分隔的扁平文件名被误判为恶意路径并返回空 URL; 2. 将路径遍历检查限制为仅对 file:/// 或无 scheme 的本地文件系统生效,gio trash:/// 等虚拟文件系统的合法文件名不受影响; 3. 修复手动分区场景下 /media 挂载点的回收站文件无法显示和清空的问题; Log: 修复 buildUrl 路径遍历安全检查误伤 gio trash 反斜杠文件名导致回收站无法显示和清空的问题 PMS: BUG-372733 Bug: https://pms.uniontech.com/bug-view-372733.html
There was a problem hiding this comment.
Sorry @Johnson-zs, you have reached your weekly rate limit of 500000 diff characters.
Please try again later or upgrade to continue using Sourcery
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: Johnson-zs The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
Reviewer's guide (collapsed on small PRs)Reviewer's GuideRestricts the path traversal protection in DEnumeratorPrivate::buildUrl to only apply for local file-system URLs (file:/// or no scheme), so that gio trash:/// backends using backslash-separated flat filenames are no longer incorrectly rejected. File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
deepin pr auto review★ 总体评分:60分■ 【总体评价】
■ 【详细分析】
■ 【改进建议代码示例】 QByteArray fileNameBa(fileName);
// 拦截路径遍历攻击,防止恶意文件名越权
// gio 的 trash:/// 后端对非用户主目录挂载点的回收站文件,使用反斜杠分隔的扁平路径
// 作为 GFileInfo 的 standard::name(例如 "\media\user\dev\.Trash-1000\files\x"),
// 这是合法的 trash 文件名而非恶意路径,故移除对单独 '/' 和 '\' 的宽泛拦截,
// 精确匹配路径遍历序列 "../"、"..\" 或以 ".." 开头的文件名,对所有协议生效。
if (fileNameBa.contains("../") || fileNameBa.contains("..\\") || fileNameBa.startsWith("..")) {
return QUrl();
} |
|
@Johnson-zs: The following test failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here. |
|
/forcemerge |
|
This pr force merged! (status: blocked) |
496e59b
into
linuxdeepin:release/snipe
根因分析
DEnumeratorPrivate::buildUrl()中的路径遍历安全检查fileNameBa.contains('\\')对 giotrash:///后端使用反斜杠分隔的扁平文件名(如\media\user\dev\.Trash-1000\files\x)返回空QUrl(""),导致/media挂载点的回收站文件无法显示和清空。fd494fb(PMS #367075, 2026-07-16)引入了该检查QUrl(""),触发kIsNotTrashFileError修复方案
将路径遍历检查限制为仅对
file:///或无 scheme 的本地文件系统生效,trash:///等 gio 虚拟文件系统跳过该检查。改动安全评估
低风险。修改仅限制检查的适用 scheme 范围,不改变
buildUrl()签名或返回值语义。对file:///scheme 行为完全不变。Summary by Sourcery
Bug Fixes: