hutiefang76 opened a new pull request, #13389: URL: https://github.com/apache/gravitino/pull/13389
### What changes were proposed in this pull request? - Build job staging paths through one normalized `Path` helper instead of string concatenation. - Reject template paths that leave or collapse to their metalake staging directory before job submission. - Reuse the same safe resolution for template deletion and expired-job cleanup, so persisted unsafe names cannot target an out-of-bound directory. - Add a regression test for the `..` template-name traversal case. ### Why are the changes needed? A job template name is part of the on-disk staging path. On main, a name such as `..` was accepted and normalized the path from `<staging>/<metalake>/../job-<id>` to the staging root; further traversal could escape the configured staging directory. This also affected deletion and cleanup paths. Fix: #13371 ### Does this PR introduce _any_ user-facing change? Job runs whose template names resolve outside their own metalake staging directory now fail with an invalid-argument error. No API or configuration key changes are introduced. ### How was this patch tested? - Added `TestJobManager.testRunJobRejectsStagingPathTraversal`. - `./gradlew :core:test --tests 'org.apache.gravitino.job.TestJobManager' -PskipITs` - `./gradlew :core:check -PskipITs` -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
