hutiefang76 opened a new pull request, #13389:
URL: https://github.com/apache/gravitino/pull/13389

   ### What changes were proposed in this pull request?
   
   - Build job staging paths through one normalized `Path` helper instead of 
string concatenation.
   - Reject template paths that leave or collapse to their metalake staging 
directory before job submission.
   - Reuse the same safe resolution for template deletion and expired-job 
cleanup, so persisted unsafe names cannot target an out-of-bound directory.
   - Add a regression test for the `..` template-name traversal case.
   
   ### Why are the changes needed?
   
   A job template name is part of the on-disk staging path. On main, a name 
such as `..` was accepted and normalized the path from 
`<staging>/<metalake>/../job-<id>` to the staging root; further traversal could 
escape the configured staging directory. This also affected deletion and 
cleanup paths.
   
   Fix: #13371
   
   ### Does this PR introduce _any_ user-facing change?
   
   Job runs whose template names resolve outside their own metalake staging 
directory now fail with an invalid-argument error. No API or configuration key 
changes are introduced.
   
   ### How was this patch tested?
   
   - Added `TestJobManager.testRunJobRejectsStagingPathTraversal`.
   - `./gradlew :core:test --tests 'org.apache.gravitino.job.TestJobManager' 
-PskipITs`
   - `./gradlew :core:check -PskipITs`
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to