davidzollo commented on PR #10618:
URL: https://github.com/apache/seatunnel/pull/10618#issuecomment-5391812957

   Closed out the blocking finding from the 2026-07-26 review, took the 
non-blocking test suggestion with it, and synced the branch with current `dev`:
   
   **The containment fix** (`FileUtils.searchJarFilesForStorage`): 
`storage.type` is user configuration, and it was resolved directly against the 
starter/zeta root — so `"../other-dir"`, an absolute path, or a subdirectory 
symlinked outside the root would make the engine plugin loader scan and load 
JARs from unrelated filesystem locations. Now:
   - the value must match `[a-z0-9_-]+` after trim/lowercase — every legitimate 
identifier (`hdfs`, `s3`, `oss`, …) passes unchanged; anything path-shaped 
fails closed to the legacy whole-root scan (which never leaves 
`zetaDirectory`), with the offending value logged;
   - both `common/` and the storage-specific directory are scanned only when 
their real path (symlinks resolved) is still inside the root's real path, since 
the JAR walk follows links; escaping directories are skipped with a warning 
naming the resolved target.
   
   Behavior for every valid configuration is unchanged: same directories 
scanned, same legacy fallback when no split layout exists.
   
   **Regression matrix added** (the review's non-blocking ask): traversal 
value, absolute-path value, and an escaping-symlink subdirectory (POSIX-only — 
symlink creation needs privileges on Windows runners) all assert the escaped 
JAR is never loaded while in-root loading keeps working.
   
   **Dev sync**: four deployment-doc conflicts — dev had enriched the legacy 
`lib/`-layout notices with the renamed `seatunnel-shade-*` jar names while this 
branch rewrote the same notices for the split layout. Kept this branch's layout 
statement and folded in dev's current jar naming/lists, since this branch's old 
text referenced the pre-rename jar names and would have shipped stale 
documentation.
   
   Fresh CI is running on the new head.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to