https://sourceware.org/git/gitweb.cgi?p=newlib-cygwin.git;h=58cc67d6536c73c463114a30b4f14f331137baeb

commit 58cc67d6536c73c463114a30b4f14f331137baeb
Author: Ken Brown <[email protected]>
Date:   Tue Sep 8 11:45:09 2020 -0400

    Cygwin: format_process_fd: add directory check
    
    The incoming path is allowed to have the form "$PID/fd/[0-9]*/.*"
    provided the descriptor symlink points to a directory.  Check that
    this is indeed the case.

Diff:
---
 winsup/cygwin/fhandler_process.cc | 15 +++++++++++++++
 1 file changed, 15 insertions(+)

diff --git a/winsup/cygwin/fhandler_process.cc 
b/winsup/cygwin/fhandler_process.cc
index a6c358217..888604e3d 100644
--- a/winsup/cygwin/fhandler_process.cc
+++ b/winsup/cygwin/fhandler_process.cc
@@ -398,6 +398,21 @@ format_process_fd (void *data, char *&destbuf)
        *((process_fd_t *) data)->fd_type = virt_fdsymlink;
       else /* trailing path */
        {
+         /* Does the descriptor link point to a directory? */
+         bool dir;
+         if (*destbuf != '/')  /* e.g., "pipe:[" or "socket:[" */
+           dir = false;
+         else
+           {
+             path_conv pc (destbuf);
+             dir = pc.isdir ();
+           }
+         if (!dir)
+           {
+             set_errno (ENOTDIR);
+             cfree (destbuf);
+             return -1;
+           }
          char *newbuf = (char *) cmalloc_abort (HEAP_STR, strlen (destbuf)
                                                           + strlen (e) + 1);
          stpcpy (stpcpy (newbuf, destbuf), e);

Reply via email to