[ 
https://issues.apache.org/jira/browse/CAMEL-25412?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Claus Ibsen updated CAMEL-25412:
--------------------------------
    Fix Version/s: 4.18.6
                   4.22.2
                   4.23.0

> camel-file - resolve symbolic links when enforcing jailStartingDirectory for 
> the producer target and local consumer listing
> ---------------------------------------------------------------------------------------------------------------------------
>
>                 Key: CAMEL-25412
>                 URL: https://issues.apache.org/jira/browse/CAMEL-25412
>             Project: Camel
>          Issue Type: Improvement
>          Components: camel-file
>            Reporter: Andrea Cosentino
>            Assignee: shashank
>            Priority: Minor
>             Fix For: 4.18.6, 4.22.2, 4.23.0
>
>
> camel-file enforces {{jailStartingDirectory}} with a lexical path-boundary 
> check only ({{GenericFileHelper.isWithinDirectory}}, after 
> {{FileUtil.compactPath}}). The underlying I/O follows symbolic links, so the 
> lexical check and the effective path can diverge when a link sits inside the 
> configured directory:
> * Producer - {{GenericFileProducer.createFileName()}} calls 
> {{jailedCheck()}}, which validates lexically; {{FileOperations.storeFile()}} 
> then writes via {{Files.newByteChannel}} / {{Files.copy}}, which resolve 
> links.
> * Local consumer - {{GenericFileConsumer.isWithinStartingDirectory()}} 
> returns {{true}} by default and {{FileConsumer}} does not override it; the 
> local directory listing resolves links (directly, and into linked 
> sub-directories when {{recursive=true}}).
> CAMEL-24627 already added symlink-aware containment 
> ({{GenericFileHelper.resolveExistingPathSegments()}}), but only for 
> {{localWorkDirectory}} downloads. The remote consumers were given an 
> {{isWithinStartingDirectory()}} override in CAMEL-24487; the local file 
> producer target and the local consumer listing were not brought to the same 
> parity, so this is a consistency / hardening follow-up to CAMEL-24627.
> Proposed change:
> * Add {{GenericFileHelper.isWithinDirectoryResolvingLinks(target, dir)}} 
> reusing the existing {{resolveExistingPathSegments()}}.
> * {{FileConsumer}} overrides {{isWithinStartingDirectory()}} with it 
> (dangling links skipped).
> * {{FileOperations.storeFile()}} applies it when {{jailStartingDirectory}} is 
> on *and* the target is lexically inside the starting directory. The 
> lexical-inside guard preserves {{tempFileName=../work/...}}, allowed since 
> CAMEL-15544 (see {{FileProduceTempFileNameTest.testParentTempFileName}}).
> Notes:
> * Check-then-write remains non-atomic (a complete solution would open with 
> {{NOFOLLOW_LINKS}}); there is a per-file {{toRealPath}} cost; deployments 
> that intentionally link files or sub-directories into these directories would 
> change behaviour, so this needs an upgrade-guide note 
> ({{docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc}}) 
> and possibly an opt-out.
> * Behaviour parity with CAMEL-24627 / CAMEL-24548 / CAMEL-24549.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to