[
https://issues.apache.org/jira/browse/CAMEL-25412?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Claus Ibsen updated CAMEL-25412:
--------------------------------
Fix Version/s: 4.18.6
4.22.2
4.23.0
> camel-file - resolve symbolic links when enforcing jailStartingDirectory for
> the producer target and local consumer listing
> ---------------------------------------------------------------------------------------------------------------------------
>
> Key: CAMEL-25412
> URL: https://issues.apache.org/jira/browse/CAMEL-25412
> Project: Camel
> Issue Type: Improvement
> Components: camel-file
> Reporter: Andrea Cosentino
> Assignee: shashank
> Priority: Minor
> Fix For: 4.18.6, 4.22.2, 4.23.0
>
>
> camel-file enforces {{jailStartingDirectory}} with a lexical path-boundary
> check only ({{GenericFileHelper.isWithinDirectory}}, after
> {{FileUtil.compactPath}}). The underlying I/O follows symbolic links, so the
> lexical check and the effective path can diverge when a link sits inside the
> configured directory:
> * Producer - {{GenericFileProducer.createFileName()}} calls
> {{jailedCheck()}}, which validates lexically; {{FileOperations.storeFile()}}
> then writes via {{Files.newByteChannel}} / {{Files.copy}}, which resolve
> links.
> * Local consumer - {{GenericFileConsumer.isWithinStartingDirectory()}}
> returns {{true}} by default and {{FileConsumer}} does not override it; the
> local directory listing resolves links (directly, and into linked
> sub-directories when {{recursive=true}}).
> CAMEL-24627 already added symlink-aware containment
> ({{GenericFileHelper.resolveExistingPathSegments()}}), but only for
> {{localWorkDirectory}} downloads. The remote consumers were given an
> {{isWithinStartingDirectory()}} override in CAMEL-24487; the local file
> producer target and the local consumer listing were not brought to the same
> parity, so this is a consistency / hardening follow-up to CAMEL-24627.
> Proposed change:
> * Add {{GenericFileHelper.isWithinDirectoryResolvingLinks(target, dir)}}
> reusing the existing {{resolveExistingPathSegments()}}.
> * {{FileConsumer}} overrides {{isWithinStartingDirectory()}} with it
> (dangling links skipped).
> * {{FileOperations.storeFile()}} applies it when {{jailStartingDirectory}} is
> on *and* the target is lexically inside the starting directory. The
> lexical-inside guard preserves {{tempFileName=../work/...}}, allowed since
> CAMEL-15544 (see {{FileProduceTempFileNameTest.testParentTempFileName}}).
> Notes:
> * Check-then-write remains non-atomic (a complete solution would open with
> {{NOFOLLOW_LINKS}}); there is a per-file {{toRealPath}} cost; deployments
> that intentionally link files or sub-directories into these directories would
> change behaviour, so this needs an upgrade-guide note
> ({{docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc}})
> and possibly an opt-out.
> * Behaviour parity with CAMEL-24627 / CAMEL-24548 / CAMEL-24549.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)