Marcono1234 commented on code in PR #776:
URL: https://github.com/apache/commons-compress/pull/776#discussion_r4062439201


##########
src/main/java/org/apache/commons/compress/archivers/extractor/Extractor.java:
##########
@@ -217,11 +217,27 @@ final void setBeforeLeafWrite(final Runnable hook) {
     }
 
     /**
-     * Resolves {@code name} against the extraction root and rejects any 
result that escapes it (the lexical zip-slip guard).
+     * Tests whether {@code path} is contained within the canonical extraction 
root, comparing component by component so a
+     * sibling that merely shares a name prefix (for example {@code root-old} 
beside {@code root}) is not treated as contained.
+     */
+    private boolean isWithinRoot(final Path path) {
+        return path.startsWith(rootDirectory);
+    }
+
+    /**
+     * Resolves {@code name} against the extraction root and applies the 
lexical zip-slip guard.
+     *
+     * @return the resolved path within the root, or {@code null} if {@code 
name} resolves to the root itself (for example
+     *         {@code a/..}), which carries nothing to materialize; the caller 
skips such entries rather than writing at or
+     *         replacing the root.
+     * @throws ArchiveException if the resolved path escapes the extraction 
root.
      */
     private Path resolveWithinRoot(final String name) throws ArchiveException {
         final Path resolved = rootDirectory.resolve(name).normalize();
-        if (!resolved.startsWith(rootDirectory)) {
+        if (resolved.equals(rootDirectory)) {

Review Comment:
   Thanks! The tests look really good to me.
   
   ----
   
   > The trailing-dots alias stays documented and fail-closed; the JDK issue is 
JDK-8248430.
   
   Thanks for digging this up; yes that was the existing JDK bug report about 
trailing dots. Though I have privately reported and suggested to the JDK 
maintainers to completely reject trailing dots on Windows (similar to how 
trailing whitespace is already rejected). But I am currently still waiting for 
their evaluation.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to