Michael Smith has uploaded this change for review. ( 
http://gerrit.cloudera.org:8080/25036


Change subject: IMPALA-15345: Resolve '..' segments before trusted_jar_paths 
check
......................................................................

IMPALA-15345: Resolve '..' segments before trusted_jar_paths check

BackendConfig.isJarPathAllowed() compared the raw driver.url / HDFS
location string against the configured --trusted_jar_paths prefixes
using String#startsWith(). That string is later turned into a Hadoop
Path and resolved by the filesystem, which collapses '.' and '..'
segments. A URL such as '<trusted_dir>/../../secret.jar' therefore
passed the prefix check while actually resolving to a JAR outside the
trusted directory, letting Impala load and execute attacker-controlled
code in impalad.

Resolve both the candidate path and each allowlist entry through
Hadoop's Path class (which performs the same '.'/'..' collapsing)
before comparing, and require the resolved path to be nested inside,
or equal to, a resolved trusted directory rather than merely share a
string prefix.

Testing:
- Added BackendConfigTest cases covering '..'-escape rejection,
  legitimate in-directory '..'/'.' usage, sibling-directory-name
  spoofing, and malformed allowlist entries.

Change-Id: I4288aba344d7d0cd07c9fb8281fc8d3c0490e432
Assisted-by: Claude Sonnet 5 (GitHub Copilot)
---
M fe/src/main/java/org/apache/impala/service/BackendConfig.java
M fe/src/test/java/org/apache/impala/service/BackendConfigTest.java
2 files changed, 88 insertions(+), 3 deletions(-)



  git pull ssh://gerrit.cloudera.org:29418/Impala-ASF refs/changes/36/25036/1
--
To view, visit http://gerrit.cloudera.org:8080/25036
To unsubscribe, visit http://gerrit.cloudera.org:8080/settings

Gerrit-Project: Impala-ASF
Gerrit-Branch: master
Gerrit-MessageType: newchange
Gerrit-Change-Id: I4288aba344d7d0cd07c9fb8281fc8d3c0490e432
Gerrit-Change-Number: 25036
Gerrit-PatchSet: 1
Gerrit-Owner: Michael Smith <[email protected]>

Reply via email to