|
1 | 1 | package extract_test |
2 | 2 |
|
3 | 3 | import ( |
| 4 | + "archive/tar" |
| 5 | + "archive/zip" |
4 | 6 | "bytes" |
5 | 7 | "context" |
6 | 8 | "fmt" |
@@ -113,6 +115,128 @@ func TestZipSlipHardening(t *testing.T) { |
113 | 115 | }) |
114 | 116 | } |
115 | 117 |
|
| 118 | +func mkTempDir(t *testing.T) *paths.Path { |
| 119 | + tmp, err := paths.MkTempDir("", "test") |
| 120 | + require.NoError(t, err) |
| 121 | + t.Cleanup(func() { tmp.RemoveAll() }) |
| 122 | + return tmp |
| 123 | +} |
| 124 | + |
| 125 | +func TestSymLinkMazeHardening(t *testing.T) { |
| 126 | + addTarSymlink := func(t *testing.T, tw *tar.Writer, new, old string) { |
| 127 | + err := tw.WriteHeader(&tar.Header{ |
| 128 | + Mode: 0o0777, Typeflag: tar.TypeSymlink, Name: new, Linkname: old, |
| 129 | + }) |
| 130 | + require.NoError(t, err) |
| 131 | + } |
| 132 | + addZipSymlink := func(t *testing.T, zw *zip.Writer, new, old string) { |
| 133 | + h := &zip.FileHeader{Name: new, Method: zip.Deflate} |
| 134 | + h.SetMode(os.ModeSymlink) |
| 135 | + w, err := zw.CreateHeader(h) |
| 136 | + require.NoError(t, err) |
| 137 | + _, err = w.Write([]byte(old)) |
| 138 | + require.NoError(t, err) |
| 139 | + } |
| 140 | + |
| 141 | + t.Run("TarWithSymlinkToAbsPath", func(t *testing.T) { |
| 142 | + // Create target dir |
| 143 | + tmp := mkTempDir(t) |
| 144 | + targetDir := tmp.Join("test") |
| 145 | + require.NoError(t, targetDir.Mkdir()) |
| 146 | + |
| 147 | + // Make a tar archive with symlink maze |
| 148 | + outputTar := bytes.NewBuffer(nil) |
| 149 | + tw := tar.NewWriter(outputTar) |
| 150 | + addTarSymlink(t, tw, "aaa", tmp.String()) |
| 151 | + addTarSymlink(t, tw, "aaa/sym", "something") |
| 152 | + require.NoError(t, tw.Close()) |
| 153 | + |
| 154 | + // Run extract |
| 155 | + extractor := extract.Extractor{FS: &LoggingFS{}} |
| 156 | + require.Error(t, extractor.Tar(context.Background(), outputTar, targetDir.String(), nil)) |
| 157 | + require.NoFileExists(t, tmp.Join("sym").String()) |
| 158 | + }) |
| 159 | + |
| 160 | + t.Run("ZipWithSymlinkToAbsPath", func(t *testing.T) { |
| 161 | + // Create target dir |
| 162 | + tmp := mkTempDir(t) |
| 163 | + targetDir := tmp.Join("test") |
| 164 | + require.NoError(t, targetDir.Mkdir()) |
| 165 | + |
| 166 | + // Make a zip archive with symlink maze |
| 167 | + outputZip := bytes.NewBuffer(nil) |
| 168 | + zw := zip.NewWriter(outputZip) |
| 169 | + addZipSymlink(t, zw, "aaa", tmp.String()) |
| 170 | + addZipSymlink(t, zw, "aaa/sym", "something") |
| 171 | + require.NoError(t, zw.Close()) |
| 172 | + |
| 173 | + // Run extract |
| 174 | + extractor := extract.Extractor{FS: &LoggingFS{}} |
| 175 | + err := extractor.Zip(context.Background(), outputZip, targetDir.String(), nil) |
| 176 | + require.NoFileExists(t, tmp.Join("sym").String()) |
| 177 | + require.Error(t, err) |
| 178 | + }) |
| 179 | + |
| 180 | + t.Run("TarWithSymlinkToRelativeExternalPath", func(t *testing.T) { |
| 181 | + // Create target dir |
| 182 | + tmp := mkTempDir(t) |
| 183 | + targetDir := tmp.Join("test") |
| 184 | + require.NoError(t, targetDir.Mkdir()) |
| 185 | + checkDir := tmp.Join("secret") |
| 186 | + require.NoError(t, checkDir.MkdirAll()) |
| 187 | + |
| 188 | + // Make a tar archive with regular symlink maze |
| 189 | + outputTar := bytes.NewBuffer(nil) |
| 190 | + tw := tar.NewWriter(outputTar) |
| 191 | + addTarSymlink(t, tw, "aaa", "../secret") |
| 192 | + addTarSymlink(t, tw, "aaa/sym", "something") |
| 193 | + require.NoError(t, tw.Close()) |
| 194 | + |
| 195 | + extractor := extract.Extractor{FS: &LoggingFS{}} |
| 196 | + require.Error(t, extractor.Tar(context.Background(), outputTar, targetDir.String(), nil)) |
| 197 | + require.NoFileExists(t, checkDir.Join("sym").String()) |
| 198 | + }) |
| 199 | + |
| 200 | + t.Run("TarWithSymlinkToInternalPath", func(t *testing.T) { |
| 201 | + // Create target dir |
| 202 | + tmp := mkTempDir(t) |
| 203 | + targetDir := tmp.Join("test") |
| 204 | + require.NoError(t, targetDir.Mkdir()) |
| 205 | + |
| 206 | + // Make a tar archive with regular symlink maze |
| 207 | + outputTar := bytes.NewBuffer(nil) |
| 208 | + tw := tar.NewWriter(outputTar) |
| 209 | + require.NoError(t, tw.WriteHeader(&tar.Header{Mode: 0o0777, Typeflag: tar.TypeDir, Name: "tmp"})) |
| 210 | + addTarSymlink(t, tw, "aaa", "tmp") |
| 211 | + addTarSymlink(t, tw, "aaa/sym", "something") |
| 212 | + require.NoError(t, tw.Close()) |
| 213 | + |
| 214 | + extractor := extract.Extractor{FS: &LoggingFS{}} |
| 215 | + require.NoError(t, extractor.Tar(context.Background(), outputTar, targetDir.String(), nil)) |
| 216 | + require.FileExists(t, targetDir.Join("tmp", "sym").String()) |
| 217 | + }) |
| 218 | + |
| 219 | + t.Run("TarWithSymlinkToExternalPathWithoutMazing", func(t *testing.T) { |
| 220 | + // Create target dir |
| 221 | + tmp := mkTempDir(t) |
| 222 | + targetDir := tmp.Join("test") |
| 223 | + require.NoError(t, targetDir.Mkdir()) |
| 224 | + |
| 225 | + // Make a tar archive with valid symlink maze |
| 226 | + outputTar := bytes.NewBuffer(nil) |
| 227 | + tw := tar.NewWriter(outputTar) |
| 228 | + require.NoError(t, tw.WriteHeader(&tar.Header{Mode: 0o0777, Typeflag: tar.TypeDir, Name: "tmp"})) |
| 229 | + addTarSymlink(t, tw, "aaa", "../tmp") |
| 230 | + require.NoError(t, tw.Close()) |
| 231 | + |
| 232 | + extractor := extract.Extractor{FS: &LoggingFS{}} |
| 233 | + require.NoError(t, extractor.Tar(context.Background(), outputTar, targetDir.String(), nil)) |
| 234 | + st, err := targetDir.Join("aaa").Lstat() |
| 235 | + require.NoError(t, err) |
| 236 | + require.Equal(t, "aaa", st.Name()) |
| 237 | + }) |
| 238 | +} |
| 239 | + |
116 | 240 | // MockDisk is a disk that chroots to a directory |
117 | 241 | type MockDisk struct { |
118 | 242 | Base string |
|
0 commit comments