Commit df91f45
feat(crypto): warn when SR keystore is a symbolic link
Aligns WalletUtils.loadCredentials with the Lighthouse-style policy:
follow the symlink (preserving compatibility with legitimate SR
deployments that organize keystores via symlinks — e.g. encrypted-
volume mounts, container volume bindings, /opt/tron → /mnt/secrets
layouts), but emit a logger.warn so operators have a chance to notice
if a path they did not expect to be a symlink has become one.
Hard-rejecting would silently break "SR fails to start" on upgrade for
operators using these legitimate patterns; warn-and-proceed surfaces
the situation without forcing a downtime cliff.
The lstat probe uses LinkOption.NOFOLLOW_LINKS so an attacker cannot
hide the symlink by racing the check; if the lstat itself fails for
unrelated reasons (permission, fs error) we silently fall through and
let the subsequent readValue surface the real error.
Tests verify a symlinked keystore still loads end-to-end (the
Lighthouse parity path) and that a regular-file roundtrip is unaffected.1 parent b89790c commit df91f45
2 files changed
Lines changed: 65 additions & 0 deletions
File tree
- crypto/src/main/java/org/tron/keystore
- framework/src/test/java/org/tron/keystore
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
| 11 | + | |
11 | 12 | | |
12 | 13 | | |
| 14 | + | |
13 | 15 | | |
14 | 16 | | |
15 | 17 | | |
| |||
19 | 21 | | |
20 | 22 | | |
21 | 23 | | |
| 24 | + | |
22 | 25 | | |
23 | 26 | | |
24 | 27 | | |
25 | 28 | | |
26 | 29 | | |
27 | 30 | | |
28 | 31 | | |
| 32 | + | |
29 | 33 | | |
30 | 34 | | |
31 | 35 | | |
| |||
117 | 121 | | |
118 | 122 | | |
119 | 123 | | |
| 124 | + | |
120 | 125 | | |
121 | 126 | | |
122 | 127 | | |
123 | 128 | | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
124 | 154 | | |
125 | 155 | | |
126 | 156 | | |
| |||
Lines changed: 35 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
166 | 166 | | |
167 | 167 | | |
168 | 168 | | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
| 185 | + | |
| 186 | + | |
| 187 | + | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
| 191 | + | |
| 192 | + | |
| 193 | + | |
| 194 | + | |
| 195 | + | |
| 196 | + | |
| 197 | + | |
| 198 | + | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
| 202 | + | |
| 203 | + | |
169 | 204 | | |
0 commit comments