fix(fs, model): improve symlink resilience in file shortcut (#10739)

Ensure file was a file before the shortcut as well as after... (This was
implied when talking to a correct implementation, but not enforced.)

Make our file opening operations safe by default by ensuring the last
path component is not a symlink.

---------

Signed-off-by: Jakob Borg <jakob@kastelo.net>
This commit is contained in:
Jakob Borg
2026-06-11 18:50:11 +02:00
committed by GitHub
parent 5dbf809a4c
commit a5cbeeafea
4 changed files with 9 additions and 19 deletions
+3
View File
@@ -14,8 +14,11 @@ import (
"path/filepath"
"strconv"
"strings"
"syscall"
)
const alwaysOpenFlags = syscall.O_NOFOLLOW // never open symlinks as the final path component
func (f *BasicFilesystem) CreateSymlink(target, name string) error {
name, err := f.rooted(name)
if err != nil {