Skip to content

dlt: Prevent symlink following in offline log storage - Issue #901 - #922

Open
KaramSathishKumar wants to merge 1 commit into
COVESA:masterfrom
KaramSathishKumar:fix/issue-901-symlink
Open

KaramSathishKumar wants to merge 1 commit into
COVESA:masterfrom
KaramSathishKumar:fix/issue-901-symlink

Conversation

@KaramSathishKumar

Copy link
Copy Markdown

Fixes #901

This change prevents offline log storage from following symbolic links when opening log output files.

The change protects log file operations against symlink-based redirection while preserving the existing behavior for regular files.

@KaramSathishKumar

Copy link
Copy Markdown
Author

Without fix (1620f85): Replaced dlt file with a symlink to a protected test file. After triggering offline logging, DLT data was written through the symlink and the target file hash changed. Issue reproduced.

With fix (e451888): Repeated the same test. The protected target remained unchanged and the hash stayed the same. Issue not reproduced with the fix.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Improper Symlink Handling Leading to Arbitrary File Write

1 participant