This is an automated email from the ASF dual-hosted git repository.

juergbi pushed a commit to branch jbilleter/checkout
in repository https://gitbox.apache.org/repos/asf/buildstream.git

commit 243174d61eb3d607f7bb8e21c434cc251c6cd996
Author: Jürg Billeter <[email protected]>
AuthorDate: Fri Oct 2 13:47:45 2026 +0200

    cascache.py: Ensure that `checkout()` doesn't follow directory symlinks
    
    `bst artifact checkout` verifies that the destination is empty. However,
    `bst artifact checkout --force` allows checkout to a non-empty
    directory. Let's not blindly follow pre-existing directory symlinks even
    in that case.
---
 src/buildstream/_cas/cascache.py | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/src/buildstream/_cas/cascache.py b/src/buildstream/_cas/cascache.py
index 1fe7b1d02..489bb938d 100644
--- a/src/buildstream/_cas/cascache.py
+++ b/src/buildstream/_cas/cascache.py
@@ -220,6 +220,11 @@ class CASCache:
         for dirnode in directory.directories:
             _validate_cas_node_name(dirnode.name, names)
             fullpath = os.path.join(dest, dirnode.name)
+            # If the destination is a regular file, `os.makedirs()` will catch 
it.
+            # However, it will not raise an error if it's a valid directory 
symlink,
+            # so check here that we're not unexpectedly following a symlink.
+            if os.path.islink(fullpath):
+                raise CASCacheError(f"Destination already exists and is a 
symlink, not a directory: {fullpath}")
             self.checkout(fullpath, dirnode.digest, can_link=can_link, 
_fetch=False)
 
         for symlinknode in directory.symlinks:

Reply via email to