Marcono1234 commented on code in PR #776:
URL: https://github.com/apache/commons-compress/pull/776#discussion_r4062439201
##########
src/main/java/org/apache/commons/compress/archivers/extractor/Extractor.java:
##########
@@ -217,11 +217,27 @@ final void setBeforeLeafWrite(final Runnable hook) {
}
/**
- * Resolves {@code name} against the extraction root and rejects any
result that escapes it (the lexical zip-slip guard).
+ * Tests whether {@code path} is contained within the canonical extraction
root, comparing component by component so a
+ * sibling that merely shares a name prefix (for example {@code root-old}
beside {@code root}) is not treated as contained.
+ */
+ private boolean isWithinRoot(final Path path) {
+ return path.startsWith(rootDirectory);
+ }
+
+ /**
+ * Resolves {@code name} against the extraction root and applies the
lexical zip-slip guard.
+ *
+ * @return the resolved path within the root, or {@code null} if {@code
name} resolves to the root itself (for example
+ * {@code a/..}), which carries nothing to materialize; the caller
skips such entries rather than writing at or
+ * replacing the root.
+ * @throws ArchiveException if the resolved path escapes the extraction
root.
*/
private Path resolveWithinRoot(final String name) throws ArchiveException {
final Path resolved = rootDirectory.resolve(name).normalize();
- if (!resolved.startsWith(rootDirectory)) {
+ if (resolved.equals(rootDirectory)) {
Review Comment:
Thanks! The tests look really good to me.
----
> The trailing-dots alias stays documented and fail-closed; the JDK issue is
JDK-8248430.
Thanks for digging this up; yes that was the existing JDK bug report about
trailing dots. Though I have privately reported and suggested to the JDK
maintainers to completely reject trailing dots on Windows (similar to how
trailing whitespace is already rejected). But I am currently still waiting for
their evaluation.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]