New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

When canonicalizing classpath URIs, use a bogus root path. #4543

Merged
merged 1 commit into from Mar 24, 2017

Conversation

Projects
None yet
2 participants
@headius
Member

headius commented Mar 23, 2017

This prevents in-classloader paths from expanding using real
filesystem paths that may resolve symlinks.

Fixes #4145.

When canonicalizing classpath URIs, use a bogus root path.
This prevents in-classloader paths from expanding using real
filesystem paths that may resolve symlinks.

Fixes #4145.

@headius headius added this to the JRuby 9.1.9.0 milestone Mar 23, 2017

@headius headius merged commit 949da51 into jruby:master Mar 24, 2017

1 check failed

continuous-integration/travis-ci/pr The Travis CI build failed
Details

@headius headius deleted the headius:fix-4145 branch Mar 24, 2017

@presidentbeef

This comment has been minimized.

Show comment
Hide comment
@presidentbeef

presidentbeef Mar 24, 2017

Thanks @headius! Now just need #4274 and Brakeman Pro can finally use an up-to-date version of JRuby 😀

Thanks @headius! Now just need #4274 and Brakeman Pro can finally use an up-to-date version of JRuby 😀

if (classloaderURI) {
String fakePrefix = "/THIS_IS_A_FAKE_PATH_FOR_JRUBY";
relativePath = canonicalizePath(fakePrefix + "/" + relativePath).substring(fakePrefix.length());

This comment has been minimized.

@presidentbeef

presidentbeef May 25, 2017

@headius this ends up being off by two characters on Windows because the canonicalized path will begin with C:. So you end up with classpath:BY\yourpathhere.rb. Sorry I couldn't test ahead of time.

@presidentbeef

presidentbeef May 25, 2017

@headius this ends up being off by two characters on Windows because the canonicalized path will begin with C:. So you end up with classpath:BY\yourpathhere.rb. Sorry I couldn't test ahead of time.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment