fix: restrict path traversal check to file scheme in DEnumerator buildUrl - #377
Conversation
…dUrl 1. DEnumeratorPrivate::buildUrl() 对所有 scheme 的文件名做路径遍历检查,导致 gio trash:/// 后端使用反斜杠分隔的扁平文件名被误判为恶意路径并返回空 URL; 2. 将路径遍历检查限制为仅对 file:/// 或无 scheme 的本地文件系统生效,gio trash:/// 等虚拟文件系统的合法文件名不受影响; 3. 修复手动分区场景下 /media 挂载点的回收站文件无法显示和清空的问题; Log: 修复 buildUrl 路径遍历安全检查误伤 gio trash 反斜杠文件名导致回收站无法显示和清空的问题 PMS: BUG-372733 Bug: https://pms.uniontech.com/bug-view-372733.html
There was a problem hiding this comment.
Sorry @Johnson-zs, you have reached your weekly rate limit of 500000 diff characters.
Please try again later or upgrade to continue using Sourcery
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: Johnson-zs The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
Reviewer's guide (collapsed on small PRs)Reviewer's GuideRestricts the path traversal filename check in DEnumeratorPrivate::buildUrl to only local file (file:/// or no-scheme) URLs so gio trash:/// backends using backslash-separated flat names are not incorrectly rejected, while preserving behavior for real local files. Flow diagram for updated path traversal check in buildUrlflowchart TD
A[buildUrl url,fileName] --> B[create QByteArray fileNameBa]
B --> C[get scheme from url]
C --> D{scheme is empty or file}
D -- yes --> E{fileNameBa contains /, contains \\, equals ., or equals ..}
E -- yes --> F[return empty QUrl]
E -- no --> G[continue building path]
D -- no --> G
G --> H[return constructed QUrl]
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
deepin pr auto review★ 总体评分:100分■ 【总体评价】
■ 【详细分析】
■ 【改进建议代码示例】 diff --git a/src/dfm-io/dfm-io/denumerator.cpp b/src/dfm-io/dfm-io/denumerator.cpp
index d2fe3501..c5aaa639 100644
--- a/src/dfm-io/dfm-io/denumerator.cpp
+++ b/src/dfm-io/dfm-io/denumerator.cpp
@@ -455,10 +455,17 @@ QUrl DEnumeratorPrivate::buildUrl(const QUrl &url, const char *fileName)
return QUrl();
}
- // 拦截路径遍历攻击,防止恶意文件名越权
QByteArray fileNameBa(fileName);
- if (fileNameBa.contains('/') || fileNameBa.contains('\\') || fileNameBa == "." || fileNameBa == "..") {
- return QUrl();
+
+ // 路径遍历检查仅对本地文件系统 (file:/// 或无 scheme) 生效
+ // gio 的 trash:/// 后端对非用户主目录挂载点的回收站文件,使用反斜杠分隔的扁平路径
+ // 作为 GFileInfo 的 standard::name(例如 "\media\user\dev\.Trash-1000\files\x"),
+ // 这是合法的 trash 文件名而非恶意路径,故不应对其做路径遍历拦截。
+ const QString scheme = url.scheme();
+ if (scheme.isEmpty() || scheme == QLatin1String("file")) {
+ if (fileNameBa.contains('/') || fileNameBa.contains('\\') || fileNameBa == "." || fileNameBa == "..") {
+ return QUrl();
+ }
}
QByteArray path; |
|
/forcemerge |
|
This pr force merged! (status: blocked) |
根因分析
DEnumeratorPrivate::buildUrl()中的路径遍历安全检查fileNameBa.contains('\\')对 giotrash:///后端使用反斜杠分隔的扁平文件名(如\media\user\dev\.Trash-1000\files\x)返回空QUrl(""),导致/media挂载点的回收站文件无法显示和清空。fd494fb(PMS #367075, 2026-07-16)引入了该检查QUrl(""),触发kIsNotTrashFileError修复方案
将路径遍历检查限制为仅对
file:///或无 scheme 的本地文件系统生效,trash:///等 gio 虚拟文件系统跳过该检查。改动安全评估
低风险。修改仅限制检查的适用 scheme 范围,不改变
buildUrl()签名或返回值语义。对file:///scheme 行为完全不变。Summary by Sourcery
Bug Fixes: