]> git.ipfire.org Git - thirdparty/libarchive.git/commitdiff
Merge pull request #3032 from stoeckmann/dotdot
authorTim Kientzle <kientzle@acm.org>
Sat, 16 May 2026 16:39:31 +0000 (09:39 -0700)
committerMartin Matuska <martin@matuska.de>
Tue, 23 Jun 2026 08:28:50 +0000 (10:28 +0200)
Port iso9660 fix for `..` (dot dot) path normalization to mtree and xar

(cherry picked from commit 89a6d760c1f6f4f840f86ee22b12a2d1973af157)

Makefile.am
libarchive/archive_write_set_format_mtree.c
libarchive/archive_write_set_format_xar.c
libarchive/test/CMakeLists.txt
libarchive/test/test_write_format_mtree_dotdot.c [new file with mode: 0644]
libarchive/test/test_write_format_xar.c

index cf54b4e5490bf8a9b19a688ae27cae5cf3020c5e..158787ebe142a667e5fb4a05a287d88bee135c76 100644 (file)
@@ -670,6 +670,7 @@ libarchive_test_SOURCES= \
        libarchive/test/test_write_format_mtree_absolute_path.c \
        libarchive/test/test_write_format_mtree_classic.c \
        libarchive/test/test_write_format_mtree_classic_indent.c\
+       libarchive/test/test_write_format_mtree_dotdot.c \
        libarchive/test/test_write_format_mtree_fflags.c \
        libarchive/test/test_write_format_mtree_no_separator.c \
        libarchive/test/test_write_format_mtree_preset_digests.c \
index 0a00a3550bbd2d55c6b01bbd3d8d9f8f8311b781..1c6c13fc655f2ddd2152831d2a1c0300d2acba8e 100644 (file)
@@ -1884,20 +1884,29 @@ mtree_entry_setup_filenames(struct archive_write *a, struct mtree_entry *file,
                                 *     --> 'dir/dir2/'
                                 */
                                char *rp = p -1;
+                               size_t off;
+                               for (off = 4; p[off] == '/'; off++)
+                                       ;
                                while (rp >= dirname) {
                                        if (*rp == '/')
                                                break;
                                        --rp;
                                }
                                if (rp > dirname) {
-                                       strcpy(rp, p+3);
+                                       memmove(rp + 1, p + off, strlen(p + off) + 1);
                                        p = rp;
                                } else {
-                                       strcpy(dirname, p+4);
+                                       memmove(dirname, p + off, strlen(p + off) + 1);
                                        p = dirname;
                                }
                        } else
                                p++;
+               } else if (p == dirname && p[0] == '.' && p[1] == '.' && p[2] == '/') {
+                       size_t off;
+                       for (off = 3; p[off] == '/'; off++)
+                               ;
+                       memmove(dirname, p + off, strlen(p + off) + 1);
+                       p = dirname;
                } else
                        p++;
        }
index e7281d0b5965cae6c0d854b0106d23b748447d6a..c9d9d686df773e87f0a65af6340c4607b33216da 100644 (file)
@@ -2205,20 +2205,29 @@ file_gen_utility_names(struct archive_write *a, struct file *file)
                                 *     --> 'dir/dir2/'
                                 */
                                char *rp = p -1;
+                               size_t off;
+                               for (off = 4; p[off] == '/'; off++)
+                                       ;
                                while (rp >= dirname) {
                                        if (*rp == '/')
                                                break;
                                        --rp;
                                }
                                if (rp > dirname) {
-                                       memmove(rp, p+3, strlen(p+3) + 1);
+                                       memmove(rp + 1, p + off, strlen(p + off) + 1);
                                        p = rp;
                                } else {
-                                       memmove(dirname, p+4, strlen(p+4) + 1);
+                                       memmove(dirname, p + off, strlen(p + off) + 1);
                                        p = dirname;
                                }
                        } else
                                p++;
+               } else if (p == dirname && p[0] == '.' && p[1] == '.' && p[2] == '/') {
+                       size_t off;
+                       for (off = 3; p[off] == '/'; off++)
+                               ;
+                       memmove(dirname, p + off, strlen(p + off) + 1);
+                       p = dirname;
                } else
                        p++;
        }
index f6f5beba7880b6d49274722548634af42a94eab2..20a20bafb3e497f8369ceeefdc409f5d72e617e4 100644 (file)
@@ -302,6 +302,7 @@ IF(ENABLE_TEST)
     test_write_format_mtree_absolute_path.c
     test_write_format_mtree_classic.c
     test_write_format_mtree_classic_indent.c
+    test_write_format_mtree_dotdot.c
     test_write_format_mtree_fflags.c
     test_write_format_mtree_no_separator.c
     test_write_format_mtree_preset_digests.c
diff --git a/libarchive/test/test_write_format_mtree_dotdot.c b/libarchive/test/test_write_format_mtree_dotdot.c
new file mode 100644 (file)
index 0000000..731b114
--- /dev/null
@@ -0,0 +1,103 @@
+/*-
+ * Copyright (c) 2026 Tobias Stoeckmann
+ * All rights reserved.
+ *
+ * Redistribution and use in source and binary forms, with or without
+ * modification, are permitted provided that the following conditions
+ * are met:
+ * 1. Redistributions of source code must retain the above copyright
+ *    notice, this list of conditions and the following disclaimer
+ *    in this position and unchanged.
+ * 2. Redistributions in binary form must reproduce the above copyright
+ *    notice, this list of conditions and the following disclaimer in the
+ *    documentation and/or other materials provided with the distribution.
+ *
+ * THIS SOFTWARE IS PROVIDED BY THE AUTHOR(S) ``AS IS'' AND ANY EXPRESS OR
+ * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
+ * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
+ * IN NO EVENT SHALL THE AUTHOR(S) BE LIABLE FOR ANY DIRECT, INDIRECT,
+ * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
+ * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
+ * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
+ * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
+ * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
+ * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
+ */
+
+#include "test.h"
+
+#ifdef HAVE_SYS_STAT_H
+#include <sys/stat.h>
+#endif
+
+static char buff[4096];
+
+DEFINE_TEST(test_write_format_mtree_dotdot)
+{
+       struct archive_entry *ae;
+       struct archive* a;
+       size_t used;
+
+       /* Create an mtree format archive. */
+       assert((a = archive_write_new()) != NULL);
+       assertEqualIntA(a, ARCHIVE_OK, archive_write_set_format_mtree(a));
+       assertEqualIntA(a, ARCHIVE_OK,
+           archive_write_open_memory(a, buff, sizeof(buff)-1, &used));
+
+       /* Write "./dir0/dir1" directory.  */
+       assert((ae = archive_entry_new()) != NULL);
+       archive_entry_copy_pathname(ae, "./dir0/dir1");
+       archive_entry_set_mode(ae, AE_IFDIR | 0755);
+       assertEqualIntA(a, ARCHIVE_OK, archive_write_header(a, ae));
+       archive_entry_free(ae);
+
+       /* Write "dir0/../../dir0/dir1/file1" file.  */
+       assert((ae = archive_entry_new()) != NULL);
+       archive_entry_copy_pathname(ae, "dir0/../../dir0/dir1/file1");
+       archive_entry_set_size(ae, 0);
+       archive_entry_set_mode(ae, AE_IFREG | 0644);
+       assertEqualIntA(a, ARCHIVE_OK, archive_write_header(a, ae));
+       archive_entry_free(ae);
+
+       /* Write "dir0/..//dir0/dir1/file2" file.  */
+       assert((ae = archive_entry_new()) != NULL);
+       archive_entry_copy_pathname(ae, "dir0/..//dir0/dir1/file2");
+       archive_entry_set_size(ae, 0);
+       archive_entry_set_mode(ae, AE_IFREG | 0644);
+       assertEqualIntA(a, ARCHIVE_OK, archive_write_header(a, ae));
+       archive_entry_free(ae);
+
+       assertEqualIntA(a, ARCHIVE_OK, archive_write_close(a));
+       assertEqualInt(ARCHIVE_OK, archive_write_free(a));
+
+       /*
+        * Read the data and check it.
+        */
+       assert((a = archive_read_new()) != NULL);
+       assertEqualIntA(a, ARCHIVE_OK, archive_read_support_format_all(a));
+       assertEqualIntA(a, ARCHIVE_OK, archive_read_support_filter_all(a));
+       assertEqualIntA(a, ARCHIVE_OK, archive_read_open_memory(a, buff, used));
+
+       /* Read "./dir0/dir1" directory. */
+       assertEqualIntA(a, ARCHIVE_OK, archive_read_next_header(a, &ae));
+       failure("The path should be just \"./dir0/dir1\"");
+       assertEqualString(archive_entry_pathname(ae), "./dir0/dir1");
+       assertEqualInt(archive_entry_mode(ae), AE_IFDIR | 0755);
+
+       /* Read "./dir0/dir1/file1" file. */
+       assertEqualIntA(a, ARCHIVE_OK, archive_read_next_header(a, &ae));
+       failure("The path should be just \"./dir0/dir1/file1\"");
+       assertEqualString(archive_entry_pathname(ae), "./dir0/dir1/file1");
+       assertEqualInt(archive_entry_mode(ae), AE_IFREG | 0644);
+
+       /* Read "./dir0/dir1/file2" file. */
+       assertEqualIntA(a, ARCHIVE_OK, archive_read_next_header(a, &ae));
+       failure("The path should be just \"./dir0/dir1/file2\"");
+       assertEqualString(archive_entry_pathname(ae), "./dir0/dir1/file2");
+       assertEqualInt(archive_entry_size(ae), 0);
+       assertEqualInt(archive_entry_mode(ae), AE_IFREG | 0644);
+
+       assertEqualIntA(a, ARCHIVE_OK, archive_read_close(a));
+       assertEqualInt(ARCHIVE_OK, archive_read_free(a));
+}
+
index a3e2577de9649f4f81af994872fb5a3c3683384e..a11d2d6a2477a2b98ca26587a76081f01a8c1a1f 100644 (file)
@@ -93,13 +93,13 @@ test_xar(const char *option)
        archive_entry_free(ae);
 
        /*
-        * "dir/file3" has a bunch of attributes and 8 bytes of data.
+        * "dir/file" has a bunch of attributes and 8 bytes of data.
         */
        assert((ae = archive_entry_new()) != NULL);
        archive_entry_set_atime(ae, 2, 20);
        archive_entry_set_ctime(ae, 4, 40);
        archive_entry_set_mtime(ae, 5, 50);
-       archive_entry_copy_pathname(ae, "dir/file");
+       archive_entry_copy_pathname(ae, "dir/../../dir/file");
        archive_entry_set_mode(ae, AE_IFREG | 0755);
        archive_entry_set_size(ae, 8);
        assertEqualIntA(a, ARCHIVE_OK, archive_write_header(a, ae));
@@ -113,7 +113,7 @@ test_xar(const char *option)
        archive_entry_set_atime(ae, 2, 20);
        archive_entry_set_ctime(ae, 4, 40);
        archive_entry_set_mtime(ae, 5, 50);
-       archive_entry_copy_pathname(ae, "dir/dir2/file4");
+       archive_entry_copy_pathname(ae, "dir/..//dir/dir2/file4");
        archive_entry_copy_hardlink(ae, "file");
        archive_entry_set_mode(ae, AE_IFREG | 0755);
        archive_entry_set_nlink(ae, 2);