Only return overlay files that refer to a path within the overlay

Signed-off-by: Jonathon Anderson <janderson@ciq.com>
This commit is contained in:
Jonathon Anderson
2025-07-14 22:01:50 -06:00
parent e089fe0101
commit 7b2c0901ed
2 changed files with 18 additions and 4 deletions

View File

@@ -66,8 +66,22 @@ func (overlay Overlay) Rootfs() string {
//
// Returns:
// - The full path to the specified file in the overlay's rootfs.
// If the specified path does not exist in the overlay, the empty string is returned.
func (overlay Overlay) File(filePath string) string {
return path.Join(overlay.Rootfs(), filePath)
rootfs := overlay.Rootfs()
fullPath := path.Join(rootfs, filePath)
cleanPath := filepath.Clean(fullPath)
cleanRootfs := filepath.Clean(rootfs)
rel, err := filepath.Rel(cleanRootfs, cleanPath)
if err != nil {
return ""
}
if strings.HasPrefix(rel, "..") {
return ""
}
return cleanPath
}
// Exists checks whether the overlay path exists and is a directory.

View File

@@ -259,9 +259,9 @@ func deleteOverlay() usecase.Interactor {
func deleteOverlayFile() usecase.Interactor {
type deleteOverlayFileInput struct {
Name string `path:"name" required:"true" description:"Name of overlay to get a file from"`
Path string `query:"path" required:"true" description:"Path to file to get from an overlay"`
Force bool `query:"force" default:"false" description:"Whether to forcely delete a overlay, default:'false'"`
Name string `path:"name" required:"true" description:"Name of overlay to delete a file from"`
Path string `query:"path" required:"true" description:"Path to file to delete from an overlay"`
Force bool `query:"force" default:"false" description:"Whether to forcefully delete an overlay file, default:'false'"`
Cleanup bool `query:"cleanup" default:"false" description:"Whether to cleanup empty parent directories, default:'false'"`
}