Skip to content

don't follow symlinks in the debugger tmp directory - #1575

Open
Keshava-kesh wants to merge 1 commit into
ipython:mainfrom
Keshava-kesh:debugger-tmp-dir-symlink
Open

Keshava-kesh wants to merge 1 commit into
ipython:mainfrom
Keshava-kesh:debugger-tmp-dir-symlink

Conversation

@Keshava-kesh

Copy link
Copy Markdown

Debugger.start only creates its scratch directory when Path(tmp_dir).exists() is false, and get_tmp_directory returns the completely predictable /ipykernel_. Path.exists follows symlinks, so on a host with a shared temp directory another local user can reach that name first and point it at a directory they own; the kernel then skips the mkdir, the 0o700 mode from #1530 never applies, and dumpCell writes the cell source straight through the link. I went back to start after that permissions change and noticed the mkdir is reachable only when the path does not already exist, which is the one case someone else gets to control. Planting the predictable name as a symlink locally confirmed it: start carried on, dumpCell dropped the cell text into the other directory, and a symlink planted under the Murmur2 cell name turned the same write into an overwrite of a file outside the temp tree. Creating the directory first and only accepting an existing one when lstat says it is a real directory owned by this user closes that, and opening the dumped cell with O_NOFOLLOW keeps the file write itself from being redirected; the cell file now lands at 0o600 instead of whatever the umask gives, matching the directory around it. Added two regressions beside the existing debugger tests, both skipped when debugpy is absent and on Windows where symlinks need privileges and O_NOFOLLOW does not exist.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant