Commit 604e691
authored
fix(storage): guard collectActiveMemoryPaths against symlink escape (info leak) (#1565)
* fix(storage): guard collectActiveMemoryPaths against symlink escape (info leak)
collectActiveMemoryPaths() (#1497) walked the RECALL_FALLBACK_DIRS memory
category dirs with a raw readdir and no symlink/containment guard. It feeds the
QMD-unavailable filesystem recall fallback, so a category dir symlinked outside
memoryDir (e.g. decisions/ -> an external dir) would be followed, pulling
out-of-store files into recall results. This is the same class of issue PR #1563
(issue #1546) hardened across the other memory-store walkers;
collectActiveMemoryPaths predates that PR and was the one remaining straggler.
Adopt the now-standard containment pattern: resolve the memory root once via
realpath; per directory lstat + skip symlinked/non-dir entries and assert the
realpath stays inside the root before reading; per entry skip symlinks and assert
the file's realpath is inside the root before including it. The shared
assertPathInsideRoot/pathIsInside check is extracted to
utils/path-containment.ts rather than forking a new one.
- Add symlinked-category-dir and symlinked-nested-entry containment tests
(win32-guarded like the existing symlink tests).
- Bump the storage.ts structural-ratchet baseline (#1520) for the added guards.
* fix(storage): isolate per-entry failures in collectActiveMemoryPaths walk
Cursor Bugbot (medium): a containment/realpath failure on a single .md entry
was caught by the directory-wide try/catch, so the deferred subdir recursion
loop never ran — valid nested in-store memories under that dir could be dropped
from QMD fallback recall because one sibling entry was poisoned.
Split the directory-level guard (lstat/realpath/readdir → skip subtree on
failure) from per-entry handling, and wrap the per-.md containment assert in its
own try/catch so a single bad entry only skips itself. Subdir recursion now runs
unconditionally. Mirrors the per-file try/catch in document-scanner.ts scanDir
and consolidation-provenance-check.ts walkMarkdownFiles.
Add a regression test asserting a nested in-store memory is still returned when
its category dir also holds a symlinked-out sibling (win32-guarded). Bump the
storage.ts structural-ratchet baseline for the added lines.1 parent fc5a972 commit 604e691
3 files changed
Lines changed: 202 additions & 16 deletions
File tree
- packages/remnic-core/src
- scripts
Lines changed: 150 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
27 | 27 | | |
28 | 28 | | |
29 | 29 | | |
30 | | - | |
| 30 | + | |
31 | 31 | | |
32 | 32 | | |
33 | 33 | | |
| |||
356 | 356 | | |
357 | 357 | | |
358 | 358 | | |
| 359 | + | |
| 360 | + | |
| 361 | + | |
| 362 | + | |
| 363 | + | |
| 364 | + | |
| 365 | + | |
| 366 | + | |
| 367 | + | |
| 368 | + | |
| 369 | + | |
| 370 | + | |
| 371 | + | |
| 372 | + | |
| 373 | + | |
| 374 | + | |
| 375 | + | |
| 376 | + | |
| 377 | + | |
| 378 | + | |
| 379 | + | |
| 380 | + | |
| 381 | + | |
| 382 | + | |
| 383 | + | |
| 384 | + | |
| 385 | + | |
| 386 | + | |
| 387 | + | |
| 388 | + | |
| 389 | + | |
| 390 | + | |
| 391 | + | |
| 392 | + | |
| 393 | + | |
| 394 | + | |
| 395 | + | |
| 396 | + | |
| 397 | + | |
| 398 | + | |
| 399 | + | |
| 400 | + | |
| 401 | + | |
| 402 | + | |
| 403 | + | |
| 404 | + | |
| 405 | + | |
| 406 | + | |
| 407 | + | |
| 408 | + | |
| 409 | + | |
| 410 | + | |
| 411 | + | |
| 412 | + | |
| 413 | + | |
| 414 | + | |
| 415 | + | |
| 416 | + | |
| 417 | + | |
| 418 | + | |
| 419 | + | |
| 420 | + | |
| 421 | + | |
| 422 | + | |
| 423 | + | |
| 424 | + | |
| 425 | + | |
| 426 | + | |
| 427 | + | |
| 428 | + | |
| 429 | + | |
| 430 | + | |
| 431 | + | |
| 432 | + | |
| 433 | + | |
| 434 | + | |
| 435 | + | |
| 436 | + | |
| 437 | + | |
| 438 | + | |
| 439 | + | |
| 440 | + | |
| 441 | + | |
| 442 | + | |
| 443 | + | |
| 444 | + | |
| 445 | + | |
| 446 | + | |
| 447 | + | |
| 448 | + | |
| 449 | + | |
| 450 | + | |
| 451 | + | |
| 452 | + | |
| 453 | + | |
| 454 | + | |
| 455 | + | |
| 456 | + | |
| 457 | + | |
| 458 | + | |
| 459 | + | |
| 460 | + | |
| 461 | + | |
| 462 | + | |
| 463 | + | |
| 464 | + | |
| 465 | + | |
| 466 | + | |
| 467 | + | |
| 468 | + | |
| 469 | + | |
| 470 | + | |
| 471 | + | |
| 472 | + | |
| 473 | + | |
| 474 | + | |
| 475 | + | |
| 476 | + | |
| 477 | + | |
| 478 | + | |
| 479 | + | |
| 480 | + | |
| 481 | + | |
| 482 | + | |
| 483 | + | |
| 484 | + | |
| 485 | + | |
| 486 | + | |
| 487 | + | |
| 488 | + | |
| 489 | + | |
| 490 | + | |
| 491 | + | |
| 492 | + | |
| 493 | + | |
| 494 | + | |
| 495 | + | |
| 496 | + | |
| 497 | + | |
| 498 | + | |
| 499 | + | |
| 500 | + | |
| 501 | + | |
| 502 | + | |
| 503 | + | |
| 504 | + | |
| 505 | + | |
| 506 | + | |
| 507 | + | |
359 | 508 | | |
360 | 509 | | |
361 | 510 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | | - | |
2 | | - | |
| 1 | + | |
| 2 | + | |
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
| 8 | + | |
8 | 9 | | |
9 | 10 | | |
10 | 11 | | |
| |||
4082 | 4083 | | |
4083 | 4084 | | |
4084 | 4085 | | |
| 4086 | + | |
| 4087 | + | |
| 4088 | + | |
| 4089 | + | |
| 4090 | + | |
| 4091 | + | |
| 4092 | + | |
| 4093 | + | |
| 4094 | + | |
| 4095 | + | |
| 4096 | + | |
| 4097 | + | |
4085 | 4098 | | |
| 4099 | + | |
| 4100 | + | |
| 4101 | + | |
| 4102 | + | |
| 4103 | + | |
4086 | 4104 | | |
4087 | | - | |
4088 | | - | |
4089 | | - | |
4090 | | - | |
4091 | | - | |
4092 | | - | |
4093 | | - | |
| 4105 | + | |
| 4106 | + | |
| 4107 | + | |
| 4108 | + | |
| 4109 | + | |
| 4110 | + | |
| 4111 | + | |
| 4112 | + | |
| 4113 | + | |
| 4114 | + | |
| 4115 | + | |
| 4116 | + | |
| 4117 | + | |
| 4118 | + | |
| 4119 | + | |
| 4120 | + | |
| 4121 | + | |
| 4122 | + | |
| 4123 | + | |
| 4124 | + | |
| 4125 | + | |
| 4126 | + | |
| 4127 | + | |
| 4128 | + | |
4094 | 4129 | | |
| 4130 | + | |
| 4131 | + | |
4095 | 4132 | | |
4096 | 4133 | | |
4097 | | - | |
4098 | | - | |
4099 | | - | |
4100 | | - | |
4101 | | - | |
| 4134 | + | |
| 4135 | + | |
| 4136 | + | |
| 4137 | + | |
| 4138 | + | |
4102 | 4139 | | |
4103 | 4140 | | |
4104 | 4141 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
7 | 7 | | |
8 | 8 | | |
9 | 9 | | |
10 | | - | |
| 10 | + | |
11 | 11 | | |
12 | 12 | | |
13 | 13 | | |
| |||
0 commit comments