I'm very pleased to announce the release of our new website and documentation using the new toolchain with Hugo and AsciiDoctor. To get more information about the new toolchain please read the FreeBSD Documentation Project Primer[1], Hugo docs[2] and AsciiDoctor docs[3]. Acknowledgment: Benedict Reuschling <bcr@> Glen Barber <gjb@> Hiroki Sato <hrs@> Li-Wen Hsu <lwhsu@> Sean Chittenden <seanc@> The FreeBSD Foundation [1] https://docs.FreeBSD.org/en/books/fdp-primer/ [2] https://gohugo.io/documentation/ [3] https://docs.asciidoctor.org/home/ Approved by: doceng, core
124 lines
4.9 KiB
Diff
124 lines
4.9 KiB
Diff
--- contrib/libarchive/cpio/bsdcpio.1.orig
|
|
+++ contrib/libarchive/cpio/bsdcpio.1
|
|
@@ -159,7 +159,8 @@
|
|
.It Fl -insecure
|
|
(i and p mode only)
|
|
Disable security checks during extraction or copying.
|
|
-This allows extraction via symbolic links and path names containing
|
|
+This allows extraction via symbolic links, absolute paths,
|
|
+and path names containing
|
|
.Sq ..
|
|
in the name.
|
|
.It Fl J
|
|
--- contrib/libarchive/cpio/cpio.c.orig
|
|
+++ contrib/libarchive/cpio/cpio.c
|
|
@@ -162,6 +162,7 @@
|
|
cpio->extract_flags |= ARCHIVE_EXTRACT_NO_OVERWRITE_NEWER;
|
|
cpio->extract_flags |= ARCHIVE_EXTRACT_SECURE_SYMLINKS;
|
|
cpio->extract_flags |= ARCHIVE_EXTRACT_SECURE_NODOTDOT;
|
|
+ cpio->extract_flags |= ARCHIVE_EXTRACT_SECURE_NOABSOLUTEPATHS;
|
|
cpio->extract_flags |= ARCHIVE_EXTRACT_PERM;
|
|
cpio->extract_flags |= ARCHIVE_EXTRACT_FFLAGS;
|
|
cpio->extract_flags |= ARCHIVE_EXTRACT_ACL;
|
|
@@ -231,6 +232,7 @@
|
|
case OPTION_INSECURE:
|
|
cpio->extract_flags &= ~ARCHIVE_EXTRACT_SECURE_SYMLINKS;
|
|
cpio->extract_flags &= ~ARCHIVE_EXTRACT_SECURE_NODOTDOT;
|
|
+ cpio->extract_flags &= ~ARCHIVE_EXTRACT_SECURE_NOABSOLUTEPATHS;
|
|
break;
|
|
case 'L': /* GNU cpio */
|
|
cpio->option_follow_links = 1;
|
|
@@ -265,6 +267,7 @@
|
|
"Cannot use both -p and -%c", cpio->mode);
|
|
cpio->mode = opt;
|
|
cpio->extract_flags &= ~ARCHIVE_EXTRACT_SECURE_NODOTDOT;
|
|
+ cpio->extract_flags &= ~ARCHIVE_EXTRACT_SECURE_NOABSOLUTEPATHS;
|
|
break;
|
|
case OPTION_PRESERVE_OWNER:
|
|
cpio->extract_flags |= ARCHIVE_EXTRACT_OWNER;
|
|
--- contrib/libarchive/libarchive/archive.h.orig
|
|
+++ contrib/libarchive/libarchive/archive.h
|
|
@@ -477,6 +477,8 @@
|
|
#define ARCHIVE_EXTRACT_NO_OVERWRITE_NEWER (0x0800)
|
|
/* Detect blocks of 0 and write holes instead. */
|
|
#define ARCHIVE_EXTRACT_SPARSE (0x1000)
|
|
+/* Default: Do not reject entries with absolute paths */
|
|
+#define ARCHIVE_EXTRACT_SECURE_NOABSOLUTEPATHS (0x10000)
|
|
|
|
__LA_DECL int archive_read_extract(struct archive *, struct archive_entry *,
|
|
int flags);
|
|
--- contrib/libarchive/libarchive/archive_write_disk.3.orig
|
|
+++ contrib/libarchive/libarchive/archive_write_disk.3
|
|
@@ -169,6 +169,9 @@
|
|
Note that paths ending in
|
|
.Pa ..
|
|
always cause an error, regardless of this flag.
|
|
+.It Cm ARCHIVE_EXTRACT_SECURE_NOABSOLUTEPATHS
|
|
+Refuse to extract an absolute path.
|
|
+The default is to not refuse such paths.
|
|
.It Cm ARCHIVE_EXTRACT_SPARSE
|
|
Scan data for blocks of NUL bytes and try to recreate them with holes.
|
|
This results in sparse files, independent of whether the archive format
|
|
--- contrib/libarchive/libarchive/archive_write_disk.c.orig
|
|
+++ contrib/libarchive/libarchive/archive_write_disk.c
|
|
@@ -1649,8 +1649,9 @@
|
|
/*
|
|
* Canonicalize the pathname. In particular, this strips duplicate
|
|
* '/' characters, '.' elements, and trailing '/'. It also raises an
|
|
- * error for an empty path, a trailing '..' or (if _SECURE_NODOTDOT is
|
|
- * set) any '..' in the path.
|
|
+ * error for an empty path, a trailing '..', (if _SECURE_NODOTDOT is
|
|
+ * set) any '..' in the path or (if ARCHIVE_EXTRACT_SECURE_NOABSOLUTEPATHS
|
|
+ * is set) if the path is absolute.
|
|
*/
|
|
static int
|
|
cleanup_pathname(struct archive_write_disk *a)
|
|
@@ -1670,8 +1671,15 @@
|
|
return (ARCHIVE_FAILED);
|
|
#endif
|
|
/* Skip leading '/'. */
|
|
- if (*src == '/')
|
|
+ if (*src == '/') {
|
|
+ if (a->flags & ARCHIVE_EXTRACT_SECURE_NOABSOLUTEPATHS) {
|
|
+ archive_set_error(&a->archive, ARCHIVE_ERRNO_MISC,
|
|
+ "Path is absolute");
|
|
+ return (ARCHIVE_FAILED);
|
|
+ }
|
|
+
|
|
separator = *src++;
|
|
+ }
|
|
|
|
/* Scan the pathname one element at a time. */
|
|
for (;;) {
|
|
--- contrib/libarchive/libarchive/test/test_write_disk_secure.c.orig
|
|
+++ contrib/libarchive/libarchive/test/test_write_disk_secure.c
|
|
@@ -178,6 +178,29 @@
|
|
assert(S_ISDIR(st.st_mode));
|
|
archive_entry_free(ae);
|
|
|
|
+ /*
|
|
+ * Without security checks, we should be able to
|
|
+ * extract an absolute path.
|
|
+ */
|
|
+ assert((ae = archive_entry_new()) != NULL);
|
|
+ archive_entry_copy_pathname(ae, "/tmp/libarchive_test-test_write_disk_secure-absolute_path.tmp");
|
|
+ archive_entry_set_mode(ae, S_IFREG | 0777);
|
|
+ assert(0 == archive_write_header(a, ae));
|
|
+ assert(0 == archive_write_finish_entry(a));
|
|
+ assertFileExists("/tmp/libarchive_test-test_write_disk_secure-absolute_path.tmp");
|
|
+ assert(0 == unlink("/tmp/libarchive_test-test_write_disk_secure-absolute_path.tmp"));
|
|
+
|
|
+ /* But with security checks enabled, this should fail. */
|
|
+ assert(archive_entry_clear(ae) != NULL);
|
|
+ archive_entry_copy_pathname(ae, "/tmp/libarchive_test-test_write_disk_secure-absolute_path.tmp");
|
|
+ archive_entry_set_mode(ae, S_IFREG | 0777);
|
|
+ archive_write_disk_set_options(a, ARCHIVE_EXTRACT_SECURE_NOABSOLUTEPATHS);
|
|
+ failure("Extracting an absolute path should fail here.");
|
|
+ assertEqualInt(ARCHIVE_FAILED, archive_write_header(a, ae));
|
|
+ archive_entry_free(ae);
|
|
+ assert(0 == archive_write_finish_entry(a));
|
|
+ assertFileNotExists("/tmp/libarchive_test-test_write_disk_secure-absolute_path.tmp");
|
|
+
|
|
assert(0 == archive_write_finish(a));
|
|
|
|
/* Test the entries on disk. */
|