Repository navigation
don't follow symlinks in the debugger tmp directory - #1575
Open
Keshava-kesh wants to merge 1 commit into
Open
Keshava-kesh wants to merge 1 commit into
Keshava-kesh wants to merge 1 commit into
Conversation
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Debugger.start only creates its scratch directory when Path(tmp_dir).exists() is false, and get_tmp_directory returns the completely predictable /ipykernel_. Path.exists follows symlinks, so on a host with a shared temp directory another local user can reach that name first and point it at a directory they own; the kernel then skips the mkdir, the 0o700 mode from #1530 never applies, and dumpCell writes the cell source straight through the link. I went back to start after that permissions change and noticed the mkdir is reachable only when the path does not already exist, which is the one case someone else gets to control. Planting the predictable name as a symlink locally confirmed it: start carried on, dumpCell dropped the cell text into the other directory, and a symlink planted under the Murmur2 cell name turned the same write into an overwrite of a file outside the temp tree. Creating the directory first and only accepting an existing one when lstat says it is a real directory owned by this user closes that, and opening the dumped cell with O_NOFOLLOW keeps the file write itself from being redirected; the cell file now lands at 0o600 instead of whatever the umask gives, matching the directory around it. Added two regressions beside the existing debugger tests, both skipped when debugpy is absent and on Windows where symlinks need privileges and O_NOFOLLOW does not exist.