]> dgit.raspbian.org Git - dovecot.git/commit
[PATCH 2/5] lib: path-util - Add t_openat_safe() for jailed openat() resolution
authorTimo Sirainen <timo.sirainen@open-xchange.com>
Mon, 4 May 2026 13:08:16 +0000 (13:08 +0000)
committerNoah Meyerhans <noahm@debian.org>
Wed, 16 Sep 2026 19:06:35 +0000 (15:06 -0400)
commit37e5c021f639fe5b85d4667ee3133cec5ba19244
treea66b4a31aa7d42a3ffdd604ec5f092be6a2d4801
parentc296f51dd9a0e2fcb8d6aa1443b18c7de8eca1a0
[PATCH 2/5] lib: path-util - Add t_openat_safe() for jailed openat() resolution

Add a helper that opens a path relative to a directory fd while refusing
any resolution that escapes that directory. Each component is opened with
O_NOFOLLOW so symlinks are detected explicitly rather than transparently
followed; symlinks are then resolved manually and only honoured when their
(recursively resolved) target also stays beneath the base fd. Absolute
symlink targets, leading '/', and '..' past the base are rejected with
errno=ELOOP. Symlink chains are bounded by
PATH_UTIL_OPENAT_SAFE_MAX_SYMLINKS hops.

Anchoring resolution at a caller-held base_fd makes the lookup TOCTOU-safe
even when intermediate path components are mutated on disk concurrently:
the kernel resolves all openat() lookups relative to the original
directory inode that base_fd refers to, so an attacker mutating path
components on the filesystem cannot redirect resolution.

This is the portable counterpart to Linux's openat2() with RESOLVE_BENEATH
and is intended for callers that need to safely look up files under a
user-writable directory (e.g. a Sieve script storage directory).

Gbp-Pq: Name 0002-lib-path-util-Add-t_openat_safe-for-jailed-openat-re.patch
src/lib/path-util.c
src/lib/path-util.h
src/lib/test-path-util.c