[PATCH 2/2] lib-sieve: storage: file - Validate script stat path through dir_fd
Extend the symlink-escape protection added in the previous commit to the
stat performed by sieve_file_script_open(): an "include :personal" lookup
or any other indirect path that triggers sieve_file_script_stat() also
needs to refuse a symlink whose target leaves the personal storage
directory, otherwise the existence check succeeds and the file is opened
later via the safe path with an unhelpful "permission denied".
Add sieve_file_script_stat_safe(), which uses fstatat(AT_SYMLINK_NOFOLLOW)
to obtain the entry's own stat (lnk_st) and then, only if the entry is a
symlink, opens it through sieve_file_storage_open_safe() to validate the
target stays inside dir_fd and to fetch the resolved target's stat (st)
via fstat(). Non-symlink entries skip the open entirely.
Use the new helper in sieve_file_script_open() whenever fstorage->dir_fd
is available, falling back to the unsafe lstat+stat variant for
non-personal or single-file storages.
Gbp-Pq: Name 0002-lib-sieve-storage-file-Validate-script-stat-path-thr.patch