]> dgit.raspbian.org Git - dovecot.git/commit
[PATCH 2/2] lib-sieve: storage: file - Validate script stat path through dir_fd
authorTimo Sirainen <timo.sirainen@open-xchange.com>
Mon, 4 May 2026 13:10:13 +0000 (13:10 +0000)
committerNoah Meyerhans <noahm@debian.org>
Wed, 16 Sep 2026 19:06:35 +0000 (15:06 -0400)
commitf122d8933686e8477686d8b02e8d819eecfc9ee4
treebf7b5e304f226c3503703a687830aeee31ce722a
parent858e97c48245c42fedb7cd6cc8b0b38934be37fb
[PATCH 2/2] lib-sieve: storage: file - Validate script stat path through dir_fd

Extend the symlink-escape protection added in the previous commit to the
stat performed by sieve_file_script_open(): an "include :personal" lookup
or any other indirect path that triggers sieve_file_script_stat() also
needs to refuse a symlink whose target leaves the personal storage
directory, otherwise the existence check succeeds and the file is opened
later via the safe path with an unhelpful "permission denied".

Add sieve_file_script_stat_safe(), which uses fstatat(AT_SYMLINK_NOFOLLOW)
to obtain the entry's own stat (lnk_st) and then, only if the entry is a
symlink, opens it through sieve_file_storage_open_safe() to validate the
target stays inside dir_fd and to fetch the resolved target's stat (st)
via fstat(). Non-symlink entries skip the open entirely.

Use the new helper in sieve_file_script_open() whenever fstorage->dir_fd
is available, falling back to the unsafe lstat+stat variant for
non-personal or single-file storages.

Gbp-Pq: Name 0002-lib-sieve-storage-file-Validate-script-stat-path-thr.patch
pigeonhole/src/lib-sieve/storage/file/sieve-file-script.c