Skip to content

security: handle-based destination checks against junction races #81

Description

@nextestudios

Summary

Replace path-based reparse checks in extraction and file operations with handle-based verification (FILE_FLAG_OPEN_REPARSE_POINT) close to each write.

Motivation

Documented limitation: a same-privilege process could swap a folder for a junction between revalidation and the final move.

Requirements

  • Open parent directories by handle, verify they are not reparse points, create/move relative to verified handles where possible.
  • Document the remaining limits in docs/security-model.md.

Controller UX

No UX change.

Technical Notes

DestinationGuard and the new operation engine.

Acceptance Criteria

  • Adversarial Windows integration test cannot redirect writes via a racing junction swap.

Testing

Unit tests for new branches and for every bug reproduced before a fix (no trivial variations, see AGENTS.md). Adversarial Windows integration tests.

Dependencies

  • None

Priority: medium · Milestone: 9 · 1.0 Readiness

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: archivesArchive extraction and creationarea: filesystemFile system access and Windows file semanticsmoscow: mustMoSCoW: required for 1.0type: securitySecurity hardening

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions