fix(xattr): whitelist path-based symlink apply; strengthen symlink xattr tests

This commit is contained in:
2026-09-23 01:01:18 +02:00
parent c29bce54fc
commit b88acdbd3c
5 changed files with 116 additions and 23 deletions
+5 -3
View File
@@ -926,12 +926,14 @@ static FileSaveResult file_save_symlink_to_disk(const FileSavePlan* plan, bool*
/* -X/-A: apply the symlink's OWN xattrs with a no-follow primitive. The
confined parent directory is the anchor and the final component is applied
with lsetxattr, so the referent is never touched. Best-effort: on Linux
the VFS refuses xattrs on symlinks, so this is normally a no-op. */
if (ok && config && config->use_xattrs && file->xattrs) {
the VFS refuses xattrs on symlinks, so this is normally a no-op. Hoist the
empty-list check so the common Linux case (NULL/empty xattrs) does not pay
an open/close of the parent per symlink. */
if (ok && config && config->use_xattrs && file->xattrs && file->xattrs->count > 0) {
char* leaf = NULL;
int parent_fd = file_open_secure_parent(link_path, &leaf, false);
if (parent_fd >= 0) {
xattr_apply_path_nofollow(parent_fd, leaf, file->xattrs);
xattr_apply_path_nofollow(parent_fd, leaf, file->xattrs, config->preserve_acls);
close(parent_fd);
}
free(leaf);