fix(xattr): whitelist path-based symlink apply; strengthen symlink xattr tests
This commit is contained in:
@@ -926,12 +926,14 @@ static FileSaveResult file_save_symlink_to_disk(const FileSavePlan* plan, bool*
|
||||
/* -X/-A: apply the symlink's OWN xattrs with a no-follow primitive. The
|
||||
confined parent directory is the anchor and the final component is applied
|
||||
with lsetxattr, so the referent is never touched. Best-effort: on Linux
|
||||
the VFS refuses xattrs on symlinks, so this is normally a no-op. */
|
||||
if (ok && config && config->use_xattrs && file->xattrs) {
|
||||
the VFS refuses xattrs on symlinks, so this is normally a no-op. Hoist the
|
||||
empty-list check so the common Linux case (NULL/empty xattrs) does not pay
|
||||
an open/close of the parent per symlink. */
|
||||
if (ok && config && config->use_xattrs && file->xattrs && file->xattrs->count > 0) {
|
||||
char* leaf = NULL;
|
||||
int parent_fd = file_open_secure_parent(link_path, &leaf, false);
|
||||
if (parent_fd >= 0) {
|
||||
xattr_apply_path_nofollow(parent_fd, leaf, file->xattrs);
|
||||
xattr_apply_path_nofollow(parent_fd, leaf, file->xattrs, config->preserve_acls);
|
||||
close(parent_fd);
|
||||
}
|
||||
free(leaf);
|
||||
|
||||
Reference in New Issue
Block a user