Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Constrain followed source symlinks to the project root during tar staging

Open
#379 0 comments 0 reactions 1 assignee View on GitHub

Maintainers usually reply within 2 days

@jonasz-lasut is already working on this.

Since Sep 18, 2026.

Assessment

This issue has not been assessed yet.

Description

Summary

internal/filesystem.FSToTar follows symlinks with filepath.EvalSymlinks and walks the resolved target without enforcing a project-root boundary. Builders that use filesystem.WithSymlinkBasePath can therefore stage readable files outside the project.

Required changes

Add a project-root boundary for followed symlinks during filesystem tar staging. Preserve valid symlinks that resolve within the project, including documented sibling-crate sharing. Reject or exclude symlinks that resolve outside the project root.

Pass the real project-root path through the relevant build and tar-staging APIs. Do not use the function directory as the boundary because functions can intentionally link to sibling project directories.

Rationale

The Rust builder newly uses the shared staging behavior. KCL and Go-templating builders already use it, and their staged files can be included in published image layers. This issue requires a shared fix rather than a Rust-specific restriction.

Affected areas

  • internal/filesystem tar and symlink handling
  • Build-context plumbing that can provide the real project-root path
  • Function builders that use filesystem.FSToTar with filesystem.WithSymlinkBasePath

Acceptance criteria

  • A followed symlink cannot cause files outside the project root to be added to a tar archive.
  • Symlinks to locations inside the project root remain supported.
  • A function can continue to share a crate from a sibling directory through an in-project symlink.
  • Tests cover direct and nested external symlinks, in-project symlinks, and the sibling-crate workflow.
  • The behavior applies consistently to Rust, KCL, and Go-templating staging paths.

Backlinks

Dominant language
Go
Stars
19
Forks
33
Avg merge
3d 4h
Merged PRs (30d)
40

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from crossplane/cli

All issues in crossplane/cli

Similar issues

More Go issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.