Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

A remote cache entry's input paths can point outside the workspace

Abierto
#768 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
4/5
Tiempo estimado
3-5 días
Aptitud para principiantes
48/100
Tipo de issue
Error
Claridad
Bastante claro
Estado de actividad
Activo
Stack tecnológico
rust
Área
security

Línea de trabajo

Start with the remote cache read path used by vp run, including the work described in #756, and trace how cached input paths are resolved and hashed. Determine how normally created entries behave outside the workspace; done means remote entries cannot cause reads outside it, including paths such as .. or endless files.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

remote cache

A cache entry lists the files the task read, as paths relative to the workspace, and vp run checks those files before it uses the entry. For entries from the remote cache, those paths aren't limited to the workspace: an entry can list paths that climb out of it with ...

A corrupted or malicious remote entry can therefore make vp run read and hash any file the user can read, anywhere on the machine, or hang while reading an endless file such as /dev/zero. When several people or CI jobs can write to the same remote cache, any one of them can affect everyone else's runs this way.

It isn't known yet whether normally created entries ever record inputs outside the workspace, which matters for deciding what to reject.

Expected: entries from the remote cache only make vp run read files inside the workspace.

Affects remote cache reads (#756).

Lenguaje dominante
Rust
Estrellas
468
Forks
42
Merge medio
2 d 31 min
PR fusionados (30 d)
46

Preparar el entorno

Abrir en Codespaces

Inicia el contenedor de desarrollo del proyecto en tu navegador, con tu propia cuenta de GitHub.

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de voidzero-dev/vite-task

Todos los issues de voidzero-dev/vite-task

Issues similares

Más issues de Rust

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.