Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

A remote cache entry's input paths can point outside the workspace

Aperta
#768 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
48/100
Tipo di issue
Bug
Chiarezza
Abbastanza chiara
Stato di attività
Attiva
Stack tecnologico
rust
Ambito
security

Direzione di ricerca

Start with the remote cache read path used by vp run, including the work described in #756, and trace how cached input paths are resolved and hashed. Determine how normally created entries behave outside the workspace; done means remote entries cannot cause reads outside it, including paths such as .. or endless files.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

remote cache

A cache entry lists the files the task read, as paths relative to the workspace, and vp run checks those files before it uses the entry. For entries from the remote cache, those paths aren't limited to the workspace: an entry can list paths that climb out of it with ...

A corrupted or malicious remote entry can therefore make vp run read and hash any file the user can read, anywhere on the machine, or hang while reading an endless file such as /dev/zero. When several people or CI jobs can write to the same remote cache, any one of them can affect everyone else's runs this way.

It isn't known yet whether normally created entries ever record inputs outside the workspace, which matters for deciding what to reject.

Expected: entries from the remote cache only make vp run read files inside the workspace.

Affects remote cache reads (#756).

Lingua principale
Rust
Stelle
468
Fork
42
Merge medio
1g 3h
PR unite (30g)
41

Preparare l'ambiente

Apri in Codespaces

Avvia il container di sviluppo del progetto nel browser, con il tuo account GitHub.

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di voidzero-dev/vite-task

Tutte le issue di voidzero-dev/vite-task

Issue simili

Altre issue su Rust

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.