harden: use filepath.VolumeName in the session-ID volume check · Entire

harden: use filepath.VolumeName in the session-ID volume check

78cf859·

Soph·1mo ago·2 files·+7 added/-4 removed

Per PR review (pjbgf): adopt the idiomatic filepath.VolumeName check for Windows volume references. Kept alongside the explicit ":" check because VolumeName is a no-op off Windows — the "C:foo" regression test would not exercise it on a non-Windows CI host, and the ":" form should be rejected on every platform regardless.

Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com

Sessions

6aa0a864cb61View transcript

Changes

2

28 unmodified lines

29
30
31
32
32
33
34
35
36
37
36
37
38
39
40
41
42
43

28 unmodified lines

if id == "." || id == ".." {
        return fmt.Errorf("invalid session ID %q: reserved path segment", id)
    }
    // Reject the Windows volume separator. A drive-relative path like "C:foo" is
    // Reject Windows volume references. A drive-relative path like "C:foo" is
    // separator-free and filepath.IsAbs reports it as non-absolute, yet
    // filepath.Join discards the base directory when the appended element
    // carries a volume name — escaping the intended directory on Windows.
    if strings.Contains(id, ":") {
        return fmt.Errorf("invalid session ID %q: contains volume separator", id)
    // filepath.VolumeName is the idiomatic check but is a no-op off Windows, so
    // also reject the ":" form directly for cross-platform coverage (and so the
    // regression test is meaningful on a non-Windows CI host).
    if filepath.VolumeName(id) != "" || strings.Contains(id, ":") {
        return fmt.Errorf("invalid session ID %q: contains volume reference", id)
    }
    // Reject glob metacharacters. Session IDs are interpolated into
    // filepath.Glob patterns in several places (agent transcript lookup,

Mcmd/entire/cli/validation/validators.go+6/-3

94 unmodified lines

95
96
97
98
98
99
100
101

94 unmodified lines

name:      "windows drive-relative path",
        sessionID: "C:foo",
        wantErr:   true,
        errMsg:    "volume separator",
        errMsg:    "volume reference",
    },
    // Glob metacharacters (would match unrelated files when used in a pattern)
    {