harden: use filepath.VolumeName in the session-ID volume check · Entire
harden: use filepath.VolumeName in the session-ID volume check
78cf859·
Soph·1mo ago·2 files·+7 added/-4 removed
Per PR review (pjbgf): adopt the idiomatic filepath.VolumeName check for Windows volume references. Kept alongside the explicit ":" check because VolumeName is a no-op off Windows — the "C:foo" regression test would not exercise it on a non-Windows CI host, and the ":" form should be rejected on every platform regardless.
Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com
Sessions
6aa0a864cb61View transcript
Changes
2
cmd/entire/cli/validation
Mvalidators.go+6/-3
Mvalidators_test.go+1/-1
28 unmodified lines
29
30
31
32
32
33
34
35
36
37
36
37
38
39
40
41
42
43
28 unmodified lines
if id == "." || id == ".." {
return fmt.Errorf("invalid session ID %q: reserved path segment", id)
}
// Reject the Windows volume separator. A drive-relative path like "C:foo" is
// Reject Windows volume references. A drive-relative path like "C:foo" is
// separator-free and filepath.IsAbs reports it as non-absolute, yet
// filepath.Join discards the base directory when the appended element
// carries a volume name — escaping the intended directory on Windows.
if strings.Contains(id, ":") {
return fmt.Errorf("invalid session ID %q: contains volume separator", id)
// filepath.VolumeName is the idiomatic check but is a no-op off Windows, so
// also reject the ":" form directly for cross-platform coverage (and so the
// regression test is meaningful on a non-Windows CI host).
if filepath.VolumeName(id) != "" || strings.Contains(id, ":") {
return fmt.Errorf("invalid session ID %q: contains volume reference", id)
}
// Reject glob metacharacters. Session IDs are interpolated into
// filepath.Glob patterns in several places (agent transcript lookup,
Mcmd/entire/cli/validation/validators.go+6/-3
94 unmodified lines
95
96
97
98
98
99
100
101
94 unmodified lines
name: "windows drive-relative path",
sessionID: "C:foo",
wantErr: true,
errMsg: "volume separator",
errMsg: "volume reference",
},
// Glob metacharacters (would match unrelated files when used in a pattern)
{