mirror of
https://github.com/docker/cli.git
synced 2026-08-28 02:24:15 -05:00
full diff: https://github.com/moby/go-archive/compare/v0.2.1...v0.3.0 v0.3.0 This release fixes CVE-2026-17106 / GHSA-hfg8-hc9c-6c3h, where a crafted tar archive could use links to cause extraction operations to create or overwrite files outside the intended destination directory. The issue affected Unpack, UnpackLayer, Untar, UntarUncompressed, and the ApplyLayer helpers. Users should upgrade and avoid extracting untrusted archives with earlier versions. What's Changed * archive: harden tar extraction against path traversal * archive: do not follow reparse points in chtimes * archive: fix creation time updates on Windows * archive: minor cleanups and godoc touch-up * archive: RebaseArchiveEntries: fix archive path rebasing Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
43 lines
828 B
Go
43 lines
828 B
Go
package archive
|
|
|
|
import (
|
|
"syscall"
|
|
"time"
|
|
"unsafe"
|
|
)
|
|
|
|
var (
|
|
minTime = time.Unix(0, 0)
|
|
maxTime time.Time
|
|
)
|
|
|
|
func init() {
|
|
if unsafe.Sizeof(syscall.Timespec{}.Nsec) == 8 {
|
|
// This is a 64 bit timespec
|
|
// os.Chtimes limits time to the following
|
|
maxTime = time.Unix(0, 1<<63-1)
|
|
} else {
|
|
// This is a 32 bit timespec
|
|
maxTime = time.Unix(1<<31-1, 0)
|
|
}
|
|
}
|
|
|
|
// boundTime returns t if it falls within the range supported by os.Chtimes.
|
|
// Times before the Unix epoch (minTime) or after the end of Unix time
|
|
// (maxTime) are replaced with minTime, as os.Chtimes has undefined behavior
|
|
// outside that range.
|
|
func boundTime(t time.Time) time.Time {
|
|
if t.Before(minTime) || t.After(maxTime) {
|
|
return minTime
|
|
}
|
|
|
|
return t
|
|
}
|
|
|
|
func latestTime(t1, t2 time.Time) time.Time {
|
|
if t1.Before(t2) {
|
|
return t2
|
|
}
|
|
return t1
|
|
}
|