Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
23 changes: 16 additions & 7 deletions hooks/lib/loop-common.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -1190,15 +1190,21 @@ is_cancel_authorized() {

# Normalize and validate source path.
#
# Canonicalize the user-provided path so a symlinked prefix in the caller's
# command (e.g. /Users/x vs /private/Users/x on macOS, or /var vs
# /private/var) matches canonical_loop_dir resolved via resolve_project_root.
# Use canonicalize_path_prefix (NOT canonicalize_path): we need to resolve
# symlinks in the parent directory so a symlinked project prefix matches
# canonical_loop_dir, but we MUST NOT dereference a symlink at the leaf.
# Otherwise a symlink like /tmp/alias -> <loop>/state.md would canonicalize
# to <loop>/state.md and pass the check, but `mv` would then operate on
# the link path itself, escaping the loop directory and/or corrupting
# loop state. The on-disk symlink rejection below (src_original check)
# still fires because it probes the real state.md under canonical_loop_dir.
#
# Re-lowercase after canonicalization because realpath on case-insensitive
# filesystems may restore the original casing of path components, which
# would diverge from the already-lowercased expected_* values.
src=$(_normalize_path "$src")
local src_canonical
src_canonical="$(canonicalize_path "$src")"
src_canonical="$(canonicalize_path_prefix "$src")"
src_canonical="${src_canonical:-$src}"
src_canonical=$(echo "$src_canonical" | tr '[:upper:]' '[:lower:]')
local expected_src_state="${loop_dir_lower}state.md"
Expand All@@ -1208,11 +1214,14 @@ is_cancel_authorized() {
return 5
fi

# Normalize and validate destination path (same canonicalize+lowercase
# transformation as source; see src comment above for rationale).
# Normalize and validate destination path. Uses canonicalize_path_prefix
# for the same reason as src: a symlink alias pointing at the real
# cancel-state.md must NOT pass authorization, because `mv` onto a
# symlink replaces the link rather than creating <loop>/cancel-state.md,
# corrupting loop state and moving state.md outside the loop dir.
dest=$(_normalize_path "$dest")
local dest_canonical
dest_canonical="$(canonicalize_path "$dest")"
dest_canonical="$(canonicalize_path_prefix "$dest")"
dest_canonical="${dest_canonical:-$dest}"
dest_canonical=$(echo "$dest_canonical" | tr '[:upper:]' '[:lower:]')
local expected_dest="${loop_dir_lower}cancel-state.md"
Expand Down
48 changes: 48 additions & 0 deletions hooks/lib/project-root.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -52,6 +52,49 @@ resolve_project_root() {
printf '%s\n' "${canonical:-$root}"
}

# canonicalize_path_prefix
#
# Resolves symlinks ONLY in the parent directory and reattaches the
# original basename verbatim. This is the right helper for comparing
# user-supplied filenames against an expected path inside a known
# directory: a symlink at /tmp/alias pointing at /real/loop/state.md
# MUST NOT canonicalize to /real/loop/state.md for comparison purposes,
# because `mv` operates on the link path itself. Resolving only the
# parent still lets a symlinked project prefix (e.g. /var vs /private/var
# on macOS) match a canonical expected path.
#
# If realpath on the parent fails, falls back to returning the input
# path unchanged (prefix cannot be canonicalized -> caller's comparison
# will correctly fail against a canonical expected path).
#
# Empty input prints nothing and returns 0.
#
canonicalize_path_prefix() {
local path="$1"
if [[ -z "$path" ]]; then
return 0
fi

local parent base parent_real
parent=$(dirname -- "$path")
base=$(basename -- "$path")

if parent_real=$(realpath "$parent" 2>/dev/null) && [[ -n "$parent_real" ]]; then
printf '%s/%s\n' "${parent_real%/}" "$base"
return 0
fi

if command -v python3 >/dev/null 2>&1; then
parent_real=$(python3 -c 'import os,sys;print(os.path.realpath(sys.argv[1]))' "$parent" 2>/dev/null || true)
if [[ -n "$parent_real" ]]; then
printf '%s/%s\n' "${parent_real%/}" "$base"
return 0
fi
fi

printf '%s\n' "$path"
}

# canonicalize_path
#
# Prints the realpath of the input path. If the path itself does not
Expand All@@ -60,6 +103,11 @@ resolve_project_root() {
# If realpath is unavailable and python3 is missing, prints the input
# path verbatim.
#
# SECURITY NOTE: This helper dereferences symlinks at the leaf when
# the leaf exists. Do NOT use it to authorize a user-supplied path
# against an expected filename -- use canonicalize_path_prefix instead,
# which only resolves the parent.
#
# Empty input prints nothing and returns 0.
#
canonicalize_path() {
Expand Down
10 changes: 6 additions & 4 deletions hooks/loop-read-validator.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -304,10 +304,12 @@ fi

CORRECT_PATH="$ACTIVE_LOOP_DIR/$CLAUDE_FILENAME"

# Compare canonical (symlink-resolved) forms -- see loop-write-validator.sh
# for the rationale; the same reasoning applies to read paths.
_READ_FILE_REAL=$(canonicalize_path "$FILE_PATH")
_READ_CORRECT_REAL=$(canonicalize_path "$CORRECT_PATH")
# Compare prefix-canonical forms -- see loop-write-validator.sh for the
# rationale; the same reasoning applies to read paths. A planted symlink
# at the leaf would otherwise let a Read follow the link outside the loop
# dir and still pass this validator.
_READ_FILE_REAL=$(canonicalize_path_prefix "$FILE_PATH")
_READ_CORRECT_REAL=$(canonicalize_path_prefix "$CORRECT_PATH")
if [[ "${_READ_FILE_REAL:-$FILE_PATH}" != "${_READ_CORRECT_REAL:-$CORRECT_PATH}" ]]; then
FALLBACK="# Wrong Directory Path

Expand Down
16 changes: 9 additions & 7 deletions hooks/loop-write-validator.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -331,13 +331,15 @@ fi

CORRECT_PATH="$ACTIVE_LOOP_DIR/$CLAUDE_FILENAME"

# Compare canonical (symlink-resolved) forms so the check is not fooled by
# equivalent paths expressed in different prefix forms (e.g. /var/... vs
# /private/var/... on macOS). A raw string compare would mis-handle a
# symlinked project prefix whenever one side was canonicalized upstream
# (e.g. by resolve_project_root) and the other was not.
_WRITE_FILE_REAL=$(canonicalize_path "$FILE_PATH")
_WRITE_CORRECT_REAL=$(canonicalize_path "$CORRECT_PATH")
# Compare prefix-canonical forms so the check is not fooled by equivalent
# paths expressed in different ancestor forms (e.g. /var/... vs /private/var/...
# on macOS) -- without dereferencing the leaf. Using full realpath here
# would let a planted symlink at <loop>/<CLAUDE_FILENAME> pointing outside
# the loop dir approve a write through the link, escalating Claude's write
# reach beyond the loop dir. canonicalize_path_prefix resolves the parent
# directory only; the basename is compared verbatim.
_WRITE_FILE_REAL=$(canonicalize_path_prefix "$FILE_PATH")
_WRITE_CORRECT_REAL=$(canonicalize_path_prefix "$CORRECT_PATH")
if [[ "${_WRITE_FILE_REAL:-$FILE_PATH}" != "${_WRITE_CORRECT_REAL:-$CORRECT_PATH}" ]]; then
FALLBACK="# Wrong Directory Path

Expand Down
45 changes: 45 additions & 0 deletions tests/test-cancel-signal-file.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -1373,6 +1373,51 @@ fi

rm -rf "$SYMLINK_ROOT" 2>/dev/null || true

echo "HELPER TEST 9: is_cancel_authorized rejects destination symlink alias"
# Regression test for a P1 security issue: if the destination argument is a
# symlink that points at <loop>/cancel-state.md, canonicalizing the full
# path (leaf dereferenced) would let the alias pass authorization. `mv`
# would then operate on the link path itself, corrupting loop state and
# leaking state.md contents outside the loop dir. The fix resolves symlinks
# only in the parent directory and preserves the basename verbatim.
setup_test_loop "helper-9"
touch "$LOOP_DIR/.cancel-requested"
# Create the target file so the symlink would resolve if the prefix-only
# canonicalizer were relaxed back to full canonicalization.
touch "$LOOP_DIR/cancel-state.md"
ln -sfn "$LOOP_DIR/cancel-state.md" "$TEST_DIR/dest-alias"

COMMAND_LOWER="mv ${LOOP_DIR}/state.md ${TEST_DIR}/dest-alias"
COMMAND_LOWER=$(to_lower "$COMMAND_LOWER")

if is_cancel_authorized "$LOOP_DIR" "$COMMAND_LOWER"; then
fail "helper dest symlink alias" "returns non-zero (rejected)" "returns 0 (authorized)"
else
pass "is_cancel_authorized rejects destination symlink alias"
fi
rm -f "$TEST_DIR/dest-alias" "$LOOP_DIR/cancel-state.md"

echo "HELPER TEST 10: is_cancel_authorized rejects source symlink alias"
# Regression test for a P1 security issue: if the source argument is a
# symlink aliasing <loop>/state.md, dereferencing the leaf would let it
# pass authorization. The on-disk symlink check (src_original) below
# would still catch this specific case because it probes the real path,
# but we defend in depth: the path comparison must reject the alias on
# its own.
setup_test_loop "helper-10"
touch "$LOOP_DIR/.cancel-requested"
ln -sfn "$LOOP_DIR/state.md" "$TEST_DIR/src-alias"

COMMAND_LOWER="mv ${TEST_DIR}/src-alias ${LOOP_DIR}/cancel-state.md"
COMMAND_LOWER=$(to_lower "$COMMAND_LOWER")

if is_cancel_authorized "$LOOP_DIR" "$COMMAND_LOWER"; then
fail "helper src symlink alias" "returns non-zero (rejected)" "returns 0 (authorized)"
else
pass "is_cancel_authorized rejects source symlink alias"
fi
rm -f "$TEST_DIR/src-alias"

# ========================================
# Summary
# ========================================
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Reject symlink aliases for cancel source and destination by SihaoLiu · Pull Request #94 · PolyArch/humanize · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
23 changes: 16 additions & 7 deletions hooks/lib/loop-common.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -1190,15 +1190,21 @@ is_cancel_authorized() {

# Normalize and validate source path.
#
# Canonicalize the user-provided path so a symlinked prefix in the caller's
# command (e.g. /Users/x vs /private/Users/x on macOS, or /var vs
# /private/var) matches canonical_loop_dir resolved via resolve_project_root.
# Use canonicalize_path_prefix (NOT canonicalize_path): we need to resolve
# symlinks in the parent directory so a symlinked project prefix matches
# canonical_loop_dir, but we MUST NOT dereference a symlink at the leaf.
# Otherwise a symlink like /tmp/alias -> <loop>/state.md would canonicalize
# to <loop>/state.md and pass the check, but `mv` would then operate on
# the link path itself, escaping the loop directory and/or corrupting
# loop state. The on-disk symlink rejection below (src_original check)
# still fires because it probes the real state.md under canonical_loop_dir.
#
# Re-lowercase after canonicalization because realpath on case-insensitive
# filesystems may restore the original casing of path components, which
# would diverge from the already-lowercased expected_* values.
src=$(_normalize_path "$src")
local src_canonical
src_canonical="$(canonicalize_path "$src")"
src_canonical="$(canonicalize_path_prefix "$src")"
src_canonical="${src_canonical:-$src}"
src_canonical=$(echo "$src_canonical" | tr '[:upper:]' '[:lower:]')
local expected_src_state="${loop_dir_lower}state.md"
Expand All@@ -1208,11 +1214,14 @@ is_cancel_authorized() {
return 5
fi

# Normalize and validate destination path (same canonicalize+lowercase
# transformation as source; see src comment above for rationale).
# Normalize and validate destination path. Uses canonicalize_path_prefix
# for the same reason as src: a symlink alias pointing at the real
# cancel-state.md must NOT pass authorization, because `mv` onto a
# symlink replaces the link rather than creating <loop>/cancel-state.md,
# corrupting loop state and moving state.md outside the loop dir.
dest=$(_normalize_path "$dest")
local dest_canonical
dest_canonical="$(canonicalize_path "$dest")"
dest_canonical="$(canonicalize_path_prefix "$dest")"
dest_canonical="${dest_canonical:-$dest}"
dest_canonical=$(echo "$dest_canonical" | tr '[:upper:]' '[:lower:]')
local expected_dest="${loop_dir_lower}cancel-state.md"
Expand Down
48 changes: 48 additions & 0 deletions hooks/lib/project-root.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -52,6 +52,49 @@ resolve_project_root() {
printf '%s\n' "${canonical:-$root}"
}

# canonicalize_path_prefix
#
# Resolves symlinks ONLY in the parent directory and reattaches the
# original basename verbatim. This is the right helper for comparing
# user-supplied filenames against an expected path inside a known
# directory: a symlink at /tmp/alias pointing at /real/loop/state.md
# MUST NOT canonicalize to /real/loop/state.md for comparison purposes,
# because `mv` operates on the link path itself. Resolving only the
# parent still lets a symlinked project prefix (e.g. /var vs /private/var
# on macOS) match a canonical expected path.
#
# If realpath on the parent fails, falls back to returning the input
# path unchanged (prefix cannot be canonicalized -> caller's comparison
# will correctly fail against a canonical expected path).
#
# Empty input prints nothing and returns 0.
#
canonicalize_path_prefix() {
local path="$1"
if [[ -z "$path" ]]; then
return 0
fi

local parent base parent_real
parent=$(dirname -- "$path")
base=$(basename -- "$path")

if parent_real=$(realpath "$parent" 2>/dev/null) && [[ -n "$parent_real" ]]; then
printf '%s/%s\n' "${parent_real%/}" "$base"
return 0
fi

if command -v python3 >/dev/null 2>&1; then
parent_real=$(python3 -c 'import os,sys;print(os.path.realpath(sys.argv[1]))' "$parent" 2>/dev/null || true)
if [[ -n "$parent_real" ]]; then
printf '%s/%s\n' "${parent_real%/}" "$base"
return 0
fi
fi

printf '%s\n' "$path"
}

# canonicalize_path
#
# Prints the realpath of the input path. If the path itself does not
Expand All@@ -60,6 +103,11 @@ resolve_project_root() {
# If realpath is unavailable and python3 is missing, prints the input
# path verbatim.
#
# SECURITY NOTE: This helper dereferences symlinks at the leaf when
# the leaf exists. Do NOT use it to authorize a user-supplied path
# against an expected filename -- use canonicalize_path_prefix instead,
# which only resolves the parent.
#
# Empty input prints nothing and returns 0.
#
canonicalize_path() {
Expand Down
10 changes: 6 additions & 4 deletions hooks/loop-read-validator.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -304,10 +304,12 @@ fi

CORRECT_PATH="$ACTIVE_LOOP_DIR/$CLAUDE_FILENAME"

# Compare canonical (symlink-resolved) forms -- see loop-write-validator.sh
# for the rationale; the same reasoning applies to read paths.
_READ_FILE_REAL=$(canonicalize_path "$FILE_PATH")
_READ_CORRECT_REAL=$(canonicalize_path "$CORRECT_PATH")
# Compare prefix-canonical forms -- see loop-write-validator.sh for the
# rationale; the same reasoning applies to read paths. A planted symlink
# at the leaf would otherwise let a Read follow the link outside the loop
# dir and still pass this validator.
_READ_FILE_REAL=$(canonicalize_path_prefix "$FILE_PATH")
_READ_CORRECT_REAL=$(canonicalize_path_prefix "$CORRECT_PATH")
if [[ "${_READ_FILE_REAL:-$FILE_PATH}" != "${_READ_CORRECT_REAL:-$CORRECT_PATH}" ]]; then
FALLBACK="# Wrong Directory Path

Expand Down
16 changes: 9 additions & 7 deletions hooks/loop-write-validator.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -331,13 +331,15 @@ fi

CORRECT_PATH="$ACTIVE_LOOP_DIR/$CLAUDE_FILENAME"

# Compare canonical (symlink-resolved) forms so the check is not fooled by
# equivalent paths expressed in different prefix forms (e.g. /var/... vs
# /private/var/... on macOS). A raw string compare would mis-handle a
# symlinked project prefix whenever one side was canonicalized upstream
# (e.g. by resolve_project_root) and the other was not.
_WRITE_FILE_REAL=$(canonicalize_path "$FILE_PATH")
_WRITE_CORRECT_REAL=$(canonicalize_path "$CORRECT_PATH")
# Compare prefix-canonical forms so the check is not fooled by equivalent
# paths expressed in different ancestor forms (e.g. /var/... vs /private/var/...
# on macOS) -- without dereferencing the leaf. Using full realpath here
# would let a planted symlink at <loop>/<CLAUDE_FILENAME> pointing outside
# the loop dir approve a write through the link, escalating Claude's write
# reach beyond the loop dir. canonicalize_path_prefix resolves the parent
# directory only; the basename is compared verbatim.
_WRITE_FILE_REAL=$(canonicalize_path_prefix "$FILE_PATH")
_WRITE_CORRECT_REAL=$(canonicalize_path_prefix "$CORRECT_PATH")
if [[ "${_WRITE_FILE_REAL:-$FILE_PATH}" != "${_WRITE_CORRECT_REAL:-$CORRECT_PATH}" ]]; then
FALLBACK="# Wrong Directory Path

Expand Down
45 changes: 45 additions & 0 deletions tests/test-cancel-signal-file.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -1373,6 +1373,51 @@ fi

rm -rf "$SYMLINK_ROOT" 2>/dev/null || true

echo "HELPER TEST 9: is_cancel_authorized rejects destination symlink alias"
# Regression test for a P1 security issue: if the destination argument is a
# symlink that points at <loop>/cancel-state.md, canonicalizing the full
# path (leaf dereferenced) would let the alias pass authorization. `mv`
# would then operate on the link path itself, corrupting loop state and
# leaking state.md contents outside the loop dir. The fix resolves symlinks
# only in the parent directory and preserves the basename verbatim.
setup_test_loop "helper-9"
touch "$LOOP_DIR/.cancel-requested"
# Create the target file so the symlink would resolve if the prefix-only
# canonicalizer were relaxed back to full canonicalization.
touch "$LOOP_DIR/cancel-state.md"
ln -sfn "$LOOP_DIR/cancel-state.md" "$TEST_DIR/dest-alias"

COMMAND_LOWER="mv ${LOOP_DIR}/state.md ${TEST_DIR}/dest-alias"
COMMAND_LOWER=$(to_lower "$COMMAND_LOWER")

if is_cancel_authorized "$LOOP_DIR" "$COMMAND_LOWER"; then
fail "helper dest symlink alias" "returns non-zero (rejected)" "returns 0 (authorized)"
else
pass "is_cancel_authorized rejects destination symlink alias"
fi
rm -f "$TEST_DIR/dest-alias" "$LOOP_DIR/cancel-state.md"

echo "HELPER TEST 10: is_cancel_authorized rejects source symlink alias"
# Regression test for a P1 security issue: if the source argument is a
# symlink aliasing <loop>/state.md, dereferencing the leaf would let it
# pass authorization. The on-disk symlink check (src_original) below
# would still catch this specific case because it probes the real path,
# but we defend in depth: the path comparison must reject the alias on
# its own.
setup_test_loop "helper-10"
touch "$LOOP_DIR/.cancel-requested"
ln -sfn "$LOOP_DIR/state.md" "$TEST_DIR/src-alias"

COMMAND_LOWER="mv ${TEST_DIR}/src-alias ${LOOP_DIR}/cancel-state.md"
COMMAND_LOWER=$(to_lower "$COMMAND_LOWER")

if is_cancel_authorized "$LOOP_DIR" "$COMMAND_LOWER"; then
fail "helper src symlink alias" "returns non-zero (rejected)" "returns 0 (authorized)"
else
pass "is_cancel_authorized rejects source symlink alias"
fi
rm -f "$TEST_DIR/src-alias"

# ========================================
# Summary
# ========================================
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Reject symlink aliases for cancel source and destination by SihaoLiu · Pull Request #94 · PolyArch/humanize · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
23 changes: 16 additions & 7 deletions hooks/lib/loop-common.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -1190,15 +1190,21 @@ is_cancel_authorized() {

# Normalize and validate source path.
#
# Canonicalize the user-provided path so a symlinked prefix in the caller's
# command (e.g. /Users/x vs /private/Users/x on macOS, or /var vs
# /private/var) matches canonical_loop_dir resolved via resolve_project_root.
# Use canonicalize_path_prefix (NOT canonicalize_path): we need to resolve
# symlinks in the parent directory so a symlinked project prefix matches
# canonical_loop_dir, but we MUST NOT dereference a symlink at the leaf.
# Otherwise a symlink like /tmp/alias -> <loop>/state.md would canonicalize
# to <loop>/state.md and pass the check, but `mv` would then operate on
# the link path itself, escaping the loop directory and/or corrupting
# loop state. The on-disk symlink rejection below (src_original check)
# still fires because it probes the real state.md under canonical_loop_dir.
#
# Re-lowercase after canonicalization because realpath on case-insensitive
# filesystems may restore the original casing of path components, which
# would diverge from the already-lowercased expected_* values.
src=$(_normalize_path "$src")
local src_canonical
src_canonical="$(canonicalize_path "$src")"
src_canonical="$(canonicalize_path_prefix "$src")"
src_canonical="${src_canonical:-$src}"
src_canonical=$(echo "$src_canonical" | tr '[:upper:]' '[:lower:]')
local expected_src_state="${loop_dir_lower}state.md"
Expand All@@ -1208,11 +1214,14 @@ is_cancel_authorized() {
return 5
fi

# Normalize and validate destination path (same canonicalize+lowercase
# transformation as source; see src comment above for rationale).
# Normalize and validate destination path. Uses canonicalize_path_prefix
# for the same reason as src: a symlink alias pointing at the real
# cancel-state.md must NOT pass authorization, because `mv` onto a
# symlink replaces the link rather than creating <loop>/cancel-state.md,
# corrupting loop state and moving state.md outside the loop dir.
dest=$(_normalize_path "$dest")
local dest_canonical
dest_canonical="$(canonicalize_path "$dest")"
dest_canonical="$(canonicalize_path_prefix "$dest")"
dest_canonical="${dest_canonical:-$dest}"
dest_canonical=$(echo "$dest_canonical" | tr '[:upper:]' '[:lower:]')
local expected_dest="${loop_dir_lower}cancel-state.md"
Expand Down
48 changes: 48 additions & 0 deletions hooks/lib/project-root.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -52,6 +52,49 @@ resolve_project_root() {
printf '%s\n' "${canonical:-$root}"
}

# canonicalize_path_prefix
#
# Resolves symlinks ONLY in the parent directory and reattaches the
# original basename verbatim. This is the right helper for comparing
# user-supplied filenames against an expected path inside a known
# directory: a symlink at /tmp/alias pointing at /real/loop/state.md
# MUST NOT canonicalize to /real/loop/state.md for comparison purposes,
# because `mv` operates on the link path itself. Resolving only the
# parent still lets a symlinked project prefix (e.g. /var vs /private/var
# on macOS) match a canonical expected path.
#
# If realpath on the parent fails, falls back to returning the input
# path unchanged (prefix cannot be canonicalized -> caller's comparison
# will correctly fail against a canonical expected path).
#
# Empty input prints nothing and returns 0.
#
canonicalize_path_prefix() {
local path="$1"
if [[ -z "$path" ]]; then
return 0
fi

local parent base parent_real
parent=$(dirname -- "$path")
base=$(basename -- "$path")

if parent_real=$(realpath "$parent" 2>/dev/null) && [[ -n "$parent_real" ]]; then
printf '%s/%s\n' "${parent_real%/}" "$base"
return 0
fi

if command -v python3 >/dev/null 2>&1; then
parent_real=$(python3 -c 'import os,sys;print(os.path.realpath(sys.argv[1]))' "$parent" 2>/dev/null || true)
if [[ -n "$parent_real" ]]; then
printf '%s/%s\n' "${parent_real%/}" "$base"
return 0
fi
fi

printf '%s\n' "$path"
}

# canonicalize_path
#
# Prints the realpath of the input path. If the path itself does not
Expand All@@ -60,6 +103,11 @@ resolve_project_root() {
# If realpath is unavailable and python3 is missing, prints the input
# path verbatim.
#
# SECURITY NOTE: This helper dereferences symlinks at the leaf when
# the leaf exists. Do NOT use it to authorize a user-supplied path
# against an expected filename -- use canonicalize_path_prefix instead,
# which only resolves the parent.
#
# Empty input prints nothing and returns 0.
#
canonicalize_path() {
Expand Down
10 changes: 6 additions & 4 deletions hooks/loop-read-validator.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -304,10 +304,12 @@ fi

CORRECT_PATH="$ACTIVE_LOOP_DIR/$CLAUDE_FILENAME"

# Compare canonical (symlink-resolved) forms -- see loop-write-validator.sh
# for the rationale; the same reasoning applies to read paths.
_READ_FILE_REAL=$(canonicalize_path "$FILE_PATH")
_READ_CORRECT_REAL=$(canonicalize_path "$CORRECT_PATH")
# Compare prefix-canonical forms -- see loop-write-validator.sh for the
# rationale; the same reasoning applies to read paths. A planted symlink
# at the leaf would otherwise let a Read follow the link outside the loop
# dir and still pass this validator.
_READ_FILE_REAL=$(canonicalize_path_prefix "$FILE_PATH")
_READ_CORRECT_REAL=$(canonicalize_path_prefix "$CORRECT_PATH")
if [[ "${_READ_FILE_REAL:-$FILE_PATH}" != "${_READ_CORRECT_REAL:-$CORRECT_PATH}" ]]; then
FALLBACK="# Wrong Directory Path

Expand Down
16 changes: 9 additions & 7 deletions hooks/loop-write-validator.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -331,13 +331,15 @@ fi

CORRECT_PATH="$ACTIVE_LOOP_DIR/$CLAUDE_FILENAME"

# Compare canonical (symlink-resolved) forms so the check is not fooled by
# equivalent paths expressed in different prefix forms (e.g. /var/... vs
# /private/var/... on macOS). A raw string compare would mis-handle a
# symlinked project prefix whenever one side was canonicalized upstream
# (e.g. by resolve_project_root) and the other was not.
_WRITE_FILE_REAL=$(canonicalize_path "$FILE_PATH")
_WRITE_CORRECT_REAL=$(canonicalize_path "$CORRECT_PATH")
# Compare prefix-canonical forms so the check is not fooled by equivalent
# paths expressed in different ancestor forms (e.g. /var/... vs /private/var/...
# on macOS) -- without dereferencing the leaf. Using full realpath here
# would let a planted symlink at <loop>/<CLAUDE_FILENAME> pointing outside
# the loop dir approve a write through the link, escalating Claude's write
# reach beyond the loop dir. canonicalize_path_prefix resolves the parent
# directory only; the basename is compared verbatim.
_WRITE_FILE_REAL=$(canonicalize_path_prefix "$FILE_PATH")
_WRITE_CORRECT_REAL=$(canonicalize_path_prefix "$CORRECT_PATH")
if [[ "${_WRITE_FILE_REAL:-$FILE_PATH}" != "${_WRITE_CORRECT_REAL:-$CORRECT_PATH}" ]]; then
FALLBACK="# Wrong Directory Path

Expand Down
45 changes: 45 additions & 0 deletions tests/test-cancel-signal-file.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -1373,6 +1373,51 @@ fi

rm -rf "$SYMLINK_ROOT" 2>/dev/null || true

echo "HELPER TEST 9: is_cancel_authorized rejects destination symlink alias"
# Regression test for a P1 security issue: if the destination argument is a
# symlink that points at <loop>/cancel-state.md, canonicalizing the full
# path (leaf dereferenced) would let the alias pass authorization. `mv`
# would then operate on the link path itself, corrupting loop state and
# leaking state.md contents outside the loop dir. The fix resolves symlinks
# only in the parent directory and preserves the basename verbatim.
setup_test_loop "helper-9"
touch "$LOOP_DIR/.cancel-requested"
# Create the target file so the symlink would resolve if the prefix-only
# canonicalizer were relaxed back to full canonicalization.
touch "$LOOP_DIR/cancel-state.md"
ln -sfn "$LOOP_DIR/cancel-state.md" "$TEST_DIR/dest-alias"

COMMAND_LOWER="mv ${LOOP_DIR}/state.md ${TEST_DIR}/dest-alias"
COMMAND_LOWER=$(to_lower "$COMMAND_LOWER")

if is_cancel_authorized "$LOOP_DIR" "$COMMAND_LOWER"; then
fail "helper dest symlink alias" "returns non-zero (rejected)" "returns 0 (authorized)"
else
pass "is_cancel_authorized rejects destination symlink alias"
fi
rm -f "$TEST_DIR/dest-alias" "$LOOP_DIR/cancel-state.md"

echo "HELPER TEST 10: is_cancel_authorized rejects source symlink alias"
# Regression test for a P1 security issue: if the source argument is a
# symlink aliasing <loop>/state.md, dereferencing the leaf would let it
# pass authorization. The on-disk symlink check (src_original) below
# would still catch this specific case because it probes the real path,
# but we defend in depth: the path comparison must reject the alias on
# its own.
setup_test_loop "helper-10"
touch "$LOOP_DIR/.cancel-requested"
ln -sfn "$LOOP_DIR/state.md" "$TEST_DIR/src-alias"

COMMAND_LOWER="mv ${TEST_DIR}/src-alias ${LOOP_DIR}/cancel-state.md"
COMMAND_LOWER=$(to_lower "$COMMAND_LOWER")

if is_cancel_authorized "$LOOP_DIR" "$COMMAND_LOWER"; then
fail "helper src symlink alias" "returns non-zero (rejected)" "returns 0 (authorized)"
else
pass "is_cancel_authorized rejects source symlink alias"
fi
rm -f "$TEST_DIR/src-alias"

# ========================================
# Summary
# ========================================
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Reject symlink aliases for cancel source and destination by SihaoLiu · Pull Request #94 · PolyArch/humanize · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
23 changes: 16 additions & 7 deletions hooks/lib/loop-common.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -1190,15 +1190,21 @@ is_cancel_authorized() {

# Normalize and validate source path.
#
# Canonicalize the user-provided path so a symlinked prefix in the caller's
# command (e.g. /Users/x vs /private/Users/x on macOS, or /var vs
# /private/var) matches canonical_loop_dir resolved via resolve_project_root.
# Use canonicalize_path_prefix (NOT canonicalize_path): we need to resolve
# symlinks in the parent directory so a symlinked project prefix matches
# canonical_loop_dir, but we MUST NOT dereference a symlink at the leaf.
# Otherwise a symlink like /tmp/alias -> <loop>/state.md would canonicalize
# to <loop>/state.md and pass the check, but `mv` would then operate on
# the link path itself, escaping the loop directory and/or corrupting
# loop state. The on-disk symlink rejection below (src_original check)
# still fires because it probes the real state.md under canonical_loop_dir.
#
# Re-lowercase after canonicalization because realpath on case-insensitive
# filesystems may restore the original casing of path components, which
# would diverge from the already-lowercased expected_* values.
src=$(_normalize_path "$src")
local src_canonical
src_canonical="$(canonicalize_path "$src")"
src_canonical="$(canonicalize_path_prefix "$src")"
src_canonical="${src_canonical:-$src}"
src_canonical=$(echo "$src_canonical" | tr '[:upper:]' '[:lower:]')
local expected_src_state="${loop_dir_lower}state.md"
Expand All@@ -1208,11 +1214,14 @@ is_cancel_authorized() {
return 5
fi

# Normalize and validate destination path (same canonicalize+lowercase
# transformation as source; see src comment above for rationale).
# Normalize and validate destination path. Uses canonicalize_path_prefix
# for the same reason as src: a symlink alias pointing at the real
# cancel-state.md must NOT pass authorization, because `mv` onto a
# symlink replaces the link rather than creating <loop>/cancel-state.md,
# corrupting loop state and moving state.md outside the loop dir.
dest=$(_normalize_path "$dest")
local dest_canonical
dest_canonical="$(canonicalize_path "$dest")"
dest_canonical="$(canonicalize_path_prefix "$dest")"
dest_canonical="${dest_canonical:-$dest}"
dest_canonical=$(echo "$dest_canonical" | tr '[:upper:]' '[:lower:]')
local expected_dest="${loop_dir_lower}cancel-state.md"
Expand Down
48 changes: 48 additions & 0 deletions hooks/lib/project-root.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -52,6 +52,49 @@ resolve_project_root() {
printf '%s\n' "${canonical:-$root}"
}

# canonicalize_path_prefix
#
# Resolves symlinks ONLY in the parent directory and reattaches the
# original basename verbatim. This is the right helper for comparing
# user-supplied filenames against an expected path inside a known
# directory: a symlink at /tmp/alias pointing at /real/loop/state.md
# MUST NOT canonicalize to /real/loop/state.md for comparison purposes,
# because `mv` operates on the link path itself. Resolving only the
# parent still lets a symlinked project prefix (e.g. /var vs /private/var
# on macOS) match a canonical expected path.
#
# If realpath on the parent fails, falls back to returning the input
# path unchanged (prefix cannot be canonicalized -> caller's comparison
# will correctly fail against a canonical expected path).
#
# Empty input prints nothing and returns 0.
#
canonicalize_path_prefix() {
local path="$1"
if [[ -z "$path" ]]; then
return 0
fi

local parent base parent_real
parent=$(dirname -- "$path")
base=$(basename -- "$path")

if parent_real=$(realpath "$parent" 2>/dev/null) && [[ -n "$parent_real" ]]; then
printf '%s/%s\n' "${parent_real%/}" "$base"
return 0
fi

if command -v python3 >/dev/null 2>&1; then
parent_real=$(python3 -c 'import os,sys;print(os.path.realpath(sys.argv[1]))' "$parent" 2>/dev/null || true)
if [[ -n "$parent_real" ]]; then
printf '%s/%s\n' "${parent_real%/}" "$base"
return 0
fi
fi

printf '%s\n' "$path"
}

# canonicalize_path
#
# Prints the realpath of the input path. If the path itself does not
Expand All@@ -60,6 +103,11 @@ resolve_project_root() {
# If realpath is unavailable and python3 is missing, prints the input
# path verbatim.
#
# SECURITY NOTE: This helper dereferences symlinks at the leaf when
# the leaf exists. Do NOT use it to authorize a user-supplied path
# against an expected filename -- use canonicalize_path_prefix instead,
# which only resolves the parent.
#
# Empty input prints nothing and returns 0.
#
canonicalize_path() {
Expand Down
10 changes: 6 additions & 4 deletions hooks/loop-read-validator.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -304,10 +304,12 @@ fi

CORRECT_PATH="$ACTIVE_LOOP_DIR/$CLAUDE_FILENAME"

# Compare canonical (symlink-resolved) forms -- see loop-write-validator.sh
# for the rationale; the same reasoning applies to read paths.
_READ_FILE_REAL=$(canonicalize_path "$FILE_PATH")
_READ_CORRECT_REAL=$(canonicalize_path "$CORRECT_PATH")
# Compare prefix-canonical forms -- see loop-write-validator.sh for the
# rationale; the same reasoning applies to read paths. A planted symlink
# at the leaf would otherwise let a Read follow the link outside the loop
# dir and still pass this validator.
_READ_FILE_REAL=$(canonicalize_path_prefix "$FILE_PATH")
_READ_CORRECT_REAL=$(canonicalize_path_prefix "$CORRECT_PATH")
if [[ "${_READ_FILE_REAL:-$FILE_PATH}" != "${_READ_CORRECT_REAL:-$CORRECT_PATH}" ]]; then
FALLBACK="# Wrong Directory Path

Expand Down
16 changes: 9 additions & 7 deletions hooks/loop-write-validator.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -331,13 +331,15 @@ fi

CORRECT_PATH="$ACTIVE_LOOP_DIR/$CLAUDE_FILENAME"

# Compare canonical (symlink-resolved) forms so the check is not fooled by
# equivalent paths expressed in different prefix forms (e.g. /var/... vs
# /private/var/... on macOS). A raw string compare would mis-handle a
# symlinked project prefix whenever one side was canonicalized upstream
# (e.g. by resolve_project_root) and the other was not.
_WRITE_FILE_REAL=$(canonicalize_path "$FILE_PATH")
_WRITE_CORRECT_REAL=$(canonicalize_path "$CORRECT_PATH")
# Compare prefix-canonical forms so the check is not fooled by equivalent
# paths expressed in different ancestor forms (e.g. /var/... vs /private/var/...
# on macOS) -- without dereferencing the leaf. Using full realpath here
# would let a planted symlink at <loop>/<CLAUDE_FILENAME> pointing outside
# the loop dir approve a write through the link, escalating Claude's write
# reach beyond the loop dir. canonicalize_path_prefix resolves the parent
# directory only; the basename is compared verbatim.
_WRITE_FILE_REAL=$(canonicalize_path_prefix "$FILE_PATH")
_WRITE_CORRECT_REAL=$(canonicalize_path_prefix "$CORRECT_PATH")
if [[ "${_WRITE_FILE_REAL:-$FILE_PATH}" != "${_WRITE_CORRECT_REAL:-$CORRECT_PATH}" ]]; then
FALLBACK="# Wrong Directory Path

Expand Down
45 changes: 45 additions & 0 deletions tests/test-cancel-signal-file.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -1373,6 +1373,51 @@ fi

rm -rf "$SYMLINK_ROOT" 2>/dev/null || true

echo "HELPER TEST 9: is_cancel_authorized rejects destination symlink alias"
# Regression test for a P1 security issue: if the destination argument is a
# symlink that points at <loop>/cancel-state.md, canonicalizing the full
# path (leaf dereferenced) would let the alias pass authorization. `mv`
# would then operate on the link path itself, corrupting loop state and
# leaking state.md contents outside the loop dir. The fix resolves symlinks
# only in the parent directory and preserves the basename verbatim.
setup_test_loop "helper-9"
touch "$LOOP_DIR/.cancel-requested"
# Create the target file so the symlink would resolve if the prefix-only
# canonicalizer were relaxed back to full canonicalization.
touch "$LOOP_DIR/cancel-state.md"
ln -sfn "$LOOP_DIR/cancel-state.md" "$TEST_DIR/dest-alias"

COMMAND_LOWER="mv ${LOOP_DIR}/state.md ${TEST_DIR}/dest-alias"
COMMAND_LOWER=$(to_lower "$COMMAND_LOWER")

if is_cancel_authorized "$LOOP_DIR" "$COMMAND_LOWER"; then
fail "helper dest symlink alias" "returns non-zero (rejected)" "returns 0 (authorized)"
else
pass "is_cancel_authorized rejects destination symlink alias"
fi
rm -f "$TEST_DIR/dest-alias" "$LOOP_DIR/cancel-state.md"

echo "HELPER TEST 10: is_cancel_authorized rejects source symlink alias"
# Regression test for a P1 security issue: if the source argument is a
# symlink aliasing <loop>/state.md, dereferencing the leaf would let it
# pass authorization. The on-disk symlink check (src_original) below
# would still catch this specific case because it probes the real path,
# but we defend in depth: the path comparison must reject the alias on
# its own.
setup_test_loop "helper-10"
touch "$LOOP_DIR/.cancel-requested"
ln -sfn "$LOOP_DIR/state.md" "$TEST_DIR/src-alias"

COMMAND_LOWER="mv ${TEST_DIR}/src-alias ${LOOP_DIR}/cancel-state.md"
COMMAND_LOWER=$(to_lower "$COMMAND_LOWER")

if is_cancel_authorized "$LOOP_DIR" "$COMMAND_LOWER"; then
fail "helper src symlink alias" "returns non-zero (rejected)" "returns 0 (authorized)"
else
pass "is_cancel_authorized rejects source symlink alias"
fi
rm -f "$TEST_DIR/src-alias"

# ========================================
# Summary
# ========================================
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' Reject symlink aliases for cancel source and destination by SihaoLiu · Pull Request #94 · PolyArch/humanize · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
23 changes: 16 additions & 7 deletions hooks/lib/loop-common.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -1190,15 +1190,21 @@ is_cancel_authorized() {

# Normalize and validate source path.
#
# Canonicalize the user-provided path so a symlinked prefix in the caller's
# command (e.g. /Users/x vs /private/Users/x on macOS, or /var vs
# /private/var) matches canonical_loop_dir resolved via resolve_project_root.
# Use canonicalize_path_prefix (NOT canonicalize_path): we need to resolve
# symlinks in the parent directory so a symlinked project prefix matches
# canonical_loop_dir, but we MUST NOT dereference a symlink at the leaf.
# Otherwise a symlink like /tmp/alias -> <loop>/state.md would canonicalize
# to <loop>/state.md and pass the check, but `mv` would then operate on
# the link path itself, escaping the loop directory and/or corrupting
# loop state. The on-disk symlink rejection below (src_original check)
# still fires because it probes the real state.md under canonical_loop_dir.
#
# Re-lowercase after canonicalization because realpath on case-insensitive
# filesystems may restore the original casing of path components, which
# would diverge from the already-lowercased expected_* values.
src=$(_normalize_path "$src")
local src_canonical
src_canonical="$(canonicalize_path "$src")"
src_canonical="$(canonicalize_path_prefix "$src")"
src_canonical="${src_canonical:-$src}"
src_canonical=$(echo "$src_canonical" | tr '[:upper:]' '[:lower:]')
local expected_src_state="${loop_dir_lower}state.md"
Expand All@@ -1208,11 +1214,14 @@ is_cancel_authorized() {
return 5
fi

# Normalize and validate destination path (same canonicalize+lowercase
# transformation as source; see src comment above for rationale).
# Normalize and validate destination path. Uses canonicalize_path_prefix
# for the same reason as src: a symlink alias pointing at the real
# cancel-state.md must NOT pass authorization, because `mv` onto a
# symlink replaces the link rather than creating <loop>/cancel-state.md,
# corrupting loop state and moving state.md outside the loop dir.
dest=$(_normalize_path "$dest")
local dest_canonical
dest_canonical="$(canonicalize_path "$dest")"
dest_canonical="$(canonicalize_path_prefix "$dest")"
dest_canonical="${dest_canonical:-$dest}"
dest_canonical=$(echo "$dest_canonical" | tr '[:upper:]' '[:lower:]')
local expected_dest="${loop_dir_lower}cancel-state.md"
Expand Down
48 changes: 48 additions & 0 deletions hooks/lib/project-root.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -52,6 +52,49 @@ resolve_project_root() {
printf '%s\n' "${canonical:-$root}"
}

# canonicalize_path_prefix
#
# Resolves symlinks ONLY in the parent directory and reattaches the
# original basename verbatim. This is the right helper for comparing
# user-supplied filenames against an expected path inside a known
# directory: a symlink at /tmp/alias pointing at /real/loop/state.md
# MUST NOT canonicalize to /real/loop/state.md for comparison purposes,
# because `mv` operates on the link path itself. Resolving only the
# parent still lets a symlinked project prefix (e.g. /var vs /private/var
# on macOS) match a canonical expected path.
#
# If realpath on the parent fails, falls back to returning the input
# path unchanged (prefix cannot be canonicalized -> caller's comparison
# will correctly fail against a canonical expected path).
#
# Empty input prints nothing and returns 0.
#
canonicalize_path_prefix() {
local path="$1"
if [[ -z "$path" ]]; then
return 0
fi

local parent base parent_real
parent=$(dirname -- "$path")
base=$(basename -- "$path")

if parent_real=$(realpath "$parent" 2>/dev/null) && [[ -n "$parent_real" ]]; then
printf '%s/%s\n' "${parent_real%/}" "$base"
return 0
fi

if command -v python3 >/dev/null 2>&1; then
parent_real=$(python3 -c 'import os,sys;print(os.path.realpath(sys.argv[1]))' "$parent" 2>/dev/null || true)
if [[ -n "$parent_real" ]]; then
printf '%s/%s\n' "${parent_real%/}" "$base"
return 0
fi
fi

printf '%s\n' "$path"
}

# canonicalize_path
#
# Prints the realpath of the input path. If the path itself does not
Expand All@@ -60,6 +103,11 @@ resolve_project_root() {
# If realpath is unavailable and python3 is missing, prints the input
# path verbatim.
#
# SECURITY NOTE: This helper dereferences symlinks at the leaf when
# the leaf exists. Do NOT use it to authorize a user-supplied path
# against an expected filename -- use canonicalize_path_prefix instead,
# which only resolves the parent.
#
# Empty input prints nothing and returns 0.
#
canonicalize_path() {
Expand Down
10 changes: 6 additions & 4 deletions hooks/loop-read-validator.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -304,10 +304,12 @@ fi

CORRECT_PATH="$ACTIVE_LOOP_DIR/$CLAUDE_FILENAME"

# Compare canonical (symlink-resolved) forms -- see loop-write-validator.sh
# for the rationale; the same reasoning applies to read paths.
_READ_FILE_REAL=$(canonicalize_path "$FILE_PATH")
_READ_CORRECT_REAL=$(canonicalize_path "$CORRECT_PATH")
# Compare prefix-canonical forms -- see loop-write-validator.sh for the
# rationale; the same reasoning applies to read paths. A planted symlink
# at the leaf would otherwise let a Read follow the link outside the loop
# dir and still pass this validator.
_READ_FILE_REAL=$(canonicalize_path_prefix "$FILE_PATH")
_READ_CORRECT_REAL=$(canonicalize_path_prefix "$CORRECT_PATH")
if [[ "${_READ_FILE_REAL:-$FILE_PATH}" != "${_READ_CORRECT_REAL:-$CORRECT_PATH}" ]]; then
FALLBACK="# Wrong Directory Path

Expand Down
16 changes: 9 additions & 7 deletions hooks/loop-write-validator.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -331,13 +331,15 @@ fi

CORRECT_PATH="$ACTIVE_LOOP_DIR/$CLAUDE_FILENAME"

# Compare canonical (symlink-resolved) forms so the check is not fooled by
# equivalent paths expressed in different prefix forms (e.g. /var/... vs
# /private/var/... on macOS). A raw string compare would mis-handle a
# symlinked project prefix whenever one side was canonicalized upstream
# (e.g. by resolve_project_root) and the other was not.
_WRITE_FILE_REAL=$(canonicalize_path "$FILE_PATH")
_WRITE_CORRECT_REAL=$(canonicalize_path "$CORRECT_PATH")
# Compare prefix-canonical forms so the check is not fooled by equivalent
# paths expressed in different ancestor forms (e.g. /var/... vs /private/var/...
# on macOS) -- without dereferencing the leaf. Using full realpath here
# would let a planted symlink at <loop>/<CLAUDE_FILENAME> pointing outside
# the loop dir approve a write through the link, escalating Claude's write
# reach beyond the loop dir. canonicalize_path_prefix resolves the parent
# directory only; the basename is compared verbatim.
_WRITE_FILE_REAL=$(canonicalize_path_prefix "$FILE_PATH")
_WRITE_CORRECT_REAL=$(canonicalize_path_prefix "$CORRECT_PATH")
if [[ "${_WRITE_FILE_REAL:-$FILE_PATH}" != "${_WRITE_CORRECT_REAL:-$CORRECT_PATH}" ]]; then
FALLBACK="# Wrong Directory Path

Expand Down
45 changes: 45 additions & 0 deletions tests/test-cancel-signal-file.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -1373,6 +1373,51 @@ fi

rm -rf "$SYMLINK_ROOT" 2>/dev/null || true

echo "HELPER TEST 9: is_cancel_authorized rejects destination symlink alias"
# Regression test for a P1 security issue: if the destination argument is a
# symlink that points at <loop>/cancel-state.md, canonicalizing the full
# path (leaf dereferenced) would let the alias pass authorization. `mv`
# would then operate on the link path itself, corrupting loop state and
# leaking state.md contents outside the loop dir. The fix resolves symlinks
# only in the parent directory and preserves the basename verbatim.
setup_test_loop "helper-9"
touch "$LOOP_DIR/.cancel-requested"
# Create the target file so the symlink would resolve if the prefix-only
# canonicalizer were relaxed back to full canonicalization.
touch "$LOOP_DIR/cancel-state.md"
ln -sfn "$LOOP_DIR/cancel-state.md" "$TEST_DIR/dest-alias"

COMMAND_LOWER="mv ${LOOP_DIR}/state.md ${TEST_DIR}/dest-alias"
COMMAND_LOWER=$(to_lower "$COMMAND_LOWER")

if is_cancel_authorized "$LOOP_DIR" "$COMMAND_LOWER"; then
fail "helper dest symlink alias" "returns non-zero (rejected)" "returns 0 (authorized)"
else
pass "is_cancel_authorized rejects destination symlink alias"
fi
rm -f "$TEST_DIR/dest-alias" "$LOOP_DIR/cancel-state.md"

echo "HELPER TEST 10: is_cancel_authorized rejects source symlink alias"
# Regression test for a P1 security issue: if the source argument is a
# symlink aliasing <loop>/state.md, dereferencing the leaf would let it
# pass authorization. The on-disk symlink check (src_original) below
# would still catch this specific case because it probes the real path,
# but we defend in depth: the path comparison must reject the alias on
# its own.
setup_test_loop "helper-10"
touch "$LOOP_DIR/.cancel-requested"
ln -sfn "$LOOP_DIR/state.md" "$TEST_DIR/src-alias"

COMMAND_LOWER="mv ${TEST_DIR}/src-alias ${LOOP_DIR}/cancel-state.md"
COMMAND_LOWER=$(to_lower "$COMMAND_LOWER")

if is_cancel_authorized "$LOOP_DIR" "$COMMAND_LOWER"; then
fail "helper src symlink alias" "returns non-zero (rejected)" "returns 0 (authorized)"
else
pass "is_cancel_authorized rejects source symlink alias"
fi
rm -f "$TEST_DIR/src-alias"

# ========================================
# Summary
# ========================================
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Reject symlink aliases for cancel source and destination by SihaoLiu · Pull Request #94 · PolyArch/humanize · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
23 changes: 16 additions & 7 deletions hooks/lib/loop-common.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -1190,15 +1190,21 @@ is_cancel_authorized() {

# Normalize and validate source path.
#
# Canonicalize the user-provided path so a symlinked prefix in the caller's
# command (e.g. /Users/x vs /private/Users/x on macOS, or /var vs
# /private/var) matches canonical_loop_dir resolved via resolve_project_root.
# Use canonicalize_path_prefix (NOT canonicalize_path): we need to resolve
# symlinks in the parent directory so a symlinked project prefix matches
# canonical_loop_dir, but we MUST NOT dereference a symlink at the leaf.
# Otherwise a symlink like /tmp/alias -> <loop>/state.md would canonicalize
# to <loop>/state.md and pass the check, but `mv` would then operate on
# the link path itself, escaping the loop directory and/or corrupting
# loop state. The on-disk symlink rejection below (src_original check)
# still fires because it probes the real state.md under canonical_loop_dir.
#
# Re-lowercase after canonicalization because realpath on case-insensitive
# filesystems may restore the original casing of path components, which
# would diverge from the already-lowercased expected_* values.
src=$(_normalize_path "$src")
local src_canonical
src_canonical="$(canonicalize_path "$src")"
src_canonical="$(canonicalize_path_prefix "$src")"
src_canonical="${src_canonical:-$src}"
src_canonical=$(echo "$src_canonical" | tr '[:upper:]' '[:lower:]')
local expected_src_state="${loop_dir_lower}state.md"
Expand All@@ -1208,11 +1214,14 @@ is_cancel_authorized() {
return 5
fi

# Normalize and validate destination path (same canonicalize+lowercase
# transformation as source; see src comment above for rationale).
# Normalize and validate destination path. Uses canonicalize_path_prefix
# for the same reason as src: a symlink alias pointing at the real
# cancel-state.md must NOT pass authorization, because `mv` onto a
# symlink replaces the link rather than creating <loop>/cancel-state.md,
# corrupting loop state and moving state.md outside the loop dir.
dest=$(_normalize_path "$dest")
local dest_canonical
dest_canonical="$(canonicalize_path "$dest")"
dest_canonical="$(canonicalize_path_prefix "$dest")"
dest_canonical="${dest_canonical:-$dest}"
dest_canonical=$(echo "$dest_canonical" | tr '[:upper:]' '[:lower:]')
local expected_dest="${loop_dir_lower}cancel-state.md"
Expand Down
48 changes: 48 additions & 0 deletions hooks/lib/project-root.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -52,6 +52,49 @@ resolve_project_root() {
printf '%s\n' "${canonical:-$root}"
}

# canonicalize_path_prefix
#
# Resolves symlinks ONLY in the parent directory and reattaches the
# original basename verbatim. This is the right helper for comparing
# user-supplied filenames against an expected path inside a known
# directory: a symlink at /tmp/alias pointing at /real/loop/state.md
# MUST NOT canonicalize to /real/loop/state.md for comparison purposes,
# because `mv` operates on the link path itself. Resolving only the
# parent still lets a symlinked project prefix (e.g. /var vs /private/var
# on macOS) match a canonical expected path.
#
# If realpath on the parent fails, falls back to returning the input
# path unchanged (prefix cannot be canonicalized -> caller's comparison
# will correctly fail against a canonical expected path).
#
# Empty input prints nothing and returns 0.
#
canonicalize_path_prefix() {
local path="$1"
if [[ -z "$path" ]]; then
return 0
fi

local parent base parent_real
parent=$(dirname -- "$path")
base=$(basename -- "$path")

if parent_real=$(realpath "$parent" 2>/dev/null) && [[ -n "$parent_real" ]]; then
printf '%s/%s\n' "${parent_real%/}" "$base"
return 0
fi

if command -v python3 >/dev/null 2>&1; then
parent_real=$(python3 -c 'import os,sys;print(os.path.realpath(sys.argv[1]))' "$parent" 2>/dev/null || true)
if [[ -n "$parent_real" ]]; then
printf '%s/%s\n' "${parent_real%/}" "$base"
return 0
fi
fi

printf '%s\n' "$path"
}

# canonicalize_path
#
# Prints the realpath of the input path. If the path itself does not
Expand All@@ -60,6 +103,11 @@ resolve_project_root() {
# If realpath is unavailable and python3 is missing, prints the input
# path verbatim.
#
# SECURITY NOTE: This helper dereferences symlinks at the leaf when
# the leaf exists. Do NOT use it to authorize a user-supplied path
# against an expected filename -- use canonicalize_path_prefix instead,
# which only resolves the parent.
#
# Empty input prints nothing and returns 0.
#
canonicalize_path() {
Expand Down
10 changes: 6 additions & 4 deletions hooks/loop-read-validator.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -304,10 +304,12 @@ fi

CORRECT_PATH="$ACTIVE_LOOP_DIR/$CLAUDE_FILENAME"

# Compare canonical (symlink-resolved) forms -- see loop-write-validator.sh
# for the rationale; the same reasoning applies to read paths.
_READ_FILE_REAL=$(canonicalize_path "$FILE_PATH")
_READ_CORRECT_REAL=$(canonicalize_path "$CORRECT_PATH")
# Compare prefix-canonical forms -- see loop-write-validator.sh for the
# rationale; the same reasoning applies to read paths. A planted symlink
# at the leaf would otherwise let a Read follow the link outside the loop
# dir and still pass this validator.
_READ_FILE_REAL=$(canonicalize_path_prefix "$FILE_PATH")
_READ_CORRECT_REAL=$(canonicalize_path_prefix "$CORRECT_PATH")
if [[ "${_READ_FILE_REAL:-$FILE_PATH}" != "${_READ_CORRECT_REAL:-$CORRECT_PATH}" ]]; then
FALLBACK="# Wrong Directory Path

Expand Down
16 changes: 9 additions & 7 deletions hooks/loop-write-validator.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -331,13 +331,15 @@ fi

CORRECT_PATH="$ACTIVE_LOOP_DIR/$CLAUDE_FILENAME"

# Compare canonical (symlink-resolved) forms so the check is not fooled by
# equivalent paths expressed in different prefix forms (e.g. /var/... vs
# /private/var/... on macOS). A raw string compare would mis-handle a
# symlinked project prefix whenever one side was canonicalized upstream
# (e.g. by resolve_project_root) and the other was not.
_WRITE_FILE_REAL=$(canonicalize_path "$FILE_PATH")
_WRITE_CORRECT_REAL=$(canonicalize_path "$CORRECT_PATH")
# Compare prefix-canonical forms so the check is not fooled by equivalent
# paths expressed in different ancestor forms (e.g. /var/... vs /private/var/...
# on macOS) -- without dereferencing the leaf. Using full realpath here
# would let a planted symlink at <loop>/<CLAUDE_FILENAME> pointing outside
# the loop dir approve a write through the link, escalating Claude's write
# reach beyond the loop dir. canonicalize_path_prefix resolves the parent
# directory only; the basename is compared verbatim.
_WRITE_FILE_REAL=$(canonicalize_path_prefix "$FILE_PATH")
_WRITE_CORRECT_REAL=$(canonicalize_path_prefix "$CORRECT_PATH")
if [[ "${_WRITE_FILE_REAL:-$FILE_PATH}" != "${_WRITE_CORRECT_REAL:-$CORRECT_PATH}" ]]; then
FALLBACK="# Wrong Directory Path

Expand Down
45 changes: 45 additions & 0 deletions tests/test-cancel-signal-file.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -1373,6 +1373,51 @@ fi

rm -rf "$SYMLINK_ROOT" 2>/dev/null || true

echo "HELPER TEST 9: is_cancel_authorized rejects destination symlink alias"
# Regression test for a P1 security issue: if the destination argument is a
# symlink that points at <loop>/cancel-state.md, canonicalizing the full
# path (leaf dereferenced) would let the alias pass authorization. `mv`
# would then operate on the link path itself, corrupting loop state and
# leaking state.md contents outside the loop dir. The fix resolves symlinks
# only in the parent directory and preserves the basename verbatim.
setup_test_loop "helper-9"
touch "$LOOP_DIR/.cancel-requested"
# Create the target file so the symlink would resolve if the prefix-only
# canonicalizer were relaxed back to full canonicalization.
touch "$LOOP_DIR/cancel-state.md"
ln -sfn "$LOOP_DIR/cancel-state.md" "$TEST_DIR/dest-alias"

COMMAND_LOWER="mv ${LOOP_DIR}/state.md ${TEST_DIR}/dest-alias"
COMMAND_LOWER=$(to_lower "$COMMAND_LOWER")

if is_cancel_authorized "$LOOP_DIR" "$COMMAND_LOWER"; then
fail "helper dest symlink alias" "returns non-zero (rejected)" "returns 0 (authorized)"
else
pass "is_cancel_authorized rejects destination symlink alias"
fi
rm -f "$TEST_DIR/dest-alias" "$LOOP_DIR/cancel-state.md"

echo "HELPER TEST 10: is_cancel_authorized rejects source symlink alias"
# Regression test for a P1 security issue: if the source argument is a
# symlink aliasing <loop>/state.md, dereferencing the leaf would let it
# pass authorization. The on-disk symlink check (src_original) below
# would still catch this specific case because it probes the real path,
# but we defend in depth: the path comparison must reject the alias on
# its own.
setup_test_loop "helper-10"
touch "$LOOP_DIR/.cancel-requested"
ln -sfn "$LOOP_DIR/state.md" "$TEST_DIR/src-alias"

COMMAND_LOWER="mv ${TEST_DIR}/src-alias ${LOOP_DIR}/cancel-state.md"
COMMAND_LOWER=$(to_lower "$COMMAND_LOWER")

if is_cancel_authorized "$LOOP_DIR" "$COMMAND_LOWER"; then
fail "helper src symlink alias" "returns non-zero (rejected)" "returns 0 (authorized)"
else
pass "is_cancel_authorized rejects source symlink alias"
fi
rm -f "$TEST_DIR/src-alias"

# ========================================
# Summary
# ========================================
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Reject symlink aliases for cancel source and destination by SihaoLiu · Pull Request #94 · PolyArch/humanize · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
23 changes: 16 additions & 7 deletions hooks/lib/loop-common.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -1190,15 +1190,21 @@ is_cancel_authorized() {

# Normalize and validate source path.
#
# Canonicalize the user-provided path so a symlinked prefix in the caller's
# command (e.g. /Users/x vs /private/Users/x on macOS, or /var vs
# /private/var) matches canonical_loop_dir resolved via resolve_project_root.
# Use canonicalize_path_prefix (NOT canonicalize_path): we need to resolve
# symlinks in the parent directory so a symlinked project prefix matches
# canonical_loop_dir, but we MUST NOT dereference a symlink at the leaf.
# Otherwise a symlink like /tmp/alias -> <loop>/state.md would canonicalize
# to <loop>/state.md and pass the check, but `mv` would then operate on
# the link path itself, escaping the loop directory and/or corrupting
# loop state. The on-disk symlink rejection below (src_original check)
# still fires because it probes the real state.md under canonical_loop_dir.
#
# Re-lowercase after canonicalization because realpath on case-insensitive
# filesystems may restore the original casing of path components, which
# would diverge from the already-lowercased expected_* values.
src=$(_normalize_path "$src")
local src_canonical
src_canonical="$(canonicalize_path "$src")"
src_canonical="$(canonicalize_path_prefix "$src")"
src_canonical="${src_canonical:-$src}"
src_canonical=$(echo "$src_canonical" | tr '[:upper:]' '[:lower:]')
local expected_src_state="${loop_dir_lower}state.md"
Expand All@@ -1208,11 +1214,14 @@ is_cancel_authorized() {
return 5
fi

# Normalize and validate destination path (same canonicalize+lowercase
# transformation as source; see src comment above for rationale).
# Normalize and validate destination path. Uses canonicalize_path_prefix
# for the same reason as src: a symlink alias pointing at the real
# cancel-state.md must NOT pass authorization, because `mv` onto a
# symlink replaces the link rather than creating <loop>/cancel-state.md,
# corrupting loop state and moving state.md outside the loop dir.
dest=$(_normalize_path "$dest")
local dest_canonical
dest_canonical="$(canonicalize_path "$dest")"
dest_canonical="$(canonicalize_path_prefix "$dest")"
dest_canonical="${dest_canonical:-$dest}"
dest_canonical=$(echo "$dest_canonical" | tr '[:upper:]' '[:lower:]')
local expected_dest="${loop_dir_lower}cancel-state.md"
Expand Down
48 changes: 48 additions & 0 deletions hooks/lib/project-root.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -52,6 +52,49 @@ resolve_project_root() {
printf '%s\n' "${canonical:-$root}"
}

# canonicalize_path_prefix
#
# Resolves symlinks ONLY in the parent directory and reattaches the
# original basename verbatim. This is the right helper for comparing
# user-supplied filenames against an expected path inside a known
# directory: a symlink at /tmp/alias pointing at /real/loop/state.md
# MUST NOT canonicalize to /real/loop/state.md for comparison purposes,
# because `mv` operates on the link path itself. Resolving only the
# parent still lets a symlinked project prefix (e.g. /var vs /private/var
# on macOS) match a canonical expected path.
#
# If realpath on the parent fails, falls back to returning the input
# path unchanged (prefix cannot be canonicalized -> caller's comparison
# will correctly fail against a canonical expected path).
#
# Empty input prints nothing and returns 0.
#
canonicalize_path_prefix() {
local path="$1"
if [[ -z "$path" ]]; then
return 0
fi

local parent base parent_real
parent=$(dirname -- "$path")
base=$(basename -- "$path")

if parent_real=$(realpath "$parent" 2>/dev/null) && [[ -n "$parent_real" ]]; then
printf '%s/%s\n' "${parent_real%/}" "$base"
return 0
fi

if command -v python3 >/dev/null 2>&1; then
parent_real=$(python3 -c 'import os,sys;print(os.path.realpath(sys.argv[1]))' "$parent" 2>/dev/null || true)
if [[ -n "$parent_real" ]]; then
printf '%s/%s\n' "${parent_real%/}" "$base"
return 0
fi
fi

printf '%s\n' "$path"
}

# canonicalize_path
#
# Prints the realpath of the input path. If the path itself does not
Expand All@@ -60,6 +103,11 @@ resolve_project_root() {
# If realpath is unavailable and python3 is missing, prints the input
# path verbatim.
#
# SECURITY NOTE: This helper dereferences symlinks at the leaf when
# the leaf exists. Do NOT use it to authorize a user-supplied path
# against an expected filename -- use canonicalize_path_prefix instead,
# which only resolves the parent.
#
# Empty input prints nothing and returns 0.
#
canonicalize_path() {
Expand Down
10 changes: 6 additions & 4 deletions hooks/loop-read-validator.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -304,10 +304,12 @@ fi

CORRECT_PATH="$ACTIVE_LOOP_DIR/$CLAUDE_FILENAME"

# Compare canonical (symlink-resolved) forms -- see loop-write-validator.sh
# for the rationale; the same reasoning applies to read paths.
_READ_FILE_REAL=$(canonicalize_path "$FILE_PATH")
_READ_CORRECT_REAL=$(canonicalize_path "$CORRECT_PATH")
# Compare prefix-canonical forms -- see loop-write-validator.sh for the
# rationale; the same reasoning applies to read paths. A planted symlink
# at the leaf would otherwise let a Read follow the link outside the loop
# dir and still pass this validator.
_READ_FILE_REAL=$(canonicalize_path_prefix "$FILE_PATH")
_READ_CORRECT_REAL=$(canonicalize_path_prefix "$CORRECT_PATH")
if [[ "${_READ_FILE_REAL:-$FILE_PATH}" != "${_READ_CORRECT_REAL:-$CORRECT_PATH}" ]]; then
FALLBACK="# Wrong Directory Path

Expand Down
16 changes: 9 additions & 7 deletions hooks/loop-write-validator.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -331,13 +331,15 @@ fi

CORRECT_PATH="$ACTIVE_LOOP_DIR/$CLAUDE_FILENAME"

# Compare canonical (symlink-resolved) forms so the check is not fooled by
# equivalent paths expressed in different prefix forms (e.g. /var/... vs
# /private/var/... on macOS). A raw string compare would mis-handle a
# symlinked project prefix whenever one side was canonicalized upstream
# (e.g. by resolve_project_root) and the other was not.
_WRITE_FILE_REAL=$(canonicalize_path "$FILE_PATH")
_WRITE_CORRECT_REAL=$(canonicalize_path "$CORRECT_PATH")
# Compare prefix-canonical forms so the check is not fooled by equivalent
# paths expressed in different ancestor forms (e.g. /var/... vs /private/var/...
# on macOS) -- without dereferencing the leaf. Using full realpath here
# would let a planted symlink at <loop>/<CLAUDE_FILENAME> pointing outside
# the loop dir approve a write through the link, escalating Claude's write
# reach beyond the loop dir. canonicalize_path_prefix resolves the parent
# directory only; the basename is compared verbatim.
_WRITE_FILE_REAL=$(canonicalize_path_prefix "$FILE_PATH")
_WRITE_CORRECT_REAL=$(canonicalize_path_prefix "$CORRECT_PATH")
if [[ "${_WRITE_FILE_REAL:-$FILE_PATH}" != "${_WRITE_CORRECT_REAL:-$CORRECT_PATH}" ]]; then
FALLBACK="# Wrong Directory Path

Expand Down
45 changes: 45 additions & 0 deletions tests/test-cancel-signal-file.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -1373,6 +1373,51 @@ fi

rm -rf "$SYMLINK_ROOT" 2>/dev/null || true

echo "HELPER TEST 9: is_cancel_authorized rejects destination symlink alias"
# Regression test for a P1 security issue: if the destination argument is a
# symlink that points at <loop>/cancel-state.md, canonicalizing the full
# path (leaf dereferenced) would let the alias pass authorization. `mv`
# would then operate on the link path itself, corrupting loop state and
# leaking state.md contents outside the loop dir. The fix resolves symlinks
# only in the parent directory and preserves the basename verbatim.
setup_test_loop "helper-9"
touch "$LOOP_DIR/.cancel-requested"
# Create the target file so the symlink would resolve if the prefix-only
# canonicalizer were relaxed back to full canonicalization.
touch "$LOOP_DIR/cancel-state.md"
ln -sfn "$LOOP_DIR/cancel-state.md" "$TEST_DIR/dest-alias"

COMMAND_LOWER="mv ${LOOP_DIR}/state.md ${TEST_DIR}/dest-alias"
COMMAND_LOWER=$(to_lower "$COMMAND_LOWER")

if is_cancel_authorized "$LOOP_DIR" "$COMMAND_LOWER"; then
fail "helper dest symlink alias" "returns non-zero (rejected)" "returns 0 (authorized)"
else
pass "is_cancel_authorized rejects destination symlink alias"
fi
rm -f "$TEST_DIR/dest-alias" "$LOOP_DIR/cancel-state.md"

echo "HELPER TEST 10: is_cancel_authorized rejects source symlink alias"
# Regression test for a P1 security issue: if the source argument is a
# symlink aliasing <loop>/state.md, dereferencing the leaf would let it
# pass authorization. The on-disk symlink check (src_original) below
# would still catch this specific case because it probes the real path,
# but we defend in depth: the path comparison must reject the alias on
# its own.
setup_test_loop "helper-10"
touch "$LOOP_DIR/.cancel-requested"
ln -sfn "$LOOP_DIR/state.md" "$TEST_DIR/src-alias"

COMMAND_LOWER="mv ${TEST_DIR}/src-alias ${LOOP_DIR}/cancel-state.md"
COMMAND_LOWER=$(to_lower "$COMMAND_LOWER")

if is_cancel_authorized "$LOOP_DIR" "$COMMAND_LOWER"; then
fail "helper src symlink alias" "returns non-zero (rejected)" "returns 0 (authorized)"
else
pass "is_cancel_authorized rejects source symlink alias"
fi
rm -f "$TEST_DIR/src-alias"

# ========================================
# Summary
# ========================================
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); Reject symlink aliases for cancel source and destination by SihaoLiu · Pull Request #94 · PolyArch/humanize · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
23 changes: 16 additions & 7 deletions hooks/lib/loop-common.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -1190,15 +1190,21 @@ is_cancel_authorized() {

# Normalize and validate source path.
#
# Canonicalize the user-provided path so a symlinked prefix in the caller's
# command (e.g. /Users/x vs /private/Users/x on macOS, or /var vs
# /private/var) matches canonical_loop_dir resolved via resolve_project_root.
# Use canonicalize_path_prefix (NOT canonicalize_path): we need to resolve
# symlinks in the parent directory so a symlinked project prefix matches
# canonical_loop_dir, but we MUST NOT dereference a symlink at the leaf.
# Otherwise a symlink like /tmp/alias -> <loop>/state.md would canonicalize
# to <loop>/state.md and pass the check, but `mv` would then operate on
# the link path itself, escaping the loop directory and/or corrupting
# loop state. The on-disk symlink rejection below (src_original check)
# still fires because it probes the real state.md under canonical_loop_dir.
#
# Re-lowercase after canonicalization because realpath on case-insensitive
# filesystems may restore the original casing of path components, which
# would diverge from the already-lowercased expected_* values.
src=$(_normalize_path "$src")
local src_canonical
src_canonical="$(canonicalize_path "$src")"
src_canonical="$(canonicalize_path_prefix "$src")"
src_canonical="${src_canonical:-$src}"
src_canonical=$(echo "$src_canonical" | tr '[:upper:]' '[:lower:]')
local expected_src_state="${loop_dir_lower}state.md"
Expand All@@ -1208,11 +1214,14 @@ is_cancel_authorized() {
return 5
fi

# Normalize and validate destination path (same canonicalize+lowercase
# transformation as source; see src comment above for rationale).
# Normalize and validate destination path. Uses canonicalize_path_prefix
# for the same reason as src: a symlink alias pointing at the real
# cancel-state.md must NOT pass authorization, because `mv` onto a
# symlink replaces the link rather than creating <loop>/cancel-state.md,
# corrupting loop state and moving state.md outside the loop dir.
dest=$(_normalize_path "$dest")
local dest_canonical
dest_canonical="$(canonicalize_path "$dest")"
dest_canonical="$(canonicalize_path_prefix "$dest")"
dest_canonical="${dest_canonical:-$dest}"
dest_canonical=$(echo "$dest_canonical" | tr '[:upper:]' '[:lower:]')
local expected_dest="${loop_dir_lower}cancel-state.md"
Expand Down
48 changes: 48 additions & 0 deletions hooks/lib/project-root.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -52,6 +52,49 @@ resolve_project_root() {
printf '%s\n' "${canonical:-$root}"
}

# canonicalize_path_prefix
#
# Resolves symlinks ONLY in the parent directory and reattaches the
# original basename verbatim. This is the right helper for comparing
# user-supplied filenames against an expected path inside a known
# directory: a symlink at /tmp/alias pointing at /real/loop/state.md
# MUST NOT canonicalize to /real/loop/state.md for comparison purposes,
# because `mv` operates on the link path itself. Resolving only the
# parent still lets a symlinked project prefix (e.g. /var vs /private/var
# on macOS) match a canonical expected path.
#
# If realpath on the parent fails, falls back to returning the input
# path unchanged (prefix cannot be canonicalized -> caller's comparison
# will correctly fail against a canonical expected path).
#
# Empty input prints nothing and returns 0.
#
canonicalize_path_prefix() {
local path="$1"
if [[ -z "$path" ]]; then
return 0
fi

local parent base parent_real
parent=$(dirname -- "$path")
base=$(basename -- "$path")

if parent_real=$(realpath "$parent" 2>/dev/null) && [[ -n "$parent_real" ]]; then
printf '%s/%s\n' "${parent_real%/}" "$base"
return 0
fi

if command -v python3 >/dev/null 2>&1; then
parent_real=$(python3 -c 'import os,sys;print(os.path.realpath(sys.argv[1]))' "$parent" 2>/dev/null || true)
if [[ -n "$parent_real" ]]; then
printf '%s/%s\n' "${parent_real%/}" "$base"
return 0
fi
fi

printf '%s\n' "$path"
}

# canonicalize_path
#
# Prints the realpath of the input path. If the path itself does not
Expand All@@ -60,6 +103,11 @@ resolve_project_root() {
# If realpath is unavailable and python3 is missing, prints the input
# path verbatim.
#
# SECURITY NOTE: This helper dereferences symlinks at the leaf when
# the leaf exists. Do NOT use it to authorize a user-supplied path
# against an expected filename -- use canonicalize_path_prefix instead,
# which only resolves the parent.
#
# Empty input prints nothing and returns 0.
#
canonicalize_path() {
Expand Down
10 changes: 6 additions & 4 deletions hooks/loop-read-validator.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -304,10 +304,12 @@ fi

CORRECT_PATH="$ACTIVE_LOOP_DIR/$CLAUDE_FILENAME"

# Compare canonical (symlink-resolved) forms -- see loop-write-validator.sh
# for the rationale; the same reasoning applies to read paths.
_READ_FILE_REAL=$(canonicalize_path "$FILE_PATH")
_READ_CORRECT_REAL=$(canonicalize_path "$CORRECT_PATH")
# Compare prefix-canonical forms -- see loop-write-validator.sh for the
# rationale; the same reasoning applies to read paths. A planted symlink
# at the leaf would otherwise let a Read follow the link outside the loop
# dir and still pass this validator.
_READ_FILE_REAL=$(canonicalize_path_prefix "$FILE_PATH")
_READ_CORRECT_REAL=$(canonicalize_path_prefix "$CORRECT_PATH")
if [[ "${_READ_FILE_REAL:-$FILE_PATH}" != "${_READ_CORRECT_REAL:-$CORRECT_PATH}" ]]; then
FALLBACK="# Wrong Directory Path

Expand Down
16 changes: 9 additions & 7 deletions hooks/loop-write-validator.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -331,13 +331,15 @@ fi

CORRECT_PATH="$ACTIVE_LOOP_DIR/$CLAUDE_FILENAME"

# Compare canonical (symlink-resolved) forms so the check is not fooled by
# equivalent paths expressed in different prefix forms (e.g. /var/... vs
# /private/var/... on macOS). A raw string compare would mis-handle a
# symlinked project prefix whenever one side was canonicalized upstream
# (e.g. by resolve_project_root) and the other was not.
_WRITE_FILE_REAL=$(canonicalize_path "$FILE_PATH")
_WRITE_CORRECT_REAL=$(canonicalize_path "$CORRECT_PATH")
# Compare prefix-canonical forms so the check is not fooled by equivalent
# paths expressed in different ancestor forms (e.g. /var/... vs /private/var/...
# on macOS) -- without dereferencing the leaf. Using full realpath here
# would let a planted symlink at <loop>/<CLAUDE_FILENAME> pointing outside
# the loop dir approve a write through the link, escalating Claude's write
# reach beyond the loop dir. canonicalize_path_prefix resolves the parent
# directory only; the basename is compared verbatim.
_WRITE_FILE_REAL=$(canonicalize_path_prefix "$FILE_PATH")
_WRITE_CORRECT_REAL=$(canonicalize_path_prefix "$CORRECT_PATH")
if [[ "${_WRITE_FILE_REAL:-$FILE_PATH}" != "${_WRITE_CORRECT_REAL:-$CORRECT_PATH}" ]]; then
FALLBACK="# Wrong Directory Path

Expand Down
45 changes: 45 additions & 0 deletions tests/test-cancel-signal-file.sh
Original file line numberDiff line numberDiff line change
Expand Up@@ -1373,6 +1373,51 @@ fi

rm -rf "$SYMLINK_ROOT" 2>/dev/null || true

echo "HELPER TEST 9: is_cancel_authorized rejects destination symlink alias"
# Regression test for a P1 security issue: if the destination argument is a
# symlink that points at <loop>/cancel-state.md, canonicalizing the full
# path (leaf dereferenced) would let the alias pass authorization. `mv`
# would then operate on the link path itself, corrupting loop state and
# leaking state.md contents outside the loop dir. The fix resolves symlinks
# only in the parent directory and preserves the basename verbatim.
setup_test_loop "helper-9"
touch "$LOOP_DIR/.cancel-requested"
# Create the target file so the symlink would resolve if the prefix-only
# canonicalizer were relaxed back to full canonicalization.
touch "$LOOP_DIR/cancel-state.md"
ln -sfn "$LOOP_DIR/cancel-state.md" "$TEST_DIR/dest-alias"

COMMAND_LOWER="mv ${LOOP_DIR}/state.md ${TEST_DIR}/dest-alias"
COMMAND_LOWER=$(to_lower "$COMMAND_LOWER")

if is_cancel_authorized "$LOOP_DIR" "$COMMAND_LOWER"; then
fail "helper dest symlink alias" "returns non-zero (rejected)" "returns 0 (authorized)"
else
pass "is_cancel_authorized rejects destination symlink alias"
fi
rm -f "$TEST_DIR/dest-alias" "$LOOP_DIR/cancel-state.md"

echo "HELPER TEST 10: is_cancel_authorized rejects source symlink alias"
# Regression test for a P1 security issue: if the source argument is a
# symlink aliasing <loop>/state.md, dereferencing the leaf would let it
# pass authorization. The on-disk symlink check (src_original) below
# would still catch this specific case because it probes the real path,
# but we defend in depth: the path comparison must reject the alias on
# its own.
setup_test_loop "helper-10"
touch "$LOOP_DIR/.cancel-requested"
ln -sfn "$LOOP_DIR/state.md" "$TEST_DIR/src-alias"

COMMAND_LOWER="mv ${TEST_DIR}/src-alias ${LOOP_DIR}/cancel-state.md"
COMMAND_LOWER=$(to_lower "$COMMAND_LOWER")

if is_cancel_authorized "$LOOP_DIR" "$COMMAND_LOWER"; then
fail "helper src symlink alias" "returns non-zero (rejected)" "returns 0 (authorized)"
else
pass "is_cancel_authorized rejects source symlink alias"
fi
rm -f "$TEST_DIR/src-alias"

# ========================================
# Summary
# ========================================
Expand Down
Loading