Repository navigation
Validate module names in the memiavl snapshot importer - #4469
Conversation
|
I'll fix CI failures and address comments from users with write access that start with 'Devin'.
|
|
The latest Buf updates on your PR. Results from workflow Buf / buf (pull_request).
|
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #4469 +/- ##
=======================================
Coverage 56.80% 56.80%
=======================================
Files 2127 2127
Lines 167022 167027 +5
=======================================
+ Hits 94879 94888 +9
+ Misses 72138 72134 -4
Partials 5 5
Flags with carried forward coverage won't be shown. Click here to find out more.
🚀 New features to boost your workflow:
|
PR SummaryMedium Risk Overview
Reviewed by Cursor Bugbot for commit 1c71b99. Bugbot is set up for automated code reviews on this repo. Configure here. |
Only accept plain directory names from the snapshot stream, so a malformed snapshot fails early with a clear error.
5d53880 to
aea3209
Compare
|
This change makes seidroid review · decision Findings: 0 blocking | 0 non-blocking | 0 posted inline |
There was a problem hiding this comment.
Since my last review only the doc comment, the test name and fixture wording and the PR description have changed; validateModuleName and the AddModule guard are identical, so names that would leave the memiavl import temp dir are still rejected, and I raised nothing before that needed addressing. Nothing blocks; the one other reading (codex) found nothing, which matches mine, and the tests were not run because this sandbox has no Go toolchain.
seidroid review · decision approve · session 91cb333bade445ca9b0b1c5e206cc88f · turn resp_claude_95e4a8270bb4cb4f5a1f0a8b3b85b60a · item 8806d07bebab51b7942be1f02a178662
Findings: 0 blocking | 0 non-blocking | 0 posted inline
|
Created backport PR for
Please cherry-pick the changes locally and resolve any conflicts. git fetch origin backport-4469-to-release/v6.7
git worktree add --checkout .worktree/backport-4469-to-release/v6.7 backport-4469-to-release/v6.7
cd .worktree/backport-4469-to-release/v6.7
git reset --hard HEAD^
git cherry-pick -x 96e048374c34995998a4a15ab12dced82c4201b3
git push --force-with-lease |
`MultiTreeImporter.AddModule` used the module name from the snapshot stream as a path component without validating it. Real module names are store keys, so anything other than a plain directory name means the snapshot is malformed. `AddModule` now rejects empty, `.`, `..`, absolute and multi-component names before it creates any files, so such a snapshot fails early with a clear error. Valid snapshots import exactly as before and the AppHash is unchanged. (cherry picked from commit 96e0483)
Systematic changelog re-generation for the v6.7.1 patch release. Adds the PRs merged to `release/v6.7` since the v6.7.0 changelog (#4443), as reported by `scripts/generate-changelog.sh release/v6.6 release/v6.7`: - #4473 Backport `release/v6.7`: Make the composite store router an atomic pointer - #4465 Backport `release/v6.7`: fix(seidb): keep the memIAVL nonce when state sync restores a mid-mig… - #4445 Backport `release/v6.7`: Update v6.7 changelog in prep to cut v6.7.0 - #4444 Bump version to v6.7.0 in prep for release Only the `## v6.7` PR list changes, so the `backport release/v6.7` cherry-pick applies cleanly (simulated with `git merge-tree` against `origin/release/v6.7`). Not included: #4474 (the `release/v6.7` backport of #4469), which is still open. If it lands before the cut, this list needs regenerating. Co-authored-by: Cursor <cursoragent@cursor.com>
MultiTreeImporter.AddModuleused the module name from the snapshot stream as a path component without validating it. Real module names are store keys, so anything other than a plain directory name means the snapshot is malformed.AddModulenow rejects empty,.,.., absolute and multi-component names before it creates any files, so such a snapshot fails early with a clear error. Valid snapshots import exactly as before and the AppHash is unchanged.