mirror of
https://github.com/mudler/LocalAI.git
synced 2026-09-29 09:35:02 -04:00
utils.VerifyPath joins its argument onto the base path, so a path that the caller already joined always passes. Several callers gave it joined paths, and their checks could not fail: - modeladmin (config view, patch, edit, pin and state): the config file path from the loader. A config loaded from outside the models directory (--models-config-file) could be pinned, and the pin wrote the outside file. The patch and state paths stopped later, in the mutation snapshot, with a different error. - core/backend/tts.go: the model path joined onto the models path. - The trellis2cpp and stablediffusion-ggml backends: option paths (*_path) joined onto the model path. A "../" value outside the model directory was accepted. Add utils.VerifyResolvedPath for a full path. modeladmin and tts use it. The backends now check the relative option value before they join it. A rename in modeladmin checks the new relative name. For models from a config file outside the models directory, the admin API and web UI now return ErrPathNotTrusted for view, edit, pin, and enable or disable. The docs describe this. Assisted-by: Claude:claude-opus-5-5 [Claude Code] Signed-off-by: Ettore Di Giacinto <mudler@localai.io> Co-authored-by: Ettore Di Giacinto <mudler@localai.io>
71 lines
2.0 KiB
Go
71 lines
2.0 KiB
Go
package utils
|
|
|
|
import (
|
|
"fmt"
|
|
"os"
|
|
"path/filepath"
|
|
"strings"
|
|
)
|
|
|
|
func ExistsInPath(path string, s string) bool {
|
|
_, err := os.Stat(filepath.Join(path, s))
|
|
return err == nil
|
|
}
|
|
|
|
func InTrustedRoot(path string, trustedRoot string) error {
|
|
for {
|
|
parent := filepath.Dir(path)
|
|
// Dir stops changing at "/" for an absolute path and at "." for a
|
|
// relative one; waiting for "/" alone spins forever on the latter.
|
|
if parent == path {
|
|
return fmt.Errorf("path is outside of trusted root")
|
|
}
|
|
path = parent
|
|
if path == trustedRoot {
|
|
return nil
|
|
}
|
|
}
|
|
}
|
|
|
|
// VerifyPath verifies that path, taken relative to basePath, is based in
|
|
// basePath. It joins path onto basePath first, so an absolute path is read as
|
|
// relative to the base as well: give it the untrusted relative name, never a
|
|
// path that has already been joined. For a full path use VerifyResolvedPath.
|
|
func VerifyPath(path, basePath string) error {
|
|
c := filepath.Clean(filepath.Join(basePath, path))
|
|
return InTrustedRoot(c, filepath.Clean(basePath))
|
|
}
|
|
|
|
// VerifyResolvedPath verifies that path, a full path rather than one relative
|
|
// to basePath, is based in basePath.
|
|
func VerifyResolvedPath(path, basePath string) error {
|
|
return InTrustedRoot(filepath.Clean(path), filepath.Clean(basePath))
|
|
}
|
|
|
|
// SanitizeFileName sanitizes the given filename
|
|
func SanitizeFileName(fileName string) string {
|
|
// filepath.Clean to clean the path
|
|
cleanName := filepath.Clean(fileName)
|
|
// filepath.Base to ensure we only get the final element, not any directory path
|
|
baseName := filepath.Base(cleanName)
|
|
// Replace any remaining tricky characters that might have survived cleaning
|
|
safeName := strings.ReplaceAll(baseName, "..", "")
|
|
return safeName
|
|
}
|
|
|
|
func GenerateUniqueFileName(dir, baseName, ext string) string {
|
|
counter := 1
|
|
fileName := baseName + ext
|
|
|
|
for {
|
|
filePath := filepath.Join(dir, fileName)
|
|
_, err := os.Stat(filePath)
|
|
if os.IsNotExist(err) {
|
|
return fileName
|
|
}
|
|
|
|
counter++
|
|
fileName = fmt.Sprintf("%s_%d%s", baseName, counter, ext)
|
|
}
|
|
}
|