Conversation
Reviewer's guide (collapsed on small PRs)Reviewer's GuideHardens temporary mount-point creation by replacing the predictable QDir exists/mkpath sequence with POSIX mkdtemp, preventing symlink and TOCTOU attacks while preserving naming, failure, and caller compatibility. Sequence diagram for secure temporary mount-point creationsequenceDiagram
participant Resize as XFS/BTRFS resize
participant Utils
participant FS as POSIX filesystem
Resize->>Utils: mkTempDir(infix)
Utils->>FS: mkdtemp(templateBytes)
alt directory created
FS-->>Utils: random directory path
Utils-->>Resize: mountPoint
Resize->>Utils: rmTempDir(dirName)
else creation failed
FS-->>Utils: nullptr
Utils-->>Resize: empty QString
end
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
1. Root cause: mkTempDir used predictable 'XXXXXX' literal with non-atomic exists()+mkpath(), vulnerable to CWE-377/367/59; LICENSES/ missing GPL-3.0-or-later.txt causing REUSE lint fail 2. Fix: replace with POSIX mkdtemp(3) for atomic random temp dir creation; add missing GPL-3.0-or-later.txt license file 3. Impact: callers unchanged (isEmpty() check preserved); CI license-check now passes Influence: 1. Verify temp directory creation succeeds with random paths 2. Verify existing mkTempDir callers work correctly 3. Confirm REUSE lint passes in CI fix: 安全创建临时目录并补充许可证文件 1. 根因:mkTempDir使用可预测的'XXXXXX'字面量配合非原子的 exists()+mkpath(),存在CWE-377/367/59漏洞;LICENSES/目录 缺少GPL-3.0-or-later.txt导致REUSE lint检查失败 2. 方案:替换为POSIX mkdtemp(3)实现原子随机临时目录创建; 补充缺失的GPL-3.0-or-later.txt许可证文件 3. 影响:所有调用方不变(isEmpty()检查保留);CI许可证检查通过 Influence: 1. 验证临时目录创建成功且路径随机 2. 验证现有mkTempDir调用方仍正常工作 3. 确认REUSE lint在CI中通过 PMS: BUG-378601
78615f7 to
735dd37
Compare
deepin pr auto reviewAI 代码审查报告
总体评价
本次 PR 修复了 修改文件列表
四维度评分维度1: 语法逻辑 ✓ (25/25)
分析:
维度2: 代码质量 ✓ (25/25)
分析:
维度3: 代码性能 ✓ (20/20)
分析:
维度4: 代码安全 ✓ (30/30)
分析: 本次 PR 修复了以下三类预存安全漏洞:
当前代码安全状态:
漏洞对比统计: 新增漏洞 0 个,减少漏洞 0 个,持平 0 个(GitHub 全量分析模式,无历史对比) OCR 审查结果: 0 条问题("Looks good to me") 改进建议虽然本次 PR 代码质量优秀,以下为可选的后续优化建议:
审查结论本次 PR 是一个高质量的安全修复,正确使用 POSIX |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: max-lvs, tianming-1996 The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
Root Cause Analysis
The
mkTempDirfunction inbasestruct/utils.cppconstructs a predictable temporary directory path using a literal"XXXXXX"suffix and creates it via non-atomicQDir::exists()+QDir::mkpath(). This introduces three CWE vulnerabilities:/var/tmp/XXXXXXis predictable — an attacker can pre-place a symlink.exists()check andmkpath()call are non-atomic, creating a TOCTOU race window.QDir::mkpath()follows symlinks, and if the path already exists it returns without rejection.Trigger path: attacker pre-creates
ln -s /etc /var/tmp/XXXXXX→ root-privileged diskmanager mounts a filesystem to/var/tmp/XXXXXX→ critical system directory overwritten.Fix
Replace the manual path construction +
QDir::mkpath()with POSIXmkdtemp(3), which atomically creates a randomly-named directory. This eliminates all three CWE classes in a single function change. Return value semantics are preserved — callers already checkisEmpty()for failure.Change Safety Assessment
Risk level: Low
mkTempDirfunction body; function signature unchanged.xfs.cpp:146,btrfs.cpp:204) checkmountPoint.isEmpty()and return false on failure — fully compatible with the new empty-string-on-failure behavior.Business Impact
Affects XFS and BTRFS filesystem resize operations that create temporary mount points. After the fix, temporary mount directories use random names, preventing symlink-based attacks. Normal resize operations are unaffected.
Verification Suggestion
Verify that XFS and BTRFS partition resize operations still work correctly — the temporary mount point should be created and cleaned up as before.
根因分析
basestruct/utils.cpp的mkTempDir函数使用字面量"XXXXXX"拼接固定路径,通过非原子的QDir::exists()+QDir::mkpath()创建目录,存在三类 CWE 漏洞:/var/tmp/XXXXXX可预测,攻击者可预置符号链接。exists()与mkpath()非原子操作,存在 TOCTOU 竞态窗口。QDir::mkpath()跟随符号链接,路径已存在时直接返回不拒绝。触发路径:攻击者预置
ln -s /etc /var/tmp/XXXXXX→ root 权限 diskmanager 挂载文件系统到/var/tmp/XXXXXX→ 系统关键目录被覆盖。修复方案
使用 POSIX
mkdtemp(3)替代手动拼接 +QDir::mkpath(),原子创建随机命名目录,一次消除三类 CWE。返回值语义保持不变——调用方已检查isEmpty()处理失败。改动安全评估
风险等级:低
mkTempDir函数体,函数签名不变。xfs.cpp:146、btrfs.cpp:204)均检查mountPoint.isEmpty()并返回 false,与新失败语义完全兼容。业务影响范围
影响 XFS 和 BTRFS 文件系统调整大小操作中创建临时挂载点的行为。修复后临时挂载目录使用随机名称,防止符号链接攻击。正常调整操作不受影响。
验证建议
验证 XFS 和 BTRFS 分区调整大小操作是否正常工作——临时挂载点的创建和清理应与之前一致。
Summary by Sourcery
Harden temporary mount-point creation against predictable-path, TOCTOU, and symlink attacks.
Bug Fixes:
Chores: