Skip to content

[v0.13.0-beta1-m.1] backport: security: path traversal and git option injection fixes - #7

Merged
smerkviladze merged 15 commits into
Mirantis:v0.13.0-beta1-m.1from
smerkviladze:v0.13.0-beta1-m.1
Jul 6, 2026
Merged

smerkviladze merged 15 commits into
Mirantis:v0.13.0-beta1-m.1from
smerkviladze:v0.13.0-beta1-m.1

Conversation

@smerkviladze

@smerkviladze smerkviladze commented May 25, 2026 •

Copy link
Copy Markdown
Collaborator

Backport of security fixes for CVE-2026-33747 onto the v0.13.0-beta1 pseudo-version base (d5c1d78) used in the docker-buildx release shipped with MCR 25.0.16.

Cherry-picked from Mirantis/buildkit#5 (v0.12 backport), adapted for the v0.13.0-beta1 codebase.

Security fixes:

  • executor: validate container IDs centrally - reject malformed container IDs before use
  • source/http: sanitize downloaded filenames - prevent path traversal via filenames
  • source/http: use os.Root for root-confined file operations - restrict writes to the cache root
  • git: harden ref arg handling - reject refs starting with - to prevent option injection
  • git: normalize and validate subdir paths - validate each subdir path component is a real directory
  • source/git: use os.Root for subdir validation - cross-platform safe subdir access

Build / CI enablement (needed to compile and test the backport on this older base):

  • Bump Go toolchain from 1.20 to 1.24 (provides os.Root for cross-platform safe file access)
  • Bump docker/bake-action from 4 to 5
  • Bump actions/upload-artifact and download-artifact to v4
  • Bump golangci-lint to 1.64.2 and address lint
  • Bump xx to 1.6.1, parameterize via ARG
  • Pin js-yaml to 4.3.0 (fixes the test matrix setup broken by the js-yaml 5.0 release)

Fixes CVE-2026-33747 and CVE-2026-33748

@corhere corhere left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Rewrite history as you go, please.

Tools like git-absorb automate the tedious part of matching fixes to the commits that need amending.

Comment thread source/git/source_unix.go Outdated
Comment thread source/git/source_windows.go Outdated

@corhere corhere left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Comment thread source/git/source.go Outdated
tonistiigi and others added 10 commits July 6, 2026 17:45
Add executor.ValidContainerID and enforce it in runc/containerd Run paths.

Only runc executor used the ID in filesystem operations.

Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com>
(cherry picked from commit 789df2422341960b7549d14ea475add43e73cd74)
(cherry picked from commit 5e285127899ea49bad2437f2d53114bbe30dd36f)
(cherry picked from commit 099cf80)
Signed-off-by: Sopho Merkviladze <smerkviladze@mirantis.com>
Add safeFileName and route all getFileName sources through it.

Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com>
(cherry picked from commit 9d117af5ab1e1032f75658884384328fea440843)
(cherry picked from commit ee4de4c2aa53a76fb2ba135cfcb2daa8e45c5b80)
(cherry picked from commit 9ce6f62)
Signed-off-by: Sopho Merkviladze <smerkviladze@mirantis.com>
Use securejoin.SecureJoin to compute a path confined to the root directory before performing operations such as opening, changing ownership, or updating timestamps on the downloaded file. This prevents path traversal attacks using crafted filenames.

os.OpenRoot (introduced in Go 1.24) is not available on this branch; securejoin provides equivalent root confinement functionality.

(cherry-picked from commit df43783)

Signed-off-by: Sopho Merkviladze <smerkviladze@mirantis.com>
Validate user-provided refs once during identifier construction and reject
option-like refs with leading '-'. There is no known attack related to
previous core, patch is to make ref handling more robust and improve
errors.

Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com>
(cherry picked from commit f5462c2)
Signed-off-by: Sopho Merkviladze <smerkviladze@mirantis.com>
Normalize Git subdir fragments and validate checkout subdir components
so each segment must be a real directory, preventing traversal and symlink escapes.

Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com>
(cherry picked from commit 45b038c)
Signed-off-by: Sopho Merkviladze <smerkviladze@mirantis.com>
  Linux:
  - Uses openat with O_PATH | O_NOFOLLOW per component to eliminate TOCTOU
    races.
  - Traversal fd is only for validation; a readable fd is opened via
    readdirnames for listing directory entries.

  Windows:
  - Falls back to os.Lstat per component and os.Open for readability.
  - TOCTOU exists theoretically, but acceptable for controlled BuildKit
    temp dirs.

  Benefits:
  - Prevents symlink escapes at kernel level, strengthening CVE-2026-33748 fix.
  - Returns a reusable *os.File, removing the separate validate+open two-step.
  - Cross-platform API via platform-specific files simplifies call site.

  Updated tests verify openSubdirSafe correctness and that readdirnames
  correctly obtains a readable fd from an O_PATH anchor on Linux.

Signed-off-by: Sopho Merkviladze <smerkviladze@mirantis.com>
docker/bake-action < v5 is not compatible with buildx >= 0.20.0.
Update both .test.yml and validate.yml to use bake-action@v5.

Signed-off-by: Sopho Merkviladze <smerkviladze@mirantis.com>
Signed-off-by: Sopho Merkviladze <smerkviladze@mirantis.com>
Signed-off-by: Sopho Merkviladze <smerkviladze@mirantis.com>
… tag

- Dockerfile: use golang:-alpine (unpinned) so the builder
  stage resolves correctly; golang:1.24-alpine3.18 does not exist
- lint.Dockerfile: golangci-lint from 1.54.2 to 1.64.2 (Go 1.24 compatible)
- .golangci.yml: exclude G115 (integer overflow — new rule in this version;
  all flagged conversions are pre-existing and intentional)
- Fix pre-existing issues now surfaced by 1.64.2: errname type naming,
  govet non-constant format strings, gosimple struct literal,
  revive indent-error-flow, gosec G306, unused nolint directive

Signed-off-by: Sopho Merkviladze <smerkviladze@mirantis.com>
  Replace the platform-specific openSubdirSafe/readdirnames approach with
  validateDirsOnly(r *os.Root, subpath string) and rootRelativePath.

Signed-off-by: Sopho Merkviladze <smerkviladze@mirantis.com>
Replace filepath-securejoin with os.OpenRoot + dirRoot.OpenFile to confine
downloaded file creation to the snapshot directory at the OS level.
Chown and Chtimes still use filepath.Join(dir, name) as a Go 1.24
workaround; name is already validated by safeFileName.

Signed-off-by: Sopho Merkviladze <smerkviladze@mirantis.com>
The hardcoded tonistiigi/xx master digest was incompatible with Go 1.24:
xx-verify rejected linux/386 cross-compiled binaries.

Also aligns with the master Dockerfile which already uses ARG XX_VERSION.

Signed-off-by: Sopho Merkviladze <smerkviladze@mirantis.com>
Signed-off-by: Sopho Merkviladze <smerkviladze@mirantis.com>
js-yaml 5.0.0 changed yaml.load('') to throw instead of returning
undefined, breaking the unpinned install once the matrix step resolved
the new major. Pin to 4.3.0 (latest 4.x) to keep the prior behavior.

Signed-off-by: Sopho Merkviladze <smerkviladze@mirantis.com>
@smerkviladze
smerkviladze merged commit 6ee7c40 into Mirantis:v0.13.0-beta1-m.1 Jul 6, 2026
27 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants