Repository navigation
fix(edge): accept case-variant paths in upgrade destination checks - #406
Closed
Dragonzz27 wants to merge 2 commits into
Closed
Dragonzz27 wants to merge 2 commits into
Dragonzz27 wants to merge 2 commits into
Conversation
Dragonzz27
force-pushed
the
niu/fix-windows-path-validation
branch
from
October 6, 2026 17:52
afcc1e9 to
eb1d676
Compare
ensureWithinDir compared the canonical path against the managed root with ==, while the sibling-prefix branch below it already used strings.EqualFold for NTFS case-insensitive semantics. A path that names the managed root with a different case matched neither branch and was rejected as an escape, so a valid upgrade destination could fail on Windows. Align the equality branch with EqualFold. On a case-sensitive filesystem both canonical values derive from the same source and already agree in case, so the change is a no-op there. Adds TestEnsureWithinDir_CaseInsensitivePaths, and moves the case-variant coverage out of the whole-test skip guard into requireCaseInsensitiveDir so the remaining whitelist and escape cases still run on Linux.
The cross-build job compiled only four edgeagent subpackages plus the entry binaries, so a Windows test file that stopped compiling or stopped vetting was not caught before a native run, and nothing executed the supervisor, upgrademachine, upgradebundle or supervisorhealth race tests on Windows. Move the package lists into the Makefile as check-windows-cross (build, vet and compile the Windows test binaries on Linux) and test-windows-native (the actual -race run on a Windows host), then have ci-windows-cross.yml call them and add a windows-latest job. Trigger the workflow on Makefile and go.mod/go.sum changes as well, and allow workflow_dispatch.
Dragonzz27
force-pushed
the
niu/fix-windows-path-validation
branch
from
October 8, 2026 10:38
eb1d676 to
152d0d4
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
同一个受管目录仅改变路径大小写时,
ensureWithinDir的根目录相等判断会将其误判为越界,导致合法 Windows 升级目标被拒绝。根目录相等判断改用strings.EqualFold,与已有的子目录比较语义保持一致;符号链接解析、父目录和兄弟目录边界检查保持有效。windows-latest原生-race测试任务,支持手动触发,并将 Makefile 和 Go 依赖变动纳入工作流触发范围。Fixes #359
Validation
go test -race通过。make check-windows-cross通过:Windows 入口构建、vet 和全部八项包/包模式的测试编译。actionlint v1.7.12检查修改的工作流通过。make build通过(Manager / Edge)。make test-race:129 个包通过,2 个包受本地环境影响失败(root 容器下权限拒绝测试、DNS 返回测试域名的地址)。两项均已在未修改的基线292ac98上复现,相关代码未修改。windows-latest原生-race测试和ubuntu-24.04Windows 构建/vet/测试编译。验证提交84f9524与本 PR 的afcc1e9仅差临时验证分支的 push 触发条件,测试代码一致。Rebase 说明(2026-10-07)
已 rebase 到当前 main(
3affaf9)。Makefile 的冲突按「保留主干新增的 target,再追加本 PR 的 Windows target」解决,相对 main 是纯 +21 行插入,未回退主干任何改动。拆成两个提交,方便分别取舍:
fix(edge): accept case-variant paths in upgrade destination checks—— 只含ensureWithinDir的 1 行修复与回归测试(validate.go+validate_test.go)。test(edge): cover Windows packages in cross-build and native CI—— 只含Makefile与ci-windows-cross.yml;test(edge/windows): 补齐 NTFS 路径大小写校验与原生 CI #359 要求的「原生 CI」部分在这里。如果只想先收安全修复,第一个提交可以独立成立;第二个提交可以拆走后续再提。
2026-10-07 重新验证(Go 1.27.1 / macOS,文件系统大小写不敏感):
TestValidateEntry_DestWhitelist/大小写变体合法与TestEnsureWithinDir_CaseInsensitivePaths的两个根目录大小写变体用例共 3 项稳定失败,报错为把同源大小写变体路径判成escapes managed root。validate.go那 1 行EqualFold后:go test -race ./internal/edgeagent/upgrademachine/通过,go vet干净。make check-windows-cross在本机通过(Windows 入口 build + vet + 8 项包/包模式的测试二进制编译,覆盖到upgrademachine)。windows-latest原生 job 本机无法执行(无 Windows 主机),依赖上面记录的 fork 实测与本 PR 的 CI 结果。Rollback
无 API、数据库或配置格式变更;回滚此 PR 可恢复原路径判断及 Windows CI 配置。第一个提交可单独 revert。
Author confirmation