Skip to content

fix(edge): accept case-variant paths in upgrade destination checks - #406

Closed
Dragonzz27 wants to merge 2 commits into
ongridio:mainfrom
Dragonzz27:niu/fix-windows-path-validation
Closed

Dragonzz27 wants to merge 2 commits into
ongridio:mainfrom
Dragonzz27:niu/fix-windows-path-validation

Conversation

@Dragonzz27

@Dragonzz27 Dragonzz27 commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

Summary

同一个受管目录仅改变路径大小写时,ensureWithinDir 的根目录相等判断会将其误判为越界,导致合法 Windows 升级目标被拒绝。根目录相等判断改用 strings.EqualFold,与已有的子目录比较语义保持一致;符号链接解析、父目录和兄弟目录边界检查保持有效。

  • 增加根目录/目标大小写变体、子目录、父目录及兄弟目录前缀的回归用例。
  • 仅跳过依赖大小写不敏感文件系统的子测试,让 Linux 继续执行其余 Dest 白名单检查;Windows 上缺少预期文件系统能力会直接失败。
  • 通过 Makefile 统一 Windows 构建、vet、测试编译和原生执行入口。交叉编译清单新增 supervisor、upgrademachine、upgradebundle、supervisorhealth。
  • 增加 windows-latest 原生 -race 测试任务,支持手动触发,并将 Makefile 和 Go 依赖变动纳入工作流触发范围。

Fixes #359

Validation

  • 在 macOS 大小写不敏感文件系统上,修复前的大小写 Dest 用例及两个根目录大小写变体稳定失败;修复后路径白名单、大小写、父目录/兄弟目录及 symlink 检查通过。
  • Linux:三个升级相关包的 go test -race 通过。
  • make check-windows-cross 通过:Windows 入口构建、vet 和全部八项包/包模式的测试编译。
  • actionlint v1.7.12 检查修改的工作流通过。
  • make build 通过(Manager / Edge)。
  • make test-race:129 个包通过,2 个包受本地环境影响失败(root 容器下权限拒绝测试、DNS 返回测试域名的地址)。两项均已在未修改的基线 292ac98 上复现,相关代码未修改。
  • Fork 验证运行 全部通过:windows-latest 原生 -race 测试和 ubuntu-24.04 Windows 构建/vet/测试编译。验证提交 84f9524 与本 PR 的 afcc1e9 仅差临时验证分支的 push 触发条件,测试代码一致。

Rebase 说明(2026-10-07)

已 rebase 到当前 main(3affaf9)。Makefile 的冲突按「保留主干新增的 target,再追加本 PR 的 Windows target」解决,相对 main 是纯 +21 行插入,未回退主干任何改动。

拆成两个提交,方便分别取舍:

  1. fix(edge): accept case-variant paths in upgrade destination checks —— 只含 ensureWithinDir 的 1 行修复与回归测试(validate.go + validate_test.go)。
  2. test(edge): cover Windows packages in cross-build and native CI —— 只含 Makefile 与 ci-windows-cross.yml;test(edge/windows): 补齐 NTFS 路径大小写校验与原生 CI #359 要求的「原生 CI」部分在这里。

如果只想先收安全修复,第一个提交可以独立成立;第二个提交可以拆走后续再提。

2026-10-07 重新验证(Go 1.27.1 / macOS,文件系统大小写不敏感):

  • 把本 PR 的测试单独打在未修复的 main 上:TestValidateEntry_DestWhitelist/大小写变体合法 与 TestEnsureWithinDir_CaseInsensitivePaths 的两个根目录大小写变体用例共 3 项稳定失败,报错为把同源大小写变体路径判成 escapes managed root。
  • 加上 validate.go 那 1 行 EqualFold 后:go test -race ./internal/edgeagent/upgrademachine/ 通过,go vet 干净。
  • make check-windows-cross 在本机通过(Windows 入口 build + vet + 8 项包/包模式的测试二进制编译,覆盖到 upgrademachine)。
  • windows-latest 原生 job 本机无法执行(无 Windows 主机),依赖上面记录的 fork 实测与本 PR 的 CI 结果。

Rollback

无 API、数据库或配置格式变更;回滚此 PR 可恢复原路径判断及 Windows CI 配置。第一个提交可单独 revert。

Author confirmation

@Dragonzz27
Dragonzz27 force-pushed the niu/fix-windows-path-validation branch from afcc1e9 to eb1d676 Compare October 6, 2026 17:52
@Dragonzz27 Dragonzz27 changed the title fix(edge): 修正路径大小写校验并补齐 Windows 原生测试 fix(edge): accept case-variant paths in upgrade destination checks Oct 6, 2026
ensureWithinDir compared the canonical path against the managed root with ==,
while the sibling-prefix branch below it already used strings.EqualFold for
NTFS case-insensitive semantics. A path that names the managed root with a
different case matched neither branch and was rejected as an escape, so a
valid upgrade destination could fail on Windows.

Align the equality branch with EqualFold. On a case-sensitive filesystem both
canonical values derive from the same source and already agree in case, so the
change is a no-op there.

Adds TestEnsureWithinDir_CaseInsensitivePaths, and moves the case-variant
coverage out of the whole-test skip guard into requireCaseInsensitiveDir so
the remaining whitelist and escape cases still run on Linux.
The cross-build job compiled only four edgeagent subpackages plus the entry
binaries, so a Windows test file that stopped compiling or stopped vetting was
not caught before a native run, and nothing executed the supervisor,
upgrademachine, upgradebundle or supervisorhealth race tests on Windows.

Move the package lists into the Makefile as check-windows-cross (build, vet
and compile the Windows test binaries on Linux) and test-windows-native (the
actual -race run on a Windows host), then have ci-windows-cross.yml call them
and add a windows-latest job. Trigger the workflow on Makefile and
go.mod/go.sum changes as well, and allow workflow_dispatch.
@Dragonzz27
Dragonzz27 force-pushed the niu/fix-windows-path-validation branch from eb1d676 to 152d0d4 Compare October 8, 2026 10:38
@Dragonzz27 Dragonzz27 closed this Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

test(edge/windows): 补齐 NTFS 路径大小写校验与原生 CI

1 participant