Skip to content

fix(host-core): ignore symbolic links during capability directory copy - #1194

Merged
vastsa merged 1 commit into
vastsa:mainfrom
Totopo27:fix/capability-copy-symlink-guard
Sep 28, 2026
Merged

vastsa merged 1 commit into
vastsa:mainfrom
Totopo27:fix/capability-copy-symlink-guard

Conversation

@Totopo27

Copy link
Copy Markdown
Contributor

Summary

Prevents following symbolic links when copying capability trees in copy_directory_tree, aligning directory copying behavior with capability package export rules and plugin installation boundaries.

Motivation & Root Cause

In crates/host-core/src/agent_capabilities.rs, copy_directory_tree previously traversed entries using path.is_dir() and fs::copy(&path, &target). Because Path::is_dir() invokes fs::metadata() which follows symlinks, importing a capability directory containing symbolic links could traverse outside the capability tree or enter infinite recursion on cyclic symlinks.

Other subsystems in host-core already reject or guard against symlinks in capability imports (collect_package_files in user_skills.rs:520 and copy_dir_filtered in plugins/install.rs:552).

Key Changes

  • Capability Directory Copy (crates/host-core/src/agent_capabilities.rs):
    • Read entry.file_type() directly instead of following links with Path::is_dir().
    • Safely ignore symbolic links (file_type.is_symlink()), traversing only regular directories and copying only regular files.
  • Regression Testing (crates/host-core/src/agent_capabilities/tests.rs):
    • Added unit test copy_directory_tree_ignores_symlinks verifying that both file symlinks and directory symlinks pointing outside the source tree are skipped without escaping.

Verification

  • Unit test added in crates/host-core/src/agent_capabilities/tests.rs.
  • Strict compliance with R6.1 (fix: change addressing verified sandbox boundary).

Prevent following symlinks outside the capability tree when importing or copying capability directories with copy_directory_tree.

Previously, copy_directory_tree used path.is_dir() and fs::copy(&path, &target), which traverse symlinks via fs::metadata. This could allow an imported directory containing symlinks to follow external paths or enter cyclic directory loops.

This change checks entry.file_type() directly, ignoring symlinks and copying only regular files and directories. Adds regression test in agent_capabilities/tests.rs.
@Totopo27
Totopo27 force-pushed the fix/capability-copy-symlink-guard branch from 74f70ed to 2bb4af4 Compare September 28, 2026 22:24
@vastsa
vastsa merged commit 1cf0335 into vastsa:main Sep 28, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants