fix(host-core): ignore symbolic links during capability directory copy - #1194
Merged
Merged
Conversation
Prevent following symlinks outside the capability tree when importing or copying capability directories with copy_directory_tree. Previously, copy_directory_tree used path.is_dir() and fs::copy(&path, &target), which traverse symlinks via fs::metadata. This could allow an imported directory containing symlinks to follow external paths or enter cyclic directory loops. This change checks entry.file_type() directly, ignoring symlinks and copying only regular files and directories. Adds regression test in agent_capabilities/tests.rs.
Totopo27
force-pushed
the
fix/capability-copy-symlink-guard
branch
from
September 28, 2026 22:24
74f70ed to
2bb4af4
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Prevents following symbolic links when copying capability trees in
copy_directory_tree, aligning directory copying behavior with capability package export rules and plugin installation boundaries.Motivation & Root Cause
In
crates/host-core/src/agent_capabilities.rs,copy_directory_treepreviously traversed entries usingpath.is_dir()andfs::copy(&path, &target). BecausePath::is_dir()invokesfs::metadata()which follows symlinks, importing a capability directory containing symbolic links could traverse outside the capability tree or enter infinite recursion on cyclic symlinks.Other subsystems in host-core already reject or guard against symlinks in capability imports (
collect_package_filesinuser_skills.rs:520andcopy_dir_filteredinplugins/install.rs:552).Key Changes
crates/host-core/src/agent_capabilities.rs):entry.file_type()directly instead of following links withPath::is_dir().file_type.is_symlink()), traversing only regular directories and copying only regular files.crates/host-core/src/agent_capabilities/tests.rs):copy_directory_tree_ignores_symlinksverifying that both file symlinks and directory symlinks pointing outside the source tree are skipped without escaping.Verification
crates/host-core/src/agent_capabilities/tests.rs.fix:change addressing verified sandbox boundary).