Skip to content

A remote cache entry's input paths can point outside the workspace #768

Description

@wan9chi

A cache entry lists the files the task read, as paths relative to the workspace, and vp run checks those files before it uses the entry. For entries from the remote cache, those paths aren't limited to the workspace: an entry can list paths that climb out of it with ...

A corrupted or malicious remote entry can therefore make vp run read and hash any file the user can read, anywhere on the machine, or hang while reading an endless file such as /dev/zero. When several people or CI jobs can write to the same remote cache, any one of them can affect everyone else's runs this way.

It isn't known yet whether normally created entries ever record inputs outside the workspace, which matters for deciding what to reject.

Expected: entries from the remote cache only make vp run read files inside the workspace.

Affects remote cache reads (#756).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Fields

    Priority

    None yet

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions