N
Hacker Next
new
past
show
ask
show
jobs
submit
login
▲
My minimal, memory-safe Go rsync steers clear of vulnerabilities
(
michael.stapelberg.ch
)
9 points by
Brajeshwar
13 hours ago
|
3 comments
add comment
Rendered at 03:02:42 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
3eb7988a1663 11 hours ago
[-]
Is there a solid reference resource on handling symlinks? It seems a never ending source of security bugs.
euroderf 10 hours ago
[-]
The new os.Root is supposed to handle symlinks correctly in a sandbox, but (of course?) the first release had a bug related to symlinks.
d0vs 10 hours ago
[-]
Agreed. Not a direct answer but this should be interesting:
https://github.com/cyphar/filepath-securejoin