From c9e5c77eb9a20d7012ee972727f250f3a2fb95cc Mon Sep 17 00:00:00 2001 From: Gabriel Schneider Date: Thu, 1 Oct 2026 06:28:40 -0300 Subject: /pager resolves its directory, `~` and `..` alike, and refuses one that may not be written, permission denied; `pardes -` from such a directory pages into the session's `/tmp/../etc` named a +Pager `/tmp/../etc/+Pager`, a second one beside `/etc/+Pager`, and `~/x` was refused as relative. The directory is now home-expanded and resolved before it is checked, and one that may not be written is refused as a file's name there is (fs.deniedAbove). `pardes -` run in such a directory (`git log` under /usr/src) asks for the session's +Pager instead, so its text is still paged. Co-Authored-By: Claude Opus 5.5 --- src/main.zig | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) (limited to 'src/main.zig') diff --git a/src/main.zig b/src/main.zig index 86558bae..99e94889 100644 --- a/src/main.zig +++ b/src/main.zig @@ -121,9 +121,11 @@ fn pageInto(io: std.Io, gpa: std.mem.Allocator, dial: []const u8, text: []const // of a ctl (a newline, a control byte): then the session's. var cwd_buf: [4096]u8 = undefined; const cwd: []const u8 = if (std.c.getcwd(&cwd_buf, cwd_buf.len)) |c| std.mem.span(@as([*:0]u8, @ptrCast(c))) else ""; + // ...or the session's when this one may not be written (`git log` in + // /usr/src), which /pager refuses: the text is paged all the same. const plain = for (cwd) |c| { if (c < ' ' or c == 0x7f) break false; - } else true; + } else !pardes.filesystem.deniedAbove(cwd); var line_buf: [4200]u8 = undefined; const dir_line = std.fmt.bufPrint(&line_buf, "{s}\n", .{if (plain) cwd else ""}) catch "\n"; // Its serial read back on the open that asked: another client's exec -- cgit v1.3