Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions .jules/sentinel.md
Original file line number Diff line number Diff line change
Expand Up @@ -88,3 +88,8 @@
**Vulnerability:** CSP ํ•ด์‹œ ๋ถˆ์ผ์น˜๋กœ ์ธํ•œ ์ธ๋ผ์ธ ์Šคํƒ€์ผ ์ฐจ๋‹จ
**Learning:** ๋ธŒ๋ผ์šฐ์ €๋Š” ์ธ๋ผ์ธ ์Šคํฌ๋ฆฝํŠธ์™€ ์Šคํƒ€์ผ์˜ ๋‚ด๋ถ€ ํ…์ŠคํŠธ(๊ณต๋ฐฑ๊ณผ ์ค„๋ฐ”๊ฟˆ ํฌํ•จ)๋ฅผ ์ •ํ™•ํ•˜๊ฒŒ ํ•ด์‹ฑํ•˜์—ฌ Content-Security-Policy(CSP) ํ•ด์‹œ์™€ ๋น„๊ตํ•ฉ๋‹ˆ๋‹ค. Kotlin์˜ ๋ฉ€ํ‹ฐ๋ผ์ธ ๋ฌธ์ž์—ด(`"""`)์„ ์‚ฌ์šฉํ•˜์—ฌ ํ…œํ”Œ๋ฆฟ์— ์ฝ˜ํ…์ธ ๋ฅผ ์ฃผ์ž…ํ•  ๋•Œ ์•”๋ฌต์ ์ธ ์—ฌ๋ฐฑ์ด๋‚˜ ์ค„๋ฐ”๊ฟˆ์ด ์ถ”๊ฐ€๋˜๋ฉด ์ตœ์ข… HTML ๋ฌธ์ž์—ด์ด ๋ณ€๊ฒฝ๋˜์–ด CSP ํ•ด์‹œ๊ฐ€ ๋ฌดํšจํ™”๋ฉ๋‹ˆ๋‹ค.
**Prevention:** ์ฝ˜ํ…์ธ ๋ฅผ ํ•ด์‹ฑํ•˜๊ธฐ ์ „์— `.trimIndent()`๋ฅผ ์ ์šฉํ•˜์—ฌ ์›๋ณธ ๋ฌธ์ž์—ด์„ ์ •๊ทœํ™”ํ•˜๊ณ , HTML ํ…œํ”Œ๋ฆฟ์— ์ฃผ์ž…ํ•  ๋•Œ `<style>${exactContent}</style>`์™€ ๊ฐ™์ด ๊ณต๋ฐฑ ์—†์ด ์ฃผ์ž…ํ•˜์—ฌ ํ•ด์‹œ๊ฐ€ ์™„๋ฒฝํ•˜๊ฒŒ ์ผ์น˜ํ•˜๋„๋ก ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

## 2024-08-09 - [html4tree] ์›์ž์  ํŒŒ์ผ ์ด๋™(Atomic Move)์„ ํ†ตํ•œ ์ž„์‹œ ํŒŒ์ผ ๋ฎ์–ด์“ฐ๊ธฐ TOCTOU ๋ณด์•ˆ ํ–ฅ์ƒ
**Vulnerability:** ํŒŒ์ผ ์‹œ์Šคํ…œ ์ƒ์„ฑ๊ณผ ๊ต์ฒด ์‚ฌ์ด์— ๋ฐœ์ƒํ•˜๋Š” Time-of-Check to Time-of-Use (TOCTOU) ์ทจ์•ฝ์ .
**Learning:** `write_index_file`์€ ์ž„์‹œ ํŒŒ์ผ์„ ์ƒ์„ฑํ•˜๊ณ  ๋ชฉํ‘œ ๊ฒฝ๋กœ(`index.html`)๋กœ ์ด๋™์‹œํ‚ค๋Š”๋ฐ, ๋‹จ์ˆœํžˆ `StandardCopyOption.REPLACE_EXISTING`๋งŒ ์‚ฌ์šฉํ•  ๊ฒฝ์šฐ ๋‹ค๋ฅธ ํ”„๋กœ์„ธ์Šค๊ฐ€ ๊ทธ ์ฐฐ๋‚˜์˜ ์ˆœ๊ฐ„์— ๋Œ€์ƒ ํŒŒ์ผ์„ ๋ณ€๊ฒฝํ•˜๊ฑฐ๋‚˜ ์‹ฌ๋ณผ๋ฆญ ๋งํฌ๋กœ ๋ฐ”๊ฟ”์น˜๊ธฐํ•  ์ˆ˜ ์žˆ๋Š” ๊ฒฝํ•ฉ ์กฐ๊ฑด(Race Condition)์ด ์กด์žฌํ•ฉ๋‹ˆ๋‹ค.
**Prevention:** ํŒŒ์ผ ๋ฎ์–ด์“ฐ๊ธฐ ์ž‘์—… ์‹œ `StandardCopyOption.ATOMIC_MOVE` ์˜ต์…˜์„ ๋ช…์‹œ์ ์œผ๋กœ ์‚ฌ์šฉํ•˜์—ฌ ํŒŒ์ผ ์ด๋™ ์—ฐ์‚ฐ์ด ์›์ž์ (atomic)์œผ๋กœ ์ด๋ฃจ์–ด์ง€๋„๋ก ๋ณด์žฅํ•˜๊ณ , ํŒŒ์ผ ์‹œ์Šคํ…œ์—์„œ ํ•ด๋‹น ์˜ต์…˜์„ ์ง€์›ํ•˜์ง€ ์•Š์„ ์ˆ˜ ์žˆ์œผ๋ฏ€๋กœ `AtomicMoveNotSupportedException`์„ `try-catch` ๋ธ”๋ก์œผ๋กœ ์•ˆ์ „ํ•˜๊ฒŒ ํด๋ฐฑ(Fallback) ์ฒ˜๋ฆฌํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.
14 changes: 12 additions & 2 deletions src/main/kotlin/html4tree/main.kt
Original file line number Diff line number Diff line change
Expand Up @@ -327,12 +327,22 @@ fun process_ignore_file(curr_dir: File, dirFilesNames: Array<String>? = null): S
return files_to_exclude
}

fun write_index_file(curr_dir: File, content: String) {
fun write_index_file(
curr_dir: File,
content: String,
moveFile: (java.nio.file.Path, java.nio.file.Path) -> Unit = { source, target ->
Files.move(source, target, StandardCopyOption.REPLACE_EXISTING, StandardCopyOption.ATOMIC_MOVE)
}
) {
val indexPath = curr_dir.toPath().resolve("index.html")
val tempPath = Files.createTempFile(curr_dir.toPath(), ".index-", ".html")
try {
Files.write(tempPath, content.toByteArray(Charsets.UTF_8))
Files.move(tempPath, indexPath, StandardCopyOption.REPLACE_EXISTING)
try {
moveFile(tempPath, indexPath)
} catch (e: java.nio.file.AtomicMoveNotSupportedException) {
Files.move(tempPath, indexPath, StandardCopyOption.REPLACE_EXISTING)
}
} finally {
Files.deleteIfExists(tempPath)
}
Expand Down
23 changes: 23 additions & 0 deletions src/test/kotlin/html4tree/MainTest.kt
Original file line number Diff line number Diff line change
Expand Up @@ -376,6 +376,29 @@ class MainTest {
assertTrue(leftoverTemp.isEmpty(), "temporary index file should be cleaned up on failure")
}

@Test
fun testWriteIndexFileHandlesAtomicMoveNotSupported() {
val content = "atomic fallback content"
write_index_file(tempDir, content) { source, target ->
throw java.nio.file.AtomicMoveNotSupportedException(source.toString(), target.toString(), "Mocked atomic move failure")
}
val indexPath = File(tempDir, "index.html")
assertTrue(indexPath.exists())
assertEquals(content, indexPath.readText())
}

@Test
fun testWriteIndexFileAtomicMoveSuccessFallback() {
val content = "atomic move success content"
// This simulates a successful atomic move when no exception is thrown
write_index_file(tempDir, content) { source, target ->
Files.move(source, target, java.nio.file.StandardCopyOption.REPLACE_EXISTING)
}
val indexPath = File(tempDir, "index.html")
assertTrue(indexPath.exists())
assertEquals(content, indexPath.readText())
}

@Test
fun testProcessDirReplacesIndexSymlinkWithoutTouchingTarget() {
val targetFile = File(tempDir, "target.txt")
Expand Down
Loading