Skip to content

fixing the "last arg is the input file" assumption - #17

Open
nzatsepina wants to merge 1 commit into
PaperCutSoftware:mainfrom
nzatsepina:fix/input-file-argument-parsing
Open

fixing the "last arg is the input file" assumption#17
nzatsepina wants to merge 1 commit into
PaperCutSoftware:mainfrom
nzatsepina:fix/input-file-argument-parsing

Conversation

@nzatsepina

Copy link
Copy Markdown

ExpandPathsInArgs() rewrote nargv[argc-1] to an absolute path, and ApplyPolicy() whitelisted that same token, whenever it did not begin with '-'. Every other file Ghostscript opens was therefore missing from the sandbox policy: multiple inputs, -ffile, and files given after --/-+/-@ were denied (exit 100, no output) although unsandboxed gsc.exe runs all of them. This is the case the TODO in the header and the FIXME beside the code already flag for -f.

ClassifyInputArgs() now walks the arguments the way psi/imainarg.c does and marks the tokens Ghostscript will open as files; those are made absolute and whitelisted. Four paths are deliberately not modelled, and are listed above the function. A token that does not exist relative to the working directory is left untouched, because Ghostscript may resolve it on its library search path.

This narrows the policy as well as widening it: the last argument is no longer whitelisted merely for being last, so an -o or -I operand sitting there loses a grant it used to receive by accident.

The -sOutputFile= rewrite in the same loop now range-checks GetFullPathName(): when the buffer is too small the documented return is the required size rather than the length written, so a bare "> 0" test read that failure as success.

Fixes #3.

ExpandPathsInArgs() rewrote nargv[argc-1] to an absolute path, and ApplyPolicy()
whitelisted that same token, whenever it did not begin with '-'. Every other file
Ghostscript opens was therefore missing from the sandbox policy: multiple inputs,
-ffile, and files given after --/-+/-@ were denied (exit 100, no output) although
unsandboxed gsc.exe runs all of them. This is the case the TODO in the header and
the FIXME beside the code already flag for -f.

ClassifyInputArgs() now walks the arguments the way psi/imainarg.c does and marks
the tokens Ghostscript will open as files; those are made absolute and
whitelisted. Four paths are deliberately not modelled, and are listed above the
function. A token that does not exist relative to the working directory is left
untouched, because Ghostscript may resolve it on its library search path.

This narrows the policy as well as widening it: the last argument is no longer
whitelisted merely for being last, so an -o or -I operand sitting there loses a
grant it used to receive by accident.

The -sOutputFile= rewrite in the same loop now range-checks GetFullPathName():
when the buffer is too small the documented return is the required size rather
than the length written, so a bare "> 0" test read that failure as success.

Fixes PaperCutSoftware#3.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Fix the "last arg is the input file" assumption

1 participant