Symlinks in the marketplace cache are checked component by component and refused if they escape.
What's wrong with this entry?
Paths in the marketplace cache are now checked one component at a time before any read or write. A link whose chain points at a network path is refused, a link pointing outside its own marketplace directory is refused, and directory listings skip links they cannot judge.
- The check runs first on reads and on copy, move, write, truncate, chmod, delete, stat and digest.
- Active only when the v5 storage backend is in use.
a link that leaves its marketplace tree is never followed
Strings lifted out of the shipped bundle, so the claim above can be checked against them.