Skip to content

fix(cli): reject unsafe plugin archive links#1043

Merged
shiyiyue1102 merged 1 commit into
agentscope-ai:mainfrom
RerankerGuo:fix/plugin-tar-link-traversal
Jul 17, 2026
Merged

fix(cli): reject unsafe plugin archive links#1043
shiyiyue1102 merged 1 commit into
agentscope-ai:mainfrom
RerankerGuo:fix/plugin-tar-link-traversal

Conversation

@RerankerGuo

Copy link
Copy Markdown
Contributor

Summary

  • reject symbolic links, hard links, and special-file members before extracting plugin tarballs
  • add a CLI regression that attempts a real symlink-based write outside the extraction directory

Root cause

_safe_extract_tar validated every member path before calling extractall, but a link member can change how a later, otherwise valid member path resolves during extraction. A crafted plugin package could therefore write outside the temporary extraction directory.

The plugin package contract only needs regular files and directories, so rejecting all other member types closes this path without changing normal TeamHarness packages.

Validation

@shiyiyue1102 shiyiyue1102 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. The extraction guard now rejects symlinks, hard links, and special-file members before tar extraction, and the regression test covers the symlink escape path. The scoped required check is green.

@shiyiyue1102
shiyiyue1102 merged commit 688ec36 into agentscope-ai:main Jul 17, 2026
1 check passed
nattiini45 added a commit to nattiini45/AgentTeams that referenced this pull request Jul 23, 2026
* fix: align AgentTeams runtime naming defaults (agentscope-ai#1041)

* fix: prepare beta release workflow (agentscope-ai#1054)

* fix: harden beta release gates (agentscope-ai#1056)

* fix(cli): reject unsafe plugin archive links (agentscope-ai#1043)

* fix(scripts): redact complete Matrix events (agentscope-ai#1047)

* fix(migrate): analyze current cron job format (agentscope-ai#1049)

* fix(migrate): print runnable ZIP import command (agentscope-ai#1048)

* fix(replay): capture immediate manager replies (agentscope-ai#1045)

* fix(hack): persist containerized skopeo auth (agentscope-ai#1050)

* chore: archive changelog for v1.2.0-beta.1 (agentscope-ai#1058)

Co-authored-by: shiyiyue1102 <20452676+shiyiyue1102@users.noreply.github.com>

* fix(copaw): route Team Leader assignments to Team Room (agentscope-ai#1060)

* fix(install): user can specify which docker.sock to mount when run install script (agentscope-ai#553)

* docs: clarify Element homeserver port (agentscope-ai#978)

Co-authored-by: Ziyang Guo <121015044+RunMarshal@users.noreply.github.com>

* docs: clarify Higress AI route matching (agentscope-ai#980)

Co-authored-by: Ziyang Guo <121015044+RunMarshal@users.noreply.github.com>

* docs: clarify OpenAI-compatible provider setup (agentscope-ai#1013)

* refactor: complete AgentTeams runtime rename (agentscope-ai#1063)

* refactor: complete the AgentTeams hard-cut rename (agentscope-ai#1065)

* docs: add v1.2.0-beta.1 release news (agentscope-ai#1066)

* feat(sync): restore fork-only product trees on agentteams paths

Replay dashboard Helm templates under helm/agentteams, dashboard values and
helpers, qwenpaw worker image defaults, and path-adapted remediation-gates
(agentteams-controller / helm/agentteams). Root dashboard/, shared/python/,
openwiki/, and Gastown skills already survived the merge baseline.

Co-authored-by: Cursor <cursoragent@cursor.com>

* feat(controller): port fork Project CRD, health, APIs, and status CLI

Replay fork-only agentteams-controller features onto the upstream rename
baseline: Project CRD/reconciler/Helm, health monitor, message and
manager-tasks APIs, worker health probes, managerstate CLI, enhanced agt
status overview, SoloOperator/QwenPaw/docker resource wiring, and related
tests.

Co-authored-by: Cursor <cursoragent@cursor.com>

* feat(runtimes): restore quiet-rooms and Higress extra-provider prefix strip

Keep upstream CoPaw Team Leader DM-to-Team-Room routing while replaying
fork AGENTTEAMS_QUIET_ROOMS bridge/channel wiring. Restore OPT-IN
AGENTTEAMS_EXTRA_LLM_PROVIDERS setup with modelMapping prefix strip in
setup-higress.sh (route names agentteams-*-route).

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs(sync): truth-up migration doc, merge changelog, agt naming sweep

Rewrite upstream-integration-migration.md for rename acceptance + fork
overlay DoD (drop dual-CRD/HICLAW_* claims). Merge changelog entries from
both sides. Point pre-commit and openwiki paths at agentteams-controller /
helm/agentteams. Align agent-facing CLI examples to agt.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(qwenpaw): resolve Windows file:// agent package refs

urlparse puts file://C:\path entirely in netloc with an empty path; Path('') became cwd and silently copied the repo instead of the package archive.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(ci): purge brand leftovers and restore fork runtime bridge/sync

Clear remaining retired-brand strings/paths so helm-lint rename gate passes, restore CoPaw fork bridge/worker APIs and Hermes thin sync semantics, and harden installer prompt helpers with printf -v.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(copaw): restore Matrix channel APIs and thin sync wrapper

Bring back fork Matrix channel behavior needed by worker tests, switch sync back to the agentteams_sync wrapper, and share filesync helpers via _toolhelpers.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(sync): restore agentteams- bucket prefix stripping for team storage

The rename pass incorrectly shortened the hiclaw- bucket prefix check to agt-, breaking team path derivation for agentteams-* buckets.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(security): remediate Kilo review findings on sync/upstream-main

Harden appservice token compare, proxy body limits, lifecycle error logging,
Helm image/RBAC/CRD alignment, OpenHuman TOML escaping, and storage alias safety.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(helm): avoid retired brand in storage.bucket comment

Rename gate rejects hiclaw tokens even in comments; keep migration note brand-free.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: shiyiyue1102 <zunfei.lzf@alibaba-inc.com>
Co-authored-by: Ziyang Guo <121015044+RerankerGuo@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: shiyiyue1102 <20452676+shiyiyue1102@users.noreply.github.com>
Co-authored-by: Daniel Qian <chanjarster@gmail.com>
Co-authored-by: Ziyang Guo <121015044+RunMarshal@users.noreply.github.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants