fix: harden copy/move/delete transfers, add CI, dead code cleanup
All checks were successful
CI / test (push) Successful in 10m0s

Audited every copy/move/delete path (local, remote same-host, cross-host)
and fixed:

- Shell command injection in same-host remote cp/mv (unescaped paths
  interpolated into exec strings); added remote.ShellQuote.
- Missing guard against copying/moving a directory into its own
  subdirectory, locally and on same-host remote transfers (unbounded
  recursion / disk fill). New regression tests in ops_test.go.
- Remote-to-remote same-path file copy silently truncating the source
  file via Create() before it finished being read.
- Overwrite warning ("N existing target(s)") never shown for remote
  destinations, only local ones.
- Remote same-host server-side cp never advancing the file-done counter
  (waited on -v output that was never requested).
- Removed a dead "plan-then-confirm" subsystem (5 functions, 2 message
  types, 2 unreachable Update() cases) superseded by the current design.
- Remote delete (SFTP) now runs as a cancellable job with the same
  progress modal as local delete, instead of a single blocking call.

Also add a CI workflow that runs build/vet/test on every push and PR,
since previously they only ran on release tags.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
vrubelroman 2026-07-03 20:36:00 +00:00
parent c15ade247a
commit 135f5e0d19
5 changed files with 268 additions and 321 deletions

View file

@ -8,6 +8,7 @@ import (
"io/fs"
"os"
"path/filepath"
"strings"
"syscall"
"time"
@ -67,6 +68,13 @@ func CopyPathWithProgressContext(ctx context.Context, srcPath string, dstDir str
} else if same {
return "", fmt.Errorf("source and target are the same: %s", targetPath)
}
if srcInfo.IsDir() {
if within, err := pathWithin(targetPath, srcPath); err != nil {
return "", err
} else if within {
return "", fmt.Errorf("cannot copy %q into itself", srcPath)
}
}
if exists, err := PathExists(targetPath); err != nil {
return "", err
@ -189,6 +197,13 @@ func MovePathWithProgressContext(ctx context.Context, srcPath string, dstDir str
} else if same {
return "", fmt.Errorf("source and target are the same: %s", targetPath)
}
if srcInfo, statErr := os.Lstat(srcPath); statErr == nil && srcInfo.IsDir() {
if within, err := pathWithin(targetPath, srcPath); err != nil {
return "", err
} else if within {
return "", fmt.Errorf("cannot move %q into itself", srcPath)
}
}
if exists, err := PathExists(targetPath); err != nil {
return "", err
@ -527,3 +542,22 @@ func samePath(left string, right string) (bool, error) {
}
return leftAbs == rightAbs, nil
}
// pathWithin reports whether child is parent itself or a path nested inside
// it. Used to reject copying/moving a directory into one of its own
// descendants, which would otherwise make copyDir recurse into the very
// destination it's writing, growing without bound until the disk fills.
func pathWithin(child, parent string) (bool, error) {
childAbs, err := filepath.Abs(child)
if err != nil {
return false, err
}
parentAbs, err := filepath.Abs(parent)
if err != nil {
return false, err
}
if childAbs == parentAbs {
return true, nil
}
return strings.HasPrefix(childAbs, parentAbs+string(filepath.Separator)), nil
}