svn commit: r1935013 - in httpd/httpd/branches/2.4.x: . modules/dav/fs

[email protected] Fri, 05 Jun 2026 10:13:46 -0000
Newsgroups gmane.comp.apache.cvs
Message-ID <178065442630.3071047.11970332804588166863@svn03-he-fi>
Author: covener
Date: Fri Jun  5 10:13:46 2026
New Revision: 1935013

Log:
Merge r1935009 from trunk:

dav_fs_get_resource: disallow DAV_FS_STATE_DIR


Submitted By: jorton
Reviewed By: jorton, covener, gbechis

Modified:
   httpd/httpd/branches/2.4.x/   (props changed)
   httpd/httpd/branches/2.4.x/modules/dav/fs/repos.c

Modified: httpd/httpd/branches/2.4.x/modules/dav/fs/repos.c
==============================================================================
--- httpd/httpd/branches/2.4.x/modules/dav/fs/repos.c	Fri Jun  5 10:10:26 2026	(r1935012)
+++ httpd/httpd/branches/2.4.x/modules/dav/fs/repos.c	Fri Jun  5 10:13:46 2026	(r1935013)
@@ -22,6 +22,7 @@
 #include "apr_file_io.h"
 #include "apr_strings.h"
 #include "apr_buckets.h"
+#include "apr_lib.h"
 
 #if APR_HAVE_UNISTD_H
 #include <unistd.h>             /* for getpid() */
@@ -673,8 +674,8 @@ static dav_error * dav_fs_get_resource(
 {
     dav_resource_private *ctx;
     dav_resource *resource;
-    char *s;
-    char *filename;
+    char *s, *parent;
+    const char *filename, *dirname;
     apr_size_t len;
 
     /* ### optimize this into a single allocation! */
@@ -708,6 +709,30 @@ static dav_error * dav_fs_get_resource(
     if (len > 1 && s[len - 1] == '/') {
         s[len - 1] = '\0';
     }
+
+    /* Deny any access to, or within, the state directory. */
+    filename = apr_filepath_name_get(s);
+    parent = ap_make_dirstr_parent(r->pool, s);
+    /* Strip the trailing slash and extract the leaf directory name. */
+    len = strlen(parent);
+    if (len > 1 && parent[len - 1] == '/') {
+        parent[len - 1] = '\0';
+    }
+    dirname = apr_filepath_name_get(parent);
+#ifdef CASE_BLIND_FILESYSTEM
+    if (ap_cstr_casecmp(filename, DAV_FS_STATE_DIR) == 0
+        || ap_cstr_casecmp(dirname, DAV_FS_STATE_DIR) == 0) {
+#else
+    if (strcmp(filename, DAV_FS_STATE_DIR) == 0
+        || strcmp(dirname, DAV_FS_STATE_DIR) == 0) {
+#endif
+        ap_log_rerror(APLOG_MARK, APLOG_ERR, 0, r,
+                      "access to " DAV_FS_STATE_DIR " state directory "
+                      "denied for %s", r->filename);
+        return dav_new_error(r->pool, HTTP_FORBIDDEN, 0, 0,
+                             "Access to the state directory denied.");
+    }
+
     ctx->pathname = s;
 
     /* Create resource descriptor */