[pseudo][PATCH 10/11] pseudo_util.c: Fix symlink processing for symlinkat and related

Mark Hatle <[email protected]>
Newsgroups org.yoctoproject.lists.yocto-patches
Message-ID <[email protected]>
From: Mark Hatle <[email protected]>

If the symlink is absolute (starts with a '/') we need to ensure that
it is still presented as if it was inside of the chroot.  This was
discovered by the openat2 chroot test case, but only when looking at
a symlink and helped indicate that symlinkat (and similar) users
were affected.

AI-Generated: Fixed by github copilot (claude opus 4.6)

Signed-off-by: Mark Hatle <[email protected]>
Signed-off-by: Mark Hatle <[email protected]>
---
 pseudo_util.c | 14 ++++++++++++++
 1 file changed, 14 insertions(+)

diff --git a/pseudo_util.c b/pseudo_util.c
index 3a06027..2b0cc04 100644
--- a/pseudo_util.c
+++ b/pseudo_util.c
@@ -729,7 +729,21 @@ pseudo_append_element(char *newpath, char *root, size_t allocated, char **pcurre
 			linkbuf[linklen] = '\0';
 			/* absolute symlink means go back to root */
 			if (*linkbuf == '/') {
+				size_t rootlen = root - newpath;
 				current = root;
+				/* If we're in a chroot (rootlen > 0) and the
+				 * symlink target starts with the chroot prefix,
+				 * strip it.  This happens when symlinkat expanded
+				 * an absolute target to include the chroot path
+				 * on disk; without stripping, we'd double-apply
+				 * the chroot prefix during resolution.
+				 */
+				if (rootlen > 0 && (size_t)linklen > rootlen &&
+				    !memcmp(linkbuf, newpath, rootlen) &&
+				    (linkbuf[rootlen] == '/' || linkbuf[rootlen] == '\0')) {
+					memmove(linkbuf, linkbuf + rootlen, linklen - rootlen + 1);
+					linklen -= rootlen;
+				}
 			} else {
 #ifdef PSEUDO_PORT_LINUX
 				if (is_proc) {
-- 
1.8.3.1
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.