Skip to content

Prevent validation report paths from overwriting compiler inputs #811

Description

@LunaStev

Problem

A report path can alias a Wave input or the selected compiler. Both runners write an initial JSON report before launching compilation. A mistaken --report-json can therefore destroy the source or compiler and make the subsequent checks operate on the replacement JSON.

Starting points: tools/check_case_sources.py, tools/run_runtime_cases.py.

Reproduction

Executed on Linux amd64 with Python 3.14.7. The affected files at local ade878134519b0f957ca28a23c6f9cd98e43dff3 are byte-identical to canonical master 286dad9c8fcb0616f7c719c72cbf453a7d9925fd.

This reproduction uses only a temporary source and a mocked compiler:

python3 -B - <<'PYREPRO'
import subprocess, sys, tempfile
from pathlib import Path
from unittest.mock import patch
from tools import check_case_sources as c
with tempfile.TemporaryDirectory() as tmp:
    root = Path(tmp)
    source = root / 'input.wave'
    source.write_text('fun main() {}\n')
    with patch.object(c, 'CASES_ROOT', root), patch.object(c, 'run_process',
            return_value=subprocess.CompletedProcess([], 0, '', '')):
        c.check_sources(sys.executable, ['input.wave'], source)
    print('source replaced with JSON:', source.read_text().startswith('{'))
PYREPRO

Observed: source replaced with JSON: True. The same write-before-input-validation ordering in run_runtime_cases.execute was confirmed by source inspection, not a separate destructive CLI run.

Scope

Moderate: validate report/input aliases before the first report write, covering selected sources and compiler executables in both runners. Include normalized paths and filesystem aliases. Related compiler-output protection in #745 does not protect these Python report writers.

Completion criteria

  • Reject report paths aliasing any selected source or compiler before changing any file.
  • Cover identical paths, normalized equivalents, symlinks and hard links where supported.
  • Preserve original bytes and return a clear failure even when the requested report destination cannot safely be used.
  • Normal report creation and replacement still work.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugA problem that causes incorrect behavior or crashes.help wantedThe issue requires extra attention or help from others.needs testingIssues that require additional testing or verification.

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions