Expand description
Building the file list on the sender, and validating it on the receiver.
The receiver treats every path in a manifest as hostile input. A transfer is a remote peer writing to your filesystem; path handling is the part that turns that from a feature into a vulnerability.
Structs§
- Manifest
- A manifest paired with the local paths each entry reads from.
- Source
- What to send: a file, or a directory sent recursively.
Functions§
- build
- Walk
sourcesand build the manifest. - safe_
join - Resolve a manifest path against
root, refusing anything that would land outside it. - split_
symlink - Split the symlink encoding back into
(path, target). - validate
- Check a received manifest for internal consistency before acting on it.