| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Sorry, something went wrong.
There was a problem hiding this comment.
This PR hardens the Python FileSystemAgentFileStore containment boundary on Windows by treating NTFS directory junctions (and other reparse points) as link-like entries during listing and recursive search, preventing enumeration from escaping the configured root.
Changes:
Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| python/packages/core/agent_framework/_harness/_file_access.py | Adds unified link/reparse detection and applies it consistently to validation, listing, and recursive search enumeration. |
| python/packages/core/tests/core/test_harness_file_access.py | Adds a Windows junction regression test and updates the fail-closed probe test to patch Path.lstat. |
Sorry, something went wrong.
|
@microsoft-github-policy-service agree |
Sorry, something went wrong.
Python Test Coverage Report •
Python Unit Test Overview
|
||||||||||||||||||||||||||||||
Sorry, something went wrong.
|
Thanks Eduard and Westey. |
Sorry, something went wrong.
| Back | FazBrowse Home | New Git URL |
Motivation & Context
FileSystemAgentFileStore promises root-scoped access and rejects linked or reparse paths during direct operations, but its directory listing and recursive search paths only checked Path.is_symlink(). On Windows, directory junctions are reparse points that do not report as symlinks, so file_access_grep could descend outside the configured root.
Description & Review Guide
Related Issue
Fixes #7290
Contribution Checklist