The trouble with symbolic links
The trouble with symbolic links
Posted Jul 7, 2022 22:39 UTC (Thu) by khim (subscriber, #9252)In reply to: The trouble with symbolic links by jthill
Parent article: The trouble with symbolic links
> Is the concept of user input utterly broken because little bobby tables is such a hellraiser?
The concept of injecting user input into a string is utterly broken, yes. That's why we have entirely different API which solves that issue once and for all. We don't have anything similar for pathnames.
> Besides, open and fstat the path's final directoryHave you actually read the article? Even finding the path's final directory is quite non-trivial.
> Instead of blackholing symlinks a quick little library to implement the operations in terms of those safety checks seems reasonableMake one. Give it to Jeremy and we can make a bet about how many ways it's broken.
