Skip to content

Validate heap profile IDs in admin API - #52

Merged
tszymczyszyn-shopify merged 4 commits into
v0.9.30-shopify-patchesfrom
fix/heap-profile-id-validation
Oct 8, 2026
Merged

tszymczyszyn-shopify merged 4 commits into
v0.9.30-shopify-patchesfrom
fix/heap-profile-id-validation

Conversation

@tszymczyszyn-shopify

@tszymczyszyn-shopify tszymczyszyn-shopify commented Oct 8, 2026 •

Copy link
Copy Markdown

Why

Heap profile IDs are used to construct local paths by the disable and delete admin handlers. Treat the ID returned by Rheaper as an opaque basename rather than depending on Rheaper's private rip-<timestamp> naming convention.

What changed

  • centralize the heap-profile directory and ID-to-path conversion
  • require exactly one normal path component before any side effect; on disable, always stop tracking first, then fail explicitly if the profile directory is missing (so tracking can be stopped even with a lost ID or deleted directory, and a wrong ID never yields an empty archive)
  • reject empty, current/parent, slash, backslash, NUL, and colon forms consistently on every platform
  • return the existing InvalidPath response (400 Bad Request) for unsafe IDs
  • add unit coverage for current and future safe basenames plus traversal, absolute, nested, Windows-style, NUL, and drive-prefix inputs
  • add Axum-level coverage proving percent-encoded traversal is decoded and rejected by both routes

Test plan

  • cargo fmt --all -- --check
  • cargo check -p libsql-server --lib
  • cargo test -p libsql-server http::admin::tests --lib (5 passed, including a live enable→disable round trip)

The targeted test link required temporarily omitting the existing pcre2_internal.h compiler input on macOS; that unrelated workaround is not included in this change.

@tszymczyszyn-shopify
tszymczyszyn-shopify requested a review from a team October 8, 2026 10:25
Comment thread libsql-server/src/http/admin/mod.rs

@raphaelfeitoza raphaelfeitoza left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

@tszymczyszyn-shopify
tszymczyszyn-shopify merged commit 5e100d7 into v0.9.30-shopify-patches Oct 8, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants