已执行推荐修复,Coverity仍触发Java文件系统路径操作告警求助
Coverity文件路径/文件名/URI操作告警无法消除问题
即使执行了推荐的修复操作,Synopsis Coverity仍会触发Java代码中的Filesystem path、filename或URI manipulation告警。此前参考过两篇针对该问题的Stack Overflow解决方案,但这些方案并未彻底消除当前代码中的告警。
原触发告警的代码
public String deleteFiles(List<String> filesToDelete){ filesToDelete.forEach(file -> { logger.info("Deleting file " + file); Path path = Paths.get(file).normalize(); new File(path).delete(); }); }
已修复但仍触发告警的代码
private static boolean doesFilenameTryPatternTraversal(String filename) { return Pattern.compile("\\.\\.|\\|/").matcher(filename).find(); } private void deleteFiles(List<String> filesToDelete) { filesToDelete.forEach(file -> { logger.info("Deleting file {}", file); if (doesFilenameTryPatternTraversal(file)) { throw new RuntimeException( "filename: '" + file + "' attempting to access a file outside of expected directory."); } Path canonicalPath = basePath.resolve(Paths.get(file).toAbsolutePath().normalize()); if (canonicalPath.startsWith(basePath.toString())) { try { Files.delete(canonicalPath); } catch (IOException e) { throw new RuntimeException("Could not delete file '" + file + "'.", e); } } else { throw new SecurityException("File '" + file + "' is outside the allowed directory"); } }); }
内容的提问来源于stack exchange,提问作者Chris
相关产品推荐
相关产品推荐

