aboutsummaryrefslogtreecommitdiffstats
path: root/packages
diff options
context:
space:
mode:
Diffstat (limited to 'packages')
-rw-r--r--packages/meshbay-client/src/main.js19
-rw-r--r--packages/meshbay-common/src/meshbay_common/paths.py8
-rw-r--r--packages/meshbay-common/tests/test_paths.py7
-rw-r--r--packages/meshbay-common/tests/test_portable_name_parity.py1
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/static/portable-name.js7
-rw-r--r--packages/meshbay-hub/tests/test_desktop_shell.py23
-rw-r--r--packages/meshbay-node/src/meshbay_node/roots.py15
-rw-r--r--packages/meshbay-node/src/meshbay_node/transport/webrtc/upload_handlers.py12
-rw-r--r--packages/meshbay-node/tests/test_partial_uploads.py21
9 files changed, 108 insertions, 5 deletions
diff --git a/packages/meshbay-client/src/main.js b/packages/meshbay-client/src/main.js
index 236a285..52ca168 100644
--- a/packages/meshbay-client/src/main.js
+++ b/packages/meshbay-client/src/main.js
@@ -1160,8 +1160,24 @@ function registerBridge() {
return { path: chosen, name: path.basename(chosen) };
});
+ // The Mark-of-the-Web, as a browser leaves on every download: the file came
+ // from somebody else's machine, and Windows decides what that means —
+ // SmartScreen for a program, Protected View for a document. This application
+ // writes its files itself, so nothing else marks them. NTFS only; elsewhere
+ // there is no such stream, and nothing is lost by not having one.
+ function markFromInternet(file) {
+ if (process.platform !== 'win32') return;
+ try {
+ fs.writeFileSync(`${file}:Zone.Identifier`, '[ZoneTransfer]\r\nZoneId=3\r\n');
+ } catch { /* FAT, exFAT, a network share: no alternate data streams */ }
+ }
+
handle('save:begin', async (_e, suggestedName, opts) => {
- const wanted = path.basename(String(suggestedName || 'download'));
+ // Bidirectional controls replaced here as well as in the page
+ // (portable-name.js): "invoice\u202efdp.exe" would be saved, and listed by
+ // the file manager, as "invoiceexe.pdf".
+ const wanted = path.basename(String(suggestedName || 'download'))
+ .replace(/[\u061c\u200e\u200f\u202a-\u202e\u2066-\u2069]/g, '_');
const chosen = chosenDownloadDir();
let target = null;
@@ -1231,6 +1247,7 @@ function registerBridge() {
console.error('[MeshBay] could not finalise download:', err.message);
return false;
}
+ markFromInternet(sink.path);
completedPaths.set(String(id), sink.path);
return true;
});
diff --git a/packages/meshbay-common/src/meshbay_common/paths.py b/packages/meshbay-common/src/meshbay_common/paths.py
index b673649..8be4680 100644
--- a/packages/meshbay-common/src/meshbay_common/paths.py
+++ b/packages/meshbay-common/src/meshbay_common/paths.py
@@ -30,8 +30,12 @@ WINDOWS_RESERVED = frozenset({
*(f"LPT{i}" for i in range(1, 10)),
})
-# Reserved on Windows; `/` is reserved everywhere. Control characters go too.
-_RESERVED_CHARS = set('<>:"/\\|?*') | {chr(c) for c in range(32)}
+# Reserved on Windows; `/` is reserved everywhere. Control characters go too,
+# and so do the bidirectional controls: "invoice\u202efdp.exe" displays as
+# "invoiceexe.pdf", and a saved name must say what the file is.
+BIDI_CONTROLS = frozenset("\u061c\u200e\u200f\u202a\u202b\u202c\u202d\u202e"
+ "\u2066\u2067\u2068\u2069")
+_RESERVED_CHARS = set('<>:"/\\|?*') | {chr(c) for c in range(32)} | BIDI_CONTROLS
# Windows without long-path support. A deep media library reaches this.
MAX_PATH_WINDOWS = 260
diff --git a/packages/meshbay-common/tests/test_paths.py b/packages/meshbay-common/tests/test_paths.py
index 223a2a6..012a32e 100644
--- a/packages/meshbay-common/tests/test_paths.py
+++ b/packages/meshbay-common/tests/test_paths.py
@@ -119,3 +119,10 @@ def test_sanitizing_produces_something_writable():
def test_sanitizing_never_returns_nothing():
assert sanitize_for_download("...") not in ("", None)
assert sanitize_for_download("???") not in ("", None)
+
+
+def test_a_bidi_override_cannot_hide_an_extension():
+ from meshbay_common.paths import portable_name_problem, sanitize_for_download
+ disguised = "invoice‮fdp.exe" # displays as "invoiceexe.pdf"
+ assert sanitize_for_download(disguised) == "invoice_fdp.exe"
+ assert portable_name_problem(disguised)
diff --git a/packages/meshbay-common/tests/test_portable_name_parity.py b/packages/meshbay-common/tests/test_portable_name_parity.py
index 3a491a7..d7df710 100644
--- a/packages/meshbay-common/tests/test_portable_name_parity.py
+++ b/packages/meshbay-common/tests/test_portable_name_parity.py
@@ -26,6 +26,7 @@ pytestmark = pytest.mark.skipif(
)
NAMES = [
+ "invoice\u202efdp.exe", "a\u2066b\u2069.txt", "mark\u200f.txt",
"plain.txt", "Réunion 12:30.pdf", 'a<b>c:d"e/f\\g|h?i*j.txt', "tab\tnew\nline",
"ends with dot.", "ends with space ", "trailing . . ", "CON", "con.txt", "aux.tar.gz",
"COM1", "com10.txt", "LPT9.log", "nul.", ".", "..", "", " ", ".bashrc", "...",
diff --git a/packages/meshbay-hub/src/meshbay_hub/static/portable-name.js b/packages/meshbay-hub/src/meshbay_hub/static/portable-name.js
index bb2438c..34085ae 100644
--- a/packages/meshbay-hub/src/meshbay_hub/static/portable-name.js
+++ b/packages/meshbay-hub/src/meshbay_hub/static/portable-name.js
@@ -20,8 +20,13 @@ const WINDOWS_RESERVED = new Set([
]);
const RESERVED_CHARS = new Set('<>:"/\\|?*');
+// The bidirectional controls: "invoice\u202efdp.exe" displays as
+// "invoiceexe.pdf", and a saved name must say what the file is.
+const BIDI_CONTROLS = new Set('\u061c\u200e\u200f\u202a\u202b\u202c\u202d\u202e'
+ + '\u2066\u2067\u2068\u2069');
-const reserved = (c) => RESERVED_CHARS.has(c) || c.charCodeAt(0) < 32;
+const reserved = (c) => RESERVED_CHARS.has(c) || BIDI_CONTROLS.has(c)
+ || c.charCodeAt(0) < 32;
function isPortable(name) {
if (!name || name === '.' || name === '..') return false;
diff --git a/packages/meshbay-hub/tests/test_desktop_shell.py b/packages/meshbay-hub/tests/test_desktop_shell.py
index 4426dd7..60aa32f 100644
--- a/packages/meshbay-hub/tests/test_desktop_shell.py
+++ b/packages/meshbay-hub/tests/test_desktop_shell.py
@@ -701,3 +701,26 @@ def test_an_account_made_in_the_application_starts_without_browser_access():
assert "platform.keys.createdHere(reg.userId)" in register
assert "userId" in (STATIC / "keyderive.js").read_text(encoding="utf-8").split(
"async function registerUser", 1)[1].split("\n}\n", 1)[0]
+
+
+def _handler(name: str) -> str:
+ source = _main()
+ start = source.index(f"handle('{name}'")
+ return source[start:source.index("\n });", start)]
+
+
+def test_a_finished_download_carries_the_mark_of_the_web():
+ """What a browser leaves on every download, so Windows applies SmartScreen
+ and Protected View. Only checkable here by reading: the stream exists on
+ NTFS alone, and this suite does not run on Windows."""
+ assert "markFromInternet(sink.path)" in _handler("save:end")
+ source = _main()
+ mark = source[source.index("function markFromInternet"):]
+ mark = mark[:mark.index("\n }\n")]
+ assert "Zone.Identifier" in mark and "ZoneId=3" in mark
+ assert "process.platform !== 'win32'" in mark
+
+
+def test_a_saved_name_cannot_hide_its_extension():
+ begin = _handler("save:begin")
+ assert "\\u202a-\\u202e" in begin and "\\u2066-\\u2069" in begin
diff --git a/packages/meshbay-node/src/meshbay_node/roots.py b/packages/meshbay-node/src/meshbay_node/roots.py
index a4f9cc9..2de0708 100644
--- a/packages/meshbay-node/src/meshbay_node/roots.py
+++ b/packages/meshbay-node/src/meshbay_node/roots.py
@@ -53,6 +53,21 @@ SAFE_UPLOAD_NAME = re.compile(
re.UNICODE)
+# Files Windows Explorer acts on by itself when it shows a folder: a link's
+# icon, a folder's settings, a search connector. Placed by a member in a folder
+# the operator browses, any of them can make Explorer contact a server of the
+# member's choosing with the operator's Windows credentials — a known attack,
+# and why mail providers refuse the same types. Refused for every node: a
+# Linux node's folder may be shared to Windows machines.
+SHELL_ACTIVE_NAMES = frozenset({"desktop.ini"})
+SHELL_ACTIVE_SUFFIXES = (".lnk", ".url", ".scf", ".library-ms", ".searchconnector-ms")
+
+
+def shell_active(filename: str) -> bool:
+ name = filename.lower()
+ return name in SHELL_ACTIVE_NAMES or name.endswith(SHELL_ACTIVE_SUFFIXES)
+
+
def _free_name(directory: Path, filename: str,
taken: frozenset[str] | set[str] = frozenset()) -> str:
"""
diff --git a/packages/meshbay-node/src/meshbay_node/transport/webrtc/upload_handlers.py b/packages/meshbay-node/src/meshbay_node/transport/webrtc/upload_handlers.py
index f1ed139..02a50af 100644
--- a/packages/meshbay-node/src/meshbay_node/transport/webrtc/upload_handlers.py
+++ b/packages/meshbay-node/src/meshbay_node/transport/webrtc/upload_handlers.py
@@ -8,7 +8,14 @@ from pathlib import Path
from meshbay_common.protocol import UPLOAD_PROBE_INDEX, file_upload_ack_wire, file_upload_payload
from meshbay_node import uploads as uploads_mod
-from meshbay_node.roots import SAFE_UPLOAD_NAME, RootSet, _free_name, off_disk, publish_upload
+from meshbay_node.roots import (
+ SAFE_UPLOAD_NAME,
+ RootSet,
+ _free_name,
+ off_disk,
+ publish_upload,
+ shell_active,
+)
from meshbay_node.transport.webrtc.disk import _append_chunk
from meshbay_node.transport.webrtc.limits import LEASE_NONE, LEASE_QUEUED
@@ -212,6 +219,9 @@ class UploadMixin:
if not SAFE_UPLOAD_NAME.match(filename):
_refuse("Invalid filename", "invalid_filename")
return
+ if shell_active(filename):
+ _refuse("This type of file is not accepted", "file_type_refused")
+ return
roots: RootSet | None = ctx.get("roots")
if not roots:
diff --git a/packages/meshbay-node/tests/test_partial_uploads.py b/packages/meshbay-node/tests/test_partial_uploads.py
index 138ee3b..556b26a 100644
--- a/packages/meshbay-node/tests/test_partial_uploads.py
+++ b/packages/meshbay-node/tests/test_partial_uploads.py
@@ -22,6 +22,7 @@ import time
import types
from pathlib import Path
+import pytest
from cryptography.hazmat.primitives.asymmetric.ed25519 import Ed25519PrivateKey
from meshbay_common.crypto import generate_gek
from meshbay_common.protocol import (
@@ -552,3 +553,23 @@ def test_without_hard_links_a_file_is_still_not_replaced(tmp_path, monkeypatch):
assert (tmp_path / "a.txt").read_bytes() == b"there first"
assert (tmp_path / "a (2).txt").read_bytes() == b"uploaded"
assert not part.exists()
+
+
+# ── files Explorer acts on by itself ─────────────────────────────────────────
+
+
+@pytest.mark.parametrize("name", ["desktop.ini", "Desktop.INI", "photos.lnk", "site.url",
+ "x.scf", "Docs.library-ms", "s.searchConnector-ms"])
+async def test_a_file_explorer_acts_on_is_refused(tmp_path, name):
+ ctx = _group_ctx(tmp_path)
+ peer = _peer(ctx)
+ await peer._do_file_upload(sealed_upload(peer, filename=name, data=b"[x]"))
+ assert [m.get("code") for m in _errors(peer)] == ["file_type_refused"]
+ assert not any(ctx["roots"].roots[0].path.iterdir())
+
+
+async def test_an_ordinary_file_with_a_near_name_is_accepted(tmp_path):
+ ctx = _group_ctx(tmp_path)
+ peer = _peer(ctx)
+ await peer._do_file_upload(sealed_upload(peer, filename="url-notes.txt", data=b"x"))
+ assert _errors(peer) == []