mirror of
https://github.com/Sea-Haven-Industries/front-integrations.git
synced 2026-09-30 10:43:13 +00:00
fix(terraform): reject symlink sources in Lambda package build
This commit is contained in:
parent
1ad265b177
commit
2b0b59b5a8
2 changed files with 37 additions and 4 deletions
|
|
@ -6,16 +6,47 @@ ROOT="$(cd "$(dirname "$0")" && pwd)"
|
|||
BUILD="${ROOT}/build"
|
||||
SRC="$(cd "${ROOT}/../src" && pwd)"
|
||||
|
||||
# Copy only regular files that resolve inside SRC (no symlink escape).
|
||||
copy_src_file() {
|
||||
local rel="$1"
|
||||
local dest="$2"
|
||||
local src_path="${SRC}/${rel}"
|
||||
|
||||
if [[ -L "${src_path}" ]]; then
|
||||
echo "error: refusing symlink source: ${src_path}" >&2
|
||||
exit 1
|
||||
fi
|
||||
if [[ ! -f "${src_path}" ]]; then
|
||||
echo "error: missing regular file: ${src_path}" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
local resolved
|
||||
resolved="$(cd "$(dirname "${src_path}")" && pwd)/$(basename "${src_path}")"
|
||||
case "${resolved}" in
|
||||
"${SRC}"/*) ;;
|
||||
*)
|
||||
echo "error: path escapes src tree: ${resolved}" >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
|
||||
mkdir -p "$(dirname "${dest}")"
|
||||
# -P: never follow symlinks if the destination path is replaced mid-run.
|
||||
cp -P "${src_path}" "${dest}"
|
||||
}
|
||||
|
||||
rm -rf "${BUILD}"
|
||||
mkdir -p "${BUILD}/sla_monitor" "${BUILD}/user_sync"
|
||||
|
||||
cp "${SRC}/sla_monitor/app.py" "${BUILD}/sla_monitor/app.py"
|
||||
copy_src_file "sla_monitor/app.py" "${BUILD}/sla_monitor/app.py"
|
||||
copy_src_file "user_sync/app.py" "${BUILD}/user_sync/app.py"
|
||||
copy_src_file "user_sync/requirements.txt" "${BUILD}/user_sync/requirements.txt"
|
||||
|
||||
cp "${SRC}/user_sync/app.py" "${BUILD}/user_sync/app.py"
|
||||
python3 -m pip install \
|
||||
--quiet \
|
||||
--disable-pip-version-check \
|
||||
-r "${SRC}/user_sync/requirements.txt" \
|
||||
-r "${BUILD}/user_sync/requirements.txt" \
|
||||
-t "${BUILD}/user_sync/" \
|
||||
--platform manylinux2014_aarch64 \
|
||||
--implementation cp \
|
||||
|
|
@ -27,3 +58,4 @@ python3 -m pip install \
|
|||
rm -rf "${BUILD}/user_sync/boto3" "${BUILD}/user_sync/botocore" \
|
||||
"${BUILD}/user_sync/s3transfer" "${BUILD}/user_sync/jmespath" \
|
||||
"${BUILD}/user_sync/"*.dist-info 2>/dev/null || true
|
||||
rm -f "${BUILD}/user_sync/requirements.txt"
|
||||
|
|
|
|||
|
|
@ -7,7 +7,8 @@ ROOT="$(cd "$(dirname "$0")" && pwd)"
|
|||
|
||||
hash="$(
|
||||
{
|
||||
find "${ROOT}/build/sla_monitor" "${ROOT}/build/user_sync" -type f -print0 2>/dev/null \
|
||||
# -P: do not follow symlinks; only hash regular files under build/.
|
||||
find -P "${ROOT}/build/sla_monitor" "${ROOT}/build/user_sync" -type f -print0 2>/dev/null \
|
||||
| sort -z \
|
||||
| xargs -0 sha256sum
|
||||
} | sha256sum | awk '{print $1}'
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue