bootstrap.ps1's Resolve-Directory checks that -Dir is fully qualified and not a drive root, and passes the text on otherwise unchanged. Two forms it should refuse still get through:
- A path that is not canonical, such as
C:\x\.., which names the drive root while passing the drive-root check, since that check matches the literal text ^[A-Za-z]:$ after trimming separators.
- A UNC share root, such as
\server\share, the network equivalent of a drive root, which the same check does not recognize.
Everything the loader creates and removes sits under -Dir, so each of these lets it work at the top of a volume the drive-root refusal exists to keep it out of. The ownership marker still stops it removing a tree it did not create, which bounds the damage to its own fixed names.
- Fix direction: canonicalize with
[IO.Path]::GetFullPath before the drive-root check, and refuse where the result equals [IO.Path]::GetPathRoot of itself, which covers both a drive root and a share root. host-setup/menu.ps1's own directory check already canonicalizes this way, so the two can share one shape.
Pre-existing. Found by the local strict review of the #1791 change, which tightened the same function's absolute-path check.
bootstrap.ps1'sResolve-Directorychecks that-Diris fully qualified and not a drive root, and passes the text on otherwise unchanged. Two forms it should refuse still get through:C:\x\.., which names the drive root while passing the drive-root check, since that check matches the literal text^[A-Za-z]:$after trimming separators.\server\share, the network equivalent of a drive root, which the same check does not recognize.Everything the loader creates and removes sits under
-Dir, so each of these lets it work at the top of a volume the drive-root refusal exists to keep it out of. The ownership marker still stops it removing a tree it did not create, which bounds the damage to its own fixed names.[IO.Path]::GetFullPathbefore the drive-root check, and refuse where the result equals[IO.Path]::GetPathRootof itself, which covers both a drive root and a share root.host-setup/menu.ps1's own directory check already canonicalizes this way, so the two can share one shape.Pre-existing. Found by the local strict review of the #1791 change, which tightened the same function's absolute-path check.