Skip to content

Canonicalize -Dir in bootstrap.ps1 Before Refusing a Drive or Share Root #2495

Description

@ptr727

bootstrap.ps1's Resolve-Directory checks that -Dir is fully qualified and not a drive root, and passes the text on otherwise unchanged. Two forms it should refuse still get through:

  • A path that is not canonical, such as C:\x\.., which names the drive root while passing the drive-root check, since that check matches the literal text ^[A-Za-z]:$ after trimming separators.
  • A UNC share root, such as \server\share, the network equivalent of a drive root, which the same check does not recognize.

Everything the loader creates and removes sits under -Dir, so each of these lets it work at the top of a volume the drive-root refusal exists to keep it out of. The ownership marker still stops it removing a tree it did not create, which bounds the damage to its own fixed names.

  • Fix direction: canonicalize with [IO.Path]::GetFullPath before the drive-root check, and refuse where the result equals [IO.Path]::GetPathRoot of itself, which covers both a drive root and a share root. host-setup/menu.ps1's own directory check already canonicalizes this way, so the two can share one shape.

Pre-existing. Found by the local strict review of the #1791 change, which tightened the same function's absolute-path check.

Activity

  1. added
    bugSomething isn't working
    pre-existingReview finding classed pre-existing per local-strict-review Disposing of Findings
    scriptA defect in hub tooling
    on Oct 7, 2026
  2. ptr727 commented on Oct 8, 2026

    @ptr727
    OwnerAuthor

    Declined per #2517, approved by the maintainer, under GOVERNANCE.md "Trust Boundaries and Hardening Effort": -Dir is a command-line argument the maintainer types, which is trusted input, a non-canonical root is not a realistic typo, and the ownership marker bounds the damage to the loader's own names.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingpre-existingReview finding classed pre-existing per local-strict-review Disposing of FindingsscriptA defect in hub tooling

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions