Skip to content

Sync streaming_globber with Go standard library filepath.Glob - #9

Merged
torsm merged 1 commit into
google:masterfrom
torsm:sync-stdlib
Oct 1, 2026
Merged

torsm merged 1 commit into
google:masterfrom
torsm:sync-stdlib

Conversation

@torsm

@torsm torsm commented Aug 19, 2026

Copy link
Copy Markdown
Collaborator

Bring streaming_globber in sync with Go stdlib filepath.Glob updates:

  • Add early pattern validation via filepath.Match(pattern, "") before initiating directory traversal.
  • Add streamWithLimit with depth parameter and pathSeparatorsLimit = 10000 to guard against stack exhaustion on deeply nested directories (CVE-2022-30632).
  • Add TestCVE202230632.

References:

Bring streaming_globber in sync with Go stdlib filepath.Glob updates:
- Add early pattern validation via filepath.Match(pattern, "") before
  initiating directory traversal.
- Add streamWithLimit with depth parameter and pathSeparatorsLimit = 10000
  to guard against stack exhaustion on deeply nested directories (CVE-2022-30632).
- Add TestCVE202230632.

References:
- CVE-2022-30632
- Go commit: golang/go@ac68c6c
- Go CL: https://go.dev/cl/417066
- Go issue: golang/go#53416
@bjackman

Copy link
Copy Markdown
Contributor

Hey Torben I can't remember if I was still the owner of this repository when I left Google, but if I was I lost control of this repo when I left, so someone else will need to merge this.

@gnoack

gnoack commented Aug 19, 2026

Copy link
Copy Markdown
Collaborator

Oh hello Brendan 👋

We all three lost control :) we'll get it back somehow by escalating to the right people :)

@torsm

torsm commented Aug 20, 2026 •

Copy link
Copy Markdown
Collaborator Author

Hi there :)
Yes i'm already on the case. The repo actually automatically got archived due to inactivity which might have been responsible for the loss of access.

@torsm
torsm merged commit f910c72 into google:master Oct 1, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants