Skip to content

fix: refuse home dir when base path has a trailing separator - #890

Merged
dmtrKovalenko merged 1 commit into
dmtrKovalenko:mainfrom
mikeschlottig:fix/home-guard-trailing-separator
Sep 27, 2026
Merged

dmtrKovalenko merged 1 commit into
dmtrKovalenko:mainfrom
mikeschlottig:fix/home-guard-trailing-separator

Conversation

@mikeschlottig

@mikeschlottig mikeschlottig commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Root cause

The home-directory guard in FilePicker::new (crates/fff-core/src/file_picker.rs:897-898) compares raw OsStr bytes:

Some(path.as_os_str()) == dirs::home_dir().as_ref().map(|p| p.as_os_str())

"/home/u/" and "/home/u" are different byte strings, so a base path with a trailing separator passes the guard.

fff-mcp produces exactly that path whenever $HOME is itself a git repository. Git root discovery returns the root with a trailing slash, so starting the server with cwd = $HOME and no --enable-home-scan indexes the whole home directory:

INFO main fff_mcp: Discovered git root: /home/mikes/
INFO main fff_search::file_picker: Spawning background threads: base_path=/home/mikes/, warmup=true, content_indexing=true, mode=Ai
... SCAN: Walk completed in 5.384089904s (804634 files, 106809 dirs, ...)

(fff-mcp 0.11.0 / 95fd777, Linux x86_64 musl.)

Fix

Compare as Path instead. Path equality is component-wise and ignores the trailing separator:

if !options.enable_home_dir_scanning && dirs::home_dir().is_some_and(|home| path == home) {

The watcher's own guard (watcher/background_watcher.rs:68) already compares PathBufs, so it was not affected.

Test

refuses_home_dir_with_trailing_separator builds a FilePicker (no walk, no watcher) at $HOME and at $HOME/, and asserts Err(Error::FilesystemRoot(_)) for both.

  • Before the fix: FAILED ... home dir accepted as /home/mikes/
  • After the fix: ok; cargo test -p fff-search --lib → 194 passed, 0 failed
  • cargo fmt --check is clean, and clippy reports no new warnings (28 before and after, none in file_picker.rs)

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes
    • File browsing now correctly rejects equivalent home-directory paths when home-directory scanning is disabled.

The home-directory guard compared raw OsStr bytes against dirs::home_dir(),
so "/home/u/" slipped past a check written for "/home/u". fff-mcp hits this
whenever $HOME is itself a git repository: git root discovery returns the
root with a trailing slash, the guard never fires, and the whole home
directory is indexed without --enable-home-scan.

Compare as Path instead, which is component-wise and ignores the trailing
separator. Adds a regression test that fails on the old comparison.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your trial has ended. Reactivate Greptile to resume code reviews.

@coderabbitai

coderabbitai Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Advanced

Run ID: d60d4e00-dd28-48d2-adf3-11ed1f5edeed

📥 Commits

Reviewing files that changed from the base of the PR and between e5dcced and 660bbf6.

📒 Files selected for processing (1)
  • crates/fff-core/src/file_picker.rs

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review.


📝 Walkthrough

Walkthrough

The home-directory guard now compares Path values. A test checks that FilePicker::new rejects the home path and home.join("") when home-directory scanning is disabled.

Changes

Home path guard

Layer / File(s) Summary
Path comparison and rejection test
crates/fff-core/src/file_picker.rs
The guard compares Path values. The test checks that both the home path and home.join("") return Error::FilesystemRoot when home-directory scanning is disabled.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Suggested reviewers: dmtrkovalenko

Merge Risk: ⚪ Minimal · up to 660bb

The home-directory guard now handles the reported trailing-separator path. No actionable merge risk remains.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 660bb

The change strengthens the default refusal of home-directory scans for paths with trailing separators. No new exposure was identified, but behavior for filesystem aliases remains unverified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — A base path accepted by the constructor can reach the filesystem walk and produce searchable file records. Refusing equivalent home paths therefore narrows the unintended scan path described by the PR.

Trust Boundaries and Controls

  • inferred — The guard compares lexical paths rather than filesystem identity. A symlink alias would not match at this check, but downstream traversal through such an alias was not verified; this is not shown to be introduced by the PR.

Hardening Proposals

  • proposed — If the restriction is intended to cover filesystem aliases, verify alias traversal in both walker backends and consider a filesystem-identity check with explicit failure and race handling.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately states the main change: reject the home directory when the base path includes a trailing separator.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 2 functions across 1 files.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@dmtrKovalenko
dmtrKovalenko merged commit 27d4930 into dmtrKovalenko:main Sep 27, 2026
53 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants