Skip to content

fix(cache): keep cache entry inputs inside the workspace - #769

Draft
wan9chi wants to merge 1 commit into
mainfrom
fix-cache-input-paths
Draft

wan9chi wants to merge 1 commit into
mainfrom
fix-cache-input-paths

Conversation

@wan9chi

@wan9chi wan9chi commented Sep 27, 2026

Copy link
Copy Markdown
Member

Motivation

A cache entry lists the files its task read, and vp run reads those files again to check the entry. Paths in a remote cache entry could climb out of the workspace with ... A corrupted or malicious entry could then make vp run read any file the user can read, or hang on a file like /dev/zero.

Changes

  • Automatic input tracking already ignored files outside the workspace that a task opened by absolute path. When a task reached the same files through .. (for example cat ../file on macOS and Linux), it recorded them as ../file. Those paths are now ignored too. Normally created entries never have inputs with ... A task that writes a file through .. is now cached instead of failing with paths in archives must not have ...
  • Checking an entry fails before any input is read if an inferred input has a .. component. For a remote entry, this is a read failure and a miss. The reason is remote cache entry couldn't be validated, with the cause input '../file' can point outside the workspace. Every .. is rejected, not just a leading one, because a .. after a symlink can leave the workspace even when the path looks like it stays inside.
  • The cache schema version goes from 18 to 19. Entries that earlier versions recorded locally with .. inputs are left behind instead of failing lookups.
  • vt_path adds RelativePath::has_parent_dir_component.

Globbed inputs are only compared with the current glob results and are never read, so they aren't checked.

Closes #768

Automatic input tracking dropped files outside the workspace when a task
used their absolute path, but kept them when it reached them through
`..`, recording paths such as `../outside.txt`. Those paths are now
dropped too, which also stops such writes from failing the cache update.

Validation now rejects an entry with an inferred input that has a `..`
component before reading any input, so a remote cache entry can't make
`vp run` read files outside the workspace. The cache schema version is
bumped so local entries recorded with such inputs aren't rejected as
errors.

Closes #768

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
@wan9chi
wan9chi force-pushed the fix-cache-input-paths branch from 36d565e to a480b20 Compare September 27, 2026 16:40
@github-actions

Copy link
Copy Markdown

fspy benchmark

linux

dynamic/launch             change  -0.46%  [ -7.96% ..  +9.02%]  overhead  +259.97%
dynamic/access             change  +0.29%  [ -0.94% ..  +1.39%]  overhead   +14.02%
dynamic/access-relative    change  +0.22%  [ -1.14% ..  +1.68%]  overhead   +59.95%
dynamic/access-contended   change  -0.01%  [ -1.25% ..  +1.71%]  overhead   +15.20%
static/launch              change  +0.46%  [ -5.64% ..  +6.90%]  overhead  +736.51%
static/access              change  +0.13%  [ -0.87% ..  +1.23%]  overhead  +815.07%
static/access-relative     change  +0.34%  [ -0.56% ..  +1.19%]  overhead +1388.62%
static/access-contended    change  +0.28%  [ -0.47% ..  +1.00%]  overhead +3161.18%

macos

dynamic/launch             change  +0.02%  [ -2.75% ..  +2.66%]  overhead  +209.63%
dynamic/access             change  -0.70%  [ -2.76% ..  +2.77%]  overhead    -0.69%
dynamic/access-relative    change  -0.11%  [ -2.57% ..  +2.52%]  overhead  +221.15%
dynamic/access-contended   change  +0.39%  [ -3.50% ..  +6.56%]  overhead    +4.20%

windows

dynamic/launch             change  -0.33%  [ -5.64% ..  +4.69%]  overhead   +24.89%
dynamic/access             change  +0.35%  [ -5.72% ..  +5.71%]  overhead    +1.26%
dynamic/access-relative    change  -1.05%  [-15.79% ..  +6.37%]  overhead    +2.17%
dynamic/access-contended   change  -0.42%  [ -4.77% ..  +4.58%]  overhead    +2.83%

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

A remote cache entry's input paths can point outside the workspace

1 participant