Conversation
📝 WalkthroughRelease Notes - ADFA-2590: Fix unzip hygieneSecurity Improvements
Changes Made
Risk ConsiderationsWalkthroughThis PR enhances security in the DynamicLibraryLoader.kt by adding path traversal prevention during Llama AAR unzipping. It validates and normalizes ZipEntry paths, computes absolute normalized destinations, and uses Path-based validation to ensure extracted files remain within the intended directory. Changes
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~20 minutes Possibly related PRs
Suggested reviewers
Poem
🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing touches
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Improve Path Validation
Add Entry Name Sanitization
Align with Existing Patterns