Prevent unwanted path traversal in file writes from buildtools. (#1491)

* Prevent unwanted path traversal in file writes from buildtools.

Buildtools previously allowed file writes through arbitrary symlinks, which could result in unintended path traversal outside of the Bazel workspace.

Use safeopen.WriteFileBeneath to ensure file writes remain confined within the Bazel workspace root. Add the -disable_symlink_safety flag to both buildifier and buildozer to allow opting out of this restriction when modifying files targeted via external symlinks.

New Behavior:
- Without flag (default): both tools refused to write and exited with error (invalid cross-device link).
- With -disable_symlink_safety: both tools successfully formatted/edited the target file.

* Fixing MODULE.bazel

* Disabling Symlink safety for windows

* Only check symlink safety on Linux for now

* Also OS-gating buildozer test

---------

Co-authored-by: Tim Malmström <oreflow@google.com>
19 files changed
tree: 0a190fe45844347118daf4c9e1794aa54a681c64
  1. .bazelci/
  2. .github/
  3. api_proto/
  4. build/
  5. build_proto/
  6. buildifier/
  7. buildozer/
  8. bzlenv/
  9. config/
  10. convertast/
  11. deps_proto/
  12. differ/
  13. edit/
  14. extra_actions_base_proto/
  15. file/
  16. generatetables/
  17. labels/
  18. lang/
  19. release/
  20. tables/
  21. testutils/
  22. unused_deps/
  23. warn/
  24. wspace/
  25. .bazelrc
  26. .bazelversion
  27. .gitignore
  28. .mailmap
  29. .pre-commit-config.yaml
  30. BUILD.bazel
  31. CODEOWNERS
  32. CONTRIBUTING.md
  33. CONTRIBUTORS
  34. go.mod
  35. go.sum
  36. launcher.js
  37. LICENSE
  38. MODULE.bazel
  39. README.md
  40. status.py
  41. update_generated.sh
  42. WARNINGS.md
  43. WORKSPACE
  44. WORKSPACE.bzlmod
README.md

Buildtools for bazel

This repository contains developer tools for working with Google's bazel buildtool.

Build status

Setup

See instructions in each tool's directory.