[vlc-commits] [Git][videolan/vlc][master] skins2: preserve URI metacharacters in archive paths

François Cartegnie (@fcartegnie) gitlab at videolan.org
Mon Sep 21 11:37:01 UTC 2026



François Cartegnie pushed to branch master at VideoLAN / VLC


Commits:
9e74dc22 by Thomas Guillem at 2026-09-21T12:46:14+02:00
skins2: preserve URI metacharacters in archive paths

Percent-encode each archive path component before URI resolution so
valid question-mark and number-sign characters remain filename data
while retaining the traversal containment check.

Reject backslashes on OS/2 as well, where they are path separators.

refs #29929

- - - - -


1 changed file:

- modules/gui/skins2/src/theme_loader.cpp


Changes:

=====================================
modules/gui/skins2/src/theme_loader.cpp
=====================================
@@ -229,11 +229,7 @@ bool ThemeLoader::unarchive( const std::string& fileName, const std::string &tem
                 return false;
             }
 
-            /* avoid bypassing uri resolve with query */
-            if( strchr( child->psz_name, '?' ) || strchr( child->psz_name, '#' ) )
-                return false;
-
-#if defined( _WIN32 )
+#if defined( _WIN32 ) || defined( __OS2__ )
             if( strchr( child->psz_name, '\\' ) )
                 return false;
 #endif
@@ -246,11 +242,23 @@ bool ThemeLoader::unarchive( const std::string& fileName, const std::string &tem
             if( base_uri.empty() || base_uri.back() != '/' )
                 base_uri += '/';
 
-            auto ref = make_cstr_ptr( vlc_uri_fixup( child->psz_name ) );
-            if( !ref )
-                return false;
+            /* URI metacharacters in member names are filename data. */
+            std::string ref;
+            for( const char *component = child->psz_name; *component; )
+            {
+                size_t len = strcspn( component, "/" );
+                auto encoded = make_cstr_ptr( vlc_uri_encode(
+                    std::string( component, len ).c_str() ) );
+                if( !encoded )
+                    return false;
 
-            auto resolved = make_cstr_ptr( vlc_uri_resolve( base_uri.c_str(), ref.get() ) );
+                ref += encoded.get();
+                component += len;
+                if( *component == '/' )
+                    ref += *component++;
+            }
+
+            auto resolved = make_cstr_ptr( vlc_uri_resolve( base_uri.c_str(), ref.c_str() ) );
             if( !resolved )
                 return false;
 
@@ -260,10 +268,6 @@ bool ThemeLoader::unarchive( const std::string& fileName, const std::string &tem
                 return false;
             }
 
-#if defined( _WIN32 )
-            if( strchr( child->psz_name, '\\' ) != nullptr )
-                return false;
-#endif
             /* Use the path validated through the uri resolution */
 
             auto out_path = tempPath + "/" + child->psz_name;



View it on GitLab: https://code.videolan.org/videolan/vlc/-/commit/9e74dc226d574c700a0ea118834723d56593dfd9

-- 
View it on GitLab: https://code.videolan.org/videolan/vlc/-/commit/9e74dc226d574c700a0ea118834723d56593dfd9
You're receiving this email because of your account on code.videolan.org. Manage all notifications: https://code.videolan.org/-/profile/notifications | Help: https://code.videolan.org/help




More information about the vlc-commits mailing list