The Installer That Deleted boot.ini — Python Bug Hunt
Modelled on EVE Online's Trinity patch of December 2007. CCP's installer for the Premium graphics update was meant to remove a file named boot.ini that…
- Language: Python
- Layer: Backend
- Difficulty: Medium
- Concepts: Security, Validation, Config
- Modelled on: EVE Online · 2007
- Visible tests: a legacy file inside the install directory is removed; a rooted manifest name stays inside the install directory
- Reward: 50 XP for a complete fix
Briefing
Modelled on EVE Online's Trinity patch of December 2007. CCP's installer for the Premium graphics update was meant to remove a file named boot.ini that belonged to EVE, but it deleted boot.ini from the root of the system drive instead — the file Windows XP needed to start. Affected machines would not boot until the file was restored, and CCP published repair instructions.
This project is a reconstruction: installer.py removes files listed in a patch manifest, and names in the manifest are relative to the game's install directory. It resolves them with the locked pathutil.join, which — like os.path.join — lets a rooted name replace the base directory, and it never checks that the result is still inside the install directory.
Fix remove_legacy_files so it can only ever delete inside the install directory.
Bug report
BUG-TRINITY-BOOT · Priority: Critical (machines unbootable) · Reported by: player support
remove_legacy_files(fs, install_dir, names) returns {"deleted": [...], "refused": [...]}:
- install_dir None or "" raises ValueError before anything is touched
- root = pathutil.normalize(install_dir)
- every name is relative to root, even when the manifest writes it with a leading "/" or "\"; a name carrying a drive letter ("D:…") is refused
- target = pathutil.normalize(root + "/" + name-without-leading-separators); a target that is not inside root (does not start with root + "/") is refused — the ORIGINAL name goes in "refused" and nothing is deleted
- a target inside root that exists is deleted and listed in "deleted"; one that does not exist is skipped silently
Observed: the manifest entry "/boot.ini" deleted C:/boot.ini.
Logs
[patcher] install_dir=C:/Program Files/CCP/EVE
[patcher] removing legacy file C:/boot.ini … ok
[support] ticket #…: "NTLDR: invalid boot.ini" after patchingThe code as shipped
src/patcher/installer.py (editable)
pathutil = bug_require("./pathutil.py")
def remove_legacy_files(fs, install_dir, names):
deleted = []
refused = []
for name in names:
target = pathutil.join(install_dir, name)
if fs.exists(target):
fs.delete(target)
deleted.append(target)
return {"deleted": deleted, "refused": refused}
Read-only context: src/patcher/fakefs.py, src/patcher/pathutil.py.
Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More Python bug hunts.