The Installer That Deleted boot.ini — Python Bug Hunt

Modelled on EVE Online's Trinity patch of December 2007. CCP's installer for the Premium graphics update was meant to remove a file named boot.ini that…

  • Language: Python
  • Layer: Backend
  • Difficulty: Medium
  • Concepts: Security, Validation, Config
  • Modelled on: EVE Online · 2007
  • Visible tests: a legacy file inside the install directory is removed; a rooted manifest name stays inside the install directory
  • Reward: 50 XP for a complete fix

Briefing

Modelled on EVE Online's Trinity patch of December 2007. CCP's installer for the Premium graphics update was meant to remove a file named boot.ini that belonged to EVE, but it deleted boot.ini from the root of the system drive instead — the file Windows XP needed to start. Affected machines would not boot until the file was restored, and CCP published repair instructions.

This project is a reconstruction: installer.py removes files listed in a patch manifest, and names in the manifest are relative to the game's install directory. It resolves them with the locked pathutil.join, which — like os.path.join — lets a rooted name replace the base directory, and it never checks that the result is still inside the install directory.

Fix remove_legacy_files so it can only ever delete inside the install directory.

Bug report

BUG-TRINITY-BOOT · Priority: Critical (machines unbootable) · Reported by: player support

remove_legacy_files(fs, install_dir, names) returns {"deleted": [...], "refused": [...]}:

  • install_dir None or "" raises ValueError before anything is touched
  • root = pathutil.normalize(install_dir)
  • every name is relative to root, even when the manifest writes it with a leading "/" or "\"; a name carrying a drive letter ("D:…") is refused
  • target = pathutil.normalize(root + "/" + name-without-leading-separators); a target that is not inside root (does not start with root + "/") is refused — the ORIGINAL name goes in "refused" and nothing is deleted
  • a target inside root that exists is deleted and listed in "deleted"; one that does not exist is skipped silently

Observed: the manifest entry "/boot.ini" deleted C:/boot.ini.

Logs

[patcher] install_dir=C:/Program Files/CCP/EVE
[patcher] removing legacy file C:/boot.ini … ok
[support] ticket #…: "NTLDR: invalid boot.ini" after patching

The code as shipped

src/patcher/installer.py (editable)

pathutil = bug_require("./pathutil.py")


def remove_legacy_files(fs, install_dir, names):
    deleted = []
    refused = []
    for name in names:
        target = pathutil.join(install_dir, name)
        if fs.exists(target):
            fs.delete(target)
            deleted.append(target)
    return {"deleted": deleted, "refused": refused}

Read-only context: src/patcher/fakefs.py, src/patcher/pathutil.py.

Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More Python bug hunts.