Skip to main content
← Back to list
01Issue
BugOpenExtensionsPublicTeam
AssigneesNone

Relationships

#2573 S3 datastore rejects valid cache paths as traversal on Windows

Opened by michael · 9/27/2026

On Windows x86_64, @swamp/s3-datastore version 2026.09.24.1 fails while pulling an ordinary namespaced object into its local cache:

Path traversal detected: <namespace>/workflow-runs/<workflow-id>/workflow-run-<run-id>.yaml

The key has no traversal segments. A workflow that triggers the pull fails before its model method runs. swamp workflow validate and swamp doctor extensions both pass.

In datastore/s3/extensions/datastores/_lib/s3_cache_sync.ts, assertSafePath normalizes the resolved path and cache path using native Windows separators, then checks resolved.startsWith(normalizedCache + "/"). A valid Windows child path contains \ at that boundary, so the check rejects it. The same literal / containment check appears in markDirty and the pushFile override-path branch. The check is still present in upstream main.

Please use a shared, platform-aware containment check across those three sites. A relative()-based check should accept paths inside the cache while continuing to reject parent traversal, sibling-prefix paths, and paths on another volume. Add Windows regression coverage for both valid keys and actual escapes.

Observed with Swamp 20260923.231117.0-sha.ad0aa46d and the S3 extension 2026.09.24.1.

02Bog Flow
◉OPEN○TRIAGED○IN PROGRESS○SHIPPED

Open

9/27/2026, 2:29:14 PM

No activity in this phase yet.

03Sludge Pulse
Editable. Press Enter to edit.

system commented 9/27/2026, 2:29:15 PM

Classified automatically when this issue was filed.

  • Source: Extensions

If you feel this classification is incorrect, add a ripple to tell us so.

michael commented 9/28/2026, 3:21:45 AM

This one is blocking me in getting my windows machine a part of the ecosystem, probably my top blocker.

stack72 commented 9/30/2026, 12:43:12 PM

Hey @michael

Windows is not a fully supported environment for us at this time - we are on the path toward doing so but we have not released a stable binary for it at this time

Paul

michael commented 10/1/2026, 8:39:32 PM

It works pretty well from your channel here: https://github.com/swamp-club/swamp/releases/tag/v20261001.202145.0-sha.a3515474

I don't expect it to work with complete parity, but why not work through these together to get it to work?

Could this issue be a start of that? It's a path separator direction.

Sign in to post a ripple.