Highlights
🐛 A recursive AFC pull stays inside its destination
Pulling a directory built each local path from names the device supplied, without checking them. A .. entry in a directory listing, or a symlink whose target ends in .., made the pull write one level above the folder you chose. Both names now go through the same safe_paths validation the backup, crash-report and symbol-fetching code already use, and the pull fails with DevicePathError (or skips the entry under --ignore-errors).
This also covers an ordinary tree containing a link to its own parent, which used to recurse until the path grew too long.
pymobiledevice3 afc pull /DCIM ./outWhat's Changed
- 94556bc afc: Validate the link target name when pulling a directory (#2002) (@doronz88)
- 9165a21 afc: Validate device-supplied names when pulling a directory (#2002) (@NotAFlightRisk)
New Contributors
- @NotAFlightRisk made their first contribution in #2002
Full Changelog: v11.23.0...v11.23.1