From 56bfb128432a38e2e6bc5448122914bb271b1252 Mon Sep 17 00:00:00 2001
From: Eric Covener <covener@apache.org>
Date: Fri, 5 Jun 2026 10:13:46 +0000
Subject: [PATCH] Merge r1935009 from trunk:

dav_fs_get_resource: disallow DAV_FS_STATE_DIR


Submitted By: jorton
Reviewed By: jorton, covener, gbechis


git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.4.x@1935013 13f79535-47bb-0310-9956-ffa450edef68

Conflict:no
Reference:https://github.com/apache/httpd/commit/56bfb128432.patch
---
 modules/dav/fs/repos.c | 29 +++++++++++++++++++++++++++--
 1 file changed, 27 insertions(+), 2 deletions(-)

diff --git a/modules/dav/fs/repos.c b/modules/dav/fs/repos.c
index cead8b19cc1..cf67c8b286e 100644
--- a/modules/dav/fs/repos.c
+++ b/modules/dav/fs/repos.c
@@ -22,6 +22,7 @@
 #include "apr_file_io.h"
 #include "apr_strings.h"
 #include "apr_buckets.h"
+#include "apr_lib.h"
 
 #if APR_HAVE_UNISTD_H
 #include <unistd.h>             /* for getpid() */
@@ -673,8 +674,8 @@ static dav_error * dav_fs_get_resource(
 {
     dav_resource_private *ctx;
     dav_resource *resource;
-    char *s;
-    char *filename;
+    char *s, *parent;
+    const char *filename, *dirname;
     apr_size_t len;
 
     /* ### optimize this into a single allocation! */
@@ -708,6 +709,30 @@ static dav_error * dav_fs_get_resource(
     if (len > 1 && s[len - 1] == '/') {
         s[len - 1] = '\0';
     }
+
+    /* Deny any access to, or within, the state directory. */
+    filename = apr_filepath_name_get(s);
+    parent = ap_make_dirstr_parent(r->pool, s);
+    /* Strip the trailing slash and extract the leaf directory name. */
+    len = strlen(parent);
+    if (len > 1 && parent[len - 1] == '/') {
+        parent[len - 1] = '\0';
+    }
+    dirname = apr_filepath_name_get(parent);
+#ifdef CASE_BLIND_FILESYSTEM
+    if (ap_cstr_casecmp(filename, DAV_FS_STATE_DIR) == 0
+        || ap_cstr_casecmp(dirname, DAV_FS_STATE_DIR) == 0) {
+#else
+    if (strcmp(filename, DAV_FS_STATE_DIR) == 0
+        || strcmp(dirname, DAV_FS_STATE_DIR) == 0) {
+#endif
+        ap_log_rerror(APLOG_MARK, APLOG_ERR, 0, r,
+                      "access to " DAV_FS_STATE_DIR " state directory "
+                      "denied for %s", r->filename);
+        return dav_new_error(r->pool, HTTP_FORBIDDEN, 0, 0,
+                             "Access to the state directory denied.");
+    }
+
     ctx->pathname = s;
 
     /* Create resource descriptor */