A song library mounted through a directory JUNCTION/symlink subfolder (a
library shared across app installs; the desktop app's own mounts) had broken
album art and couldn't load: the scanner's rglob follows the junction and
indexes the songs, but _resolve_dlc_path (via safe_join's .resolve()) followed
the junction to its real target, saw it outside DLC_DIR, and rejected every
song reached through it → 403 on /art, 404 on /art/candidates, broken covers.
- _resolve_dlc_path now uses LEXICAL containment (os.path.normpath, no symlink
following) so an in-library junction is allowed, while `..` traversal and
absolute paths are still rejected (the traversal tests pin this).
- safe_join is left STRICT (.resolve()-based) — it is the zip-slip / plugin-
asset / avatar guard, where following a symlink out IS the defense — but
gains an explicit NUL guard (on Python 3.13/Windows resolve() no longer
raises on an embedded NUL, so the byte was leaking through; strictly-more-
rejection, no effect on the zip-slip contract).
Tests: test_dlc_junction (junction allowed; `..`/absolute/NUL rejected; the
safe_join-stays-strict contrast). Existing traversal/safepath/art-candidates
suites stay green.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>