AWS cli: Document --no-follow-symlinks behavior when downloading from S3
Summary
Expands the --follow-symlinks/--no-follow-symlinks description to state that on download, --no-follow-symlinks skips objects whose destination is a symlink or lies under one, while symlinks in the leading path are still followed.
Security assessment
Same symlink-handling documentation as s3 cp: --no-follow-symlinks avoids writing through symlinked destinations during download, reducing symlink-based file overwrite risk; no CVE referenced.
Evidence
+`--follow-symlinks` | `--no-follow-symlinks` (boolean) Symbolic links are followed when uploading to S3 from the local filesystem. Note that S3 does not support symbolic links, so the contents of the link target are uploaded under the name of the link. When downloading from S3, `--no-follow-symlinks` skips any object whose destination is a symbolic link, or is located under one, starting at the destination you specified. Symbolic links in the path leading up to that destination are still followed. When neither `--follow-symlinks` nor `--no-follow-symlinks` is specified, the default is to follow symlinks.
Diff
diff --git a/cli/latest/reference/s3/mv.md b/cli/latest/reference/s3/mv.md index 2c2b3df..19af8e5 100644 --- a//cli/latest/reference/s3/mv.md +++ b//cli/latest/reference/s3/mv.md @@ -15 +15 @@ - * [AWS CLI 2.37.6 Command Reference](../../index.html) » + * [AWS CLI 2.37.7 Command Reference](../../index.html) » @@ -147 +147 @@ To verify that the source and destination buckets are not the same, use the `--v -`--follow-symlinks` | `--no-follow-symlinks` (boolean) Symbolic links are followed only when uploading to S3 from the local filesystem. Note that S3 does not support symbolic links, so the contents of the link target are uploaded under the name of the link. When neither `--follow-symlinks` nor `--no-follow-symlinks` is specified, the default is to follow symlinks. +`--follow-symlinks` | `--no-follow-symlinks` (boolean) Symbolic links are followed when uploading to S3 from the local filesystem. Note that S3 does not support symbolic links, so the contents of the link target are uploaded under the name of the link. When downloading from S3, `--no-follow-symlinks` skips any object whose destination is a symbolic link, or is located under one, starting at the destination you specified. Symbolic links in the path leading up to that destination are still followed. When neither `--follow-symlinks` nor `--no-follow-symlinks` is specified, the default is to follow symlinks. @@ -553 +553 @@ Output: - * [AWS CLI 2.37.6 Command Reference](../../index.html) » + * [AWS CLI 2.37.7 Command Reference](../../index.html) »