Never write fetch's temp file into an existing file (closes #115)
check / check (push) Failing after 27s

downloadFile opened the temp file with os.Create, which opens and
empties a file already at that name. If that file was a hard link to a
file outside the destination directory, fetch overwrote the outside
file. It now removes whatever is at the temp name, which removes only
that name, and creates the temp file with O_EXCL, so the create fails if
the name reappears in between. A leftover temp file from an interrupted
run is still replaced. The new test puts a hard link at the temp name and
checks that fetch succeeds and the outside file is unchanged.

Model: opus-5-5
This commit is contained in:
2026-10-03 14:28:43 +00:00
parent 7e601929c8
commit 8686091f2d
3 changed files with 54 additions and 5 deletions
+3
View File
@@ -24,6 +24,9 @@ only thing left of the `chore/align-repo-policies` branch is the list below.
# Completed Steps
- 2026-10-03: `fetch` removes whatever sits at a file's temp name and then
creates the temp file only if that name is free, so a hard link left there
cannot make it write into a file outside the destination directory (#115)
- 2026-10-03: `fetch` refuses any manifest path that runs through a symlink
already in the destination directory, checked before each of its writes
(directories, temp file, rename), so such a symlink cannot send a write