Never write fetch's temp file into an existing file (closes #115)
check / check (push) Failing after 27s
check / check (push) Failing after 27s
downloadFile opened the temp file with os.Create, which opens and empties a file already at that name. If that file was a hard link to a file outside the destination directory, fetch overwrote the outside file. It now removes whatever is at the temp name, which removes only that name, and creates the temp file with O_EXCL, so the create fails if the name reappears in between. A leftover temp file from an interrupted run is still replaced. The new test puts a hard link at the temp name and checks that fetch succeeds and the outside file is unchanged. Model: opus-5-5
This commit is contained in:
@@ -24,6 +24,9 @@ only thing left of the `chore/align-repo-policies` branch is the list below.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-03: `fetch` removes whatever sits at a file's temp name and then
|
||||
creates the temp file only if that name is free, so a hard link left there
|
||||
cannot make it write into a file outside the destination directory (#115)
|
||||
- 2026-10-03: `fetch` refuses any manifest path that runs through a symlink
|
||||
already in the destination directory, checked before each of its writes
|
||||
(directories, temp file, rename), so such a symlink cannot send a write
|
||||
|
||||
Reference in New Issue
Block a user