Never write fetch's temp file into an existing file (closes #115)
check / check (push) Successful in 53s
check / check (push) Successful in 53s
downloadFile opened the temp file with os.Create, which opens and empties a file already at that name. If that file was a hard link to a file outside the destination directory, fetch overwrote the outside file. It now removes whatever is at the temp name, which removes only that name, and creates the temp file with O_EXCL, so the create fails if anything is still or again there. A leftover temp file from an interrupted run is still replaced. The new test puts a hard link at the temp name and checks that fetch succeeds and the outside file is unchanged. The command name is now the constant cmdFetch, like the other command names, because lint requires it once a third test uses it. Model: opus-5-5
This commit was merged in pull request #118.
This commit is contained in:
@@ -24,6 +24,9 @@ only thing left of the `chore/align-repo-policies` branch is the list below.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-03: `fetch` removes whatever sits at a file's temp name and then
|
||||
creates the temp file only if that name is free, so a hard link left there
|
||||
cannot make it write into a file outside the destination directory (#115)
|
||||
- 2026-10-03: `fetch` refuses any manifest path that runs through a symlink
|
||||
already in the destination directory, checked before each of its writes
|
||||
(directories, temp file, rename), so such a symlink cannot send a write
|
||||
|
||||
Reference in New Issue
Block a user