Never write fetch's temp file into an existing file (closes #115) #118

Merged
clawbot merged 1 commits from issue-115-fetch-tmp-hardlink into next 2026-10-03 16:58:36 +02:00
1 Commits
Author SHA1 Message Date
sneak 8461b2a3b9 Never write fetch's temp file into an existing file (closes #115)
check / check (push) Successful in 1m3s
downloadFile opened the temp file with os.Create, which opens and
empties a file already at that name. If that file was a hard link to a
file outside the destination directory, fetch overwrote the outside
file. It now removes whatever is at the temp name, which removes only
that name, and creates the temp file with O_EXCL, so the create fails if
anything is still or again there. A leftover temp file from an
interrupted run is still replaced. The new test puts a hard link at the
temp name and checks that fetch succeeds and the outside file is
unchanged. The command name is now the constant cmdFetch, like the other
command names, because lint requires it once a third test uses it.

Model: opus-5-5
2026-10-03 14:31:46 +00:00