Files
mfer/internal
sneak 58c40eceba
check / check (push) Successful in 1m46s
Refuse fetch writes through a symlink in the destination (closes #86)
sanitizePath checks manifest paths only as text, so a symlink already
inside the destination directory could send fetch's writes outside it.
checkNoSymlinks now looks at each existing part of a path with os.Lstat
and refuses the path if any part is a symlink, wherever it points.
fetch runs it immediately before each write: creating the parent
directories, creating the temp file, and renaming it into place. The new
test puts such a symlink at each of those three places and checks that
the fetch fails and nothing outside changes. The G304 comment now states
what holds. A symlink swapped in between a check and its write is not
caught; os.Root closes that once the Go version is raised.

Model: opus-5-5
2026-10-03 12:42:05 +00:00
..