check / check (push) Failing after 31s
sanitizePath checks manifest paths only as text, so a symlink already inside the destination directory could send fetch's writes outside it. checkNoSymlinks now looks at each existing part of a path with os.Lstat and refuses the path if any part is a symlink, wherever it points. fetch runs it immediately before each write: creating the parent directories, creating the temp file, and renaming it into place. The new test puts such a symlink at each of those three places, and once inside a plain directory, and checks that the fetch fails and nothing outside changes. The G304 comment now states what holds. A symlink swapped in between a check and its write is not caught; os.Root closes that once the Go version is raised. Model: opus-5-5