Skip to content

Atomic JSON replacement changes evidence permissions #478

Description

@Anionix

Source: #477 (comment)

Classification

  • Category: evidence accessibility
  • Micro-category: atomic replacement mode drift
  • Severity: P2

Trigger

At PR #477 commit a8b2a09c7b9d5317c74ad96b6bed5faba8c6c358,
atomic_write_json replaces lifecycle JSON with a file created by
tempfile.mkstemp. The replacement therefore installs the temporary file's
private 0600 mode instead of preserving an existing destination mode such as
0644 or 0660.

Impact

A lifecycle transition can make previously shared benchmark evidence unreadable
to a packaging, reporting, or review process running under another account.

Expected

  • Preserve the exact permission bits of an existing regular destination.
  • Give first-write lifecycle JSON an explicit, environment-independent 0644
    evidence mode.
  • Apply the mode before replacement so every failure leaves the previous
    destination unchanged.
  • Keep symlink and cross-directory rejection intact.

Acceptance

  • Replacement preserves a non-default existing mode byte-for-byte and
    mode-for-mode.
  • First write has the declared evidence mode.
  • Mode-setting failure cleans the temporary file and preserves the old file.
  • macOS/Linux focused tests and the existing atomic-write matrix pass.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions