Source: #477 (comment)
Classification
- Category: evidence accessibility
- Micro-category: atomic replacement mode drift
- Severity: P2
Trigger
At PR #477 commit a8b2a09c7b9d5317c74ad96b6bed5faba8c6c358,
atomic_write_json replaces lifecycle JSON with a file created by
tempfile.mkstemp. The replacement therefore installs the temporary file's
private 0600 mode instead of preserving an existing destination mode such as
0644 or 0660.
Impact
A lifecycle transition can make previously shared benchmark evidence unreadable
to a packaging, reporting, or review process running under another account.
Expected
- Preserve the exact permission bits of an existing regular destination.
- Give first-write lifecycle JSON an explicit, environment-independent
0644
evidence mode.
- Apply the mode before replacement so every failure leaves the previous
destination unchanged.
- Keep symlink and cross-directory rejection intact.
Acceptance
- Replacement preserves a non-default existing mode byte-for-byte and
mode-for-mode.
- First write has the declared evidence mode.
- Mode-setting failure cleans the temporary file and preserves the old file.
- macOS/Linux focused tests and the existing atomic-write matrix pass.
Source: #477 (comment)
Classification
Trigger
At PR #477 commit
a8b2a09c7b9d5317c74ad96b6bed5faba8c6c358,atomic_write_jsonreplaces lifecycle JSON with a file created bytempfile.mkstemp. The replacement therefore installs the temporary file'sprivate
0600mode instead of preserving an existing destination mode such as0644or0660.Impact
A lifecycle transition can make previously shared benchmark evidence unreadable
to a packaging, reporting, or review process running under another account.
Expected
0644evidence mode.
destination unchanged.
Acceptance
mode-for-mode.