Source review comment:
#477 (comment)
Exact reviewed SHA: 5ef7c1ffe5200ffb68f5d1b5b425c63961790c37
Trigger
Write lifecycle JSON into an owner-owned directory that is readable/searchable
by other principals, then fail os.replace after the temporary file has been
restored to the destination's public mode.
Expected
Unpublished lifecycle payloads remain private.
Actual
The completed temporary file is widened before publication. A failed replace
retains the complete payload at that wider mode.
Impact
Confidentiality leak of unpublished lifecycle evidence.
Required regression
Keep the temporary inode at 0600 through a successful replace. Restore the
intended destination mode only after the retained descriptor names the
published inode, and prove a failed replace retains a private temp.
Source review comment:
#477 (comment)
Exact reviewed SHA:
5ef7c1ffe5200ffb68f5d1b5b425c63961790c37Trigger
Write lifecycle JSON into an owner-owned directory that is readable/searchable
by other principals, then fail
os.replaceafter the temporary file has beenrestored to the destination's public mode.
Expected
Unpublished lifecycle payloads remain private.
Actual
The completed temporary file is widened before publication. A failed replace
retains the complete payload at that wider mode.
Impact
Confidentiality leak of unpublished lifecycle evidence.
Required regression
Keep the temporary inode at
0600through a successful replace. Restore theintended destination mode only after the retained descriptor names the
published inode, and prove a failed replace retains a private temp.