Skip to content

Keep completed atomic JSON temps private until publication #490

Description

@Anionix

Source review comment:
#477 (comment)

Exact reviewed SHA: 5ef7c1ffe5200ffb68f5d1b5b425c63961790c37

Trigger

Write lifecycle JSON into an owner-owned directory that is readable/searchable
by other principals, then fail os.replace after the temporary file has been
restored to the destination's public mode.

Expected

Unpublished lifecycle payloads remain private.

Actual

The completed temporary file is widened before publication. A failed replace
retains the complete payload at that wider mode.

Impact

Confidentiality leak of unpublished lifecycle evidence.

Required regression

Keep the temporary inode at 0600 through a successful replace. Restore the
intended destination mode only after the retained descriptor names the
published inode, and prove a failed replace retains a private temp.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions