Source review comment:
#477 (comment)
Exact reviewed SHA: da6b5a09504f709f42a66e2d9683088815ea4e21
Trigger
Use the default root/runs/<id> destination when root/runs is missing under
umask 002 or 000.
Expected
Every newly created lifecycle ancestor is private.
Actual
Path.mkdir(parents=True, mode=0o700) applies 0700 only to the leaf and
creates the missing runs ancestor through the process umask.
Impact
Another principal can rename or replace the whole run directory between later
commands that reopen it by path.
Required regression
Create the default root/runs parent explicitly at 0700 before creating the
run leaf, and prove both modes under collaborative umasks.
Source review comment:
#477 (comment)
Exact reviewed SHA:
da6b5a09504f709f42a66e2d9683088815ea4e21Trigger
Use the default
root/runs/<id>destination whenroot/runsis missing underumask
002or000.Expected
Every newly created lifecycle ancestor is private.
Actual
Path.mkdir(parents=True, mode=0o700)applies0700only to the leaf andcreates the missing
runsancestor through the process umask.Impact
Another principal can rename or replace the whole run directory between later
commands that reopen it by path.
Required regression
Create the default
root/runsparent explicitly at0700before creating therun leaf, and prove both modes under collaborative umasks.