Skip to content

fix(ingestor): stats .tmp writer follows a hard link to another file of the ingestor's user #228

Description

@dborup

Relates to #160, #161, #216

Problem

A hard link at <stats path>.tmp that points to another file owned by the ingestor's user passes the regular-file and owner checks in writeStatsAtomic. The writer then truncates that file, overwrites it with the stats JSON, and the rename publishes it.

Proposed fix

  • After the open, refuse a tmp whose Fstat shows nlink > 1, and leave it in place.
  • Report it with the same statsWriteError shape, e.g. <tmp>: hard-linked (nlink N); remove it.

Acceptance

  • A Unix test with a hard link at the tmp path gets an error, the link target stays unchanged, and nothing is published.
  • The existing stats-file tests stay green.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions