Relates to #160, #161, #216
Problem
A hard link at <stats path>.tmp that points to another file owned by the ingestor's user passes the regular-file and owner checks in writeStatsAtomic. The writer then truncates that file, overwrites it with the stats JSON, and the rename publishes it.
Proposed fix
- After the open, refuse a tmp whose
Fstat shows nlink > 1, and leave it in place.
- Report it with the same
statsWriteError shape, e.g. <tmp>: hard-linked (nlink N); remove it.
Acceptance
Relates to #160, #161, #216
Problem
A hard link at
<stats path>.tmpthat points to another file owned by the ingestor's user passes the regular-file and owner checks inwriteStatsAtomic. The writer then truncates that file, overwrites it with the stats JSON, and the rename publishes it./tmp), and withfs.protected_hardlinks=1also access to the target.Proposed fix
Fstatshowsnlink > 1, and leave it in place.statsWriteErrorshape, e.g.<tmp>: hard-linked (nlink N); remove it.Acceptance