fix: harden durable workspace runtime config leases
This commit is contained in:
+27
-3
@@ -573,10 +573,34 @@ def _validate_raw_config_shape(raw: dict[str, Any], path: Path) -> None:
|
||||
|
||||
|
||||
def load_config(path: Path) -> Config:
|
||||
if not path.exists():
|
||||
raise ConfigError(f"File di configurazione non trovato: {path}")
|
||||
# Backend runtime leases pass the verified canonical config as fd 3 while retaining
|
||||
# the ordinary absolute -c argument for diagnostics and source identity. Never reopen
|
||||
# that pathname: an ancestor or leaf replacement after spawn must not alter bytes used
|
||||
# by the harness.
|
||||
runtime_fd = os.environ.get("THT_CONFIG_FD")
|
||||
if runtime_fd is not None:
|
||||
try:
|
||||
fd = int(runtime_fd)
|
||||
info = os.fstat(fd)
|
||||
if (not stat.S_ISREG(info.st_mode) or info.st_nlink != 1
|
||||
or stat.S_IMODE(info.st_mode) != 0o400
|
||||
or info.st_uid != os.getuid()):
|
||||
raise OSError("unsafe runtime config descriptor")
|
||||
chunks: list[bytes] = []
|
||||
while chunk := os.read(fd, 1024 * 1024):
|
||||
chunks.append(chunk)
|
||||
source_text = b"".join(chunks).decode("utf-8")
|
||||
except (OSError, UnicodeError, ValueError) as exc:
|
||||
raise ConfigError("File di configurazione runtime non attendibile") from exc
|
||||
else:
|
||||
if not path.exists():
|
||||
raise ConfigError(f"File di configurazione non trovato: {path}")
|
||||
try:
|
||||
source_text = path.read_text()
|
||||
except OSError as exc:
|
||||
raise ConfigError(f"File di configurazione non trovato: {path}") from exc
|
||||
try:
|
||||
raw = yaml.safe_load(path.read_text())
|
||||
raw = yaml.safe_load(source_text)
|
||||
except yaml.YAMLError as exc:
|
||||
raise ConfigError(f"Configurazione YAML non valida: {path}") from exc
|
||||
if not isinstance(raw, dict):
|
||||
|
||||
Reference in New Issue
Block a user