fix: harden durable workspace runtime config leases

This commit is contained in:
2026-08-11 09:44:08 +02:00
parent e0950f5ed4
commit 390122480a
5 changed files with 510 additions and 175 deletions
+27 -3
View File
@@ -573,10 +573,34 @@ def _validate_raw_config_shape(raw: dict[str, Any], path: Path) -> None:
def load_config(path: Path) -> Config:
if not path.exists():
raise ConfigError(f"File di configurazione non trovato: {path}")
# Backend runtime leases pass the verified canonical config as fd 3 while retaining
# the ordinary absolute -c argument for diagnostics and source identity. Never reopen
# that pathname: an ancestor or leaf replacement after spawn must not alter bytes used
# by the harness.
runtime_fd = os.environ.get("THT_CONFIG_FD")
if runtime_fd is not None:
try:
fd = int(runtime_fd)
info = os.fstat(fd)
if (not stat.S_ISREG(info.st_mode) or info.st_nlink != 1
or stat.S_IMODE(info.st_mode) != 0o400
or info.st_uid != os.getuid()):
raise OSError("unsafe runtime config descriptor")
chunks: list[bytes] = []
while chunk := os.read(fd, 1024 * 1024):
chunks.append(chunk)
source_text = b"".join(chunks).decode("utf-8")
except (OSError, UnicodeError, ValueError) as exc:
raise ConfigError("File di configurazione runtime non attendibile") from exc
else:
if not path.exists():
raise ConfigError(f"File di configurazione non trovato: {path}")
try:
source_text = path.read_text()
except OSError as exc:
raise ConfigError(f"File di configurazione non trovato: {path}") from exc
try:
raw = yaml.safe_load(path.read_text())
raw = yaml.safe_load(source_text)
except yaml.YAMLError as exc:
raise ConfigError(f"Configurazione YAML non valida: {path}") from exc
if not isinstance(raw, dict):