fix workspace output and cleanup uncertainty

This commit is contained in:
2026-08-11 04:46:48 +02:00
parent c7f7a6e1b0
commit 69cc47c13f
12 changed files with 358 additions and 91 deletions
+12
View File
@@ -13,6 +13,15 @@ import (
var ErrUnsafeFile = errors.New("unsafe file")
// ErrIndeterminateFile means publication cleanup could not establish whether a
// private candidate is still named. Callers must reconcile the destination and
// private stages before retrying; it is never a blind-retry-safe failure.
var ErrIndeterminateFile = errors.New("indeterminate file state")
// beforeBoundedRead is an internal test seam used to deterministically suspend
// a read between opening the file and resolving its final pathname.
var beforeBoundedRead func()
// ValidateCanonicalPath rejects relative or lexically non-canonical paths before they are opened.
func ValidateCanonicalPath(path string) error {
if !filepath.IsAbs(path) || filepath.Clean(path) != path || strings.Contains(path, string(filepath.Separator)+".."+string(filepath.Separator)) {
@@ -32,6 +41,9 @@ func readBoundedRegularFile(file *os.File, maximum int64) ([]byte, error) {
if err != nil || !info.Mode().IsRegular() {
return nil, ErrUnsafeFile
}
if beforeBoundedRead != nil {
beforeBoundedRead()
}
contents, err := io.ReadAll(io.LimitReader(file, maximum+1))
if err != nil || int64(len(contents)) > maximum {
return nil, ErrUnsafeFile