fix(auth): close diagnostic filesystem races

This commit is contained in:
2026-08-17 13:04:15 +02:00
parent be1724890a
commit 6d438f4c7e
16 changed files with 545 additions and 90 deletions
+17
View File
@@ -11,11 +11,28 @@ import (
)
func createPrivateDirectory(path string) error {
return createPrivateDirectoryAfterParentOpen(path, nil)
}
func createPrivateDirectoryAfterParentOpen(path string, afterOpen func()) error {
parents, err := openCanonicalUnixParent(path)
if err != nil {
return ErrUnsafeFile
}
defer parents.Close()
if afterOpen != nil {
afterOpen()
}
return createPrivateDirectoryAt(parents)
}
// createPrivateDirectoryAt performs every mutating operation relative to the already-opened
// parent. An attacker can rename or replace any lexical ancestor after the open without
// redirecting mkdir or chmod into a different directory tree.
func createPrivateDirectoryAt(parents *unixParentHandles) error {
if parents == nil || parents.parent < 0 || parents.target == "" {
return ErrUnsafeFile
}
if err := unix.Mkdirat(parents.parent, parents.target, 0o700); err != nil {
if errors.Is(err, unix.EEXIST) {
return os.ErrExist