fix(thothctl): fail closed on partial secret loads

This commit is contained in:
2026-08-11 05:10:32 +02:00
parent 69cc47c13f
commit 783cc3bb34
7 changed files with 60 additions and 18 deletions
@@ -16,6 +16,10 @@ import (
// descriptor. O_NOFOLLOW rejects symlinks at every component, and the open directory descriptors
// prevent later parent replacement from redirecting the final open.
func ReadCanonicalRegular(path string, maximum int64) ([]byte, error) {
return readCanonicalRegularWithHook(path, maximum, nil)
}
func readCanonicalRegularWithHook(path string, maximum int64, beforeRead func()) ([]byte, error) {
if err := ValidateCanonicalPath(path); err != nil {
return nil, err
}
@@ -54,7 +58,7 @@ func ReadCanonicalRegular(path string, maximum int64) ([]byte, error) {
if err := unix.Fstat(int(file.Fd()), &before); err != nil || before.Nlink > 1 || before.Mode&unix.S_IFMT != unix.S_IFREG {
return nil, ErrUnsafeFile
}
contents, err := readBoundedRegularFile(file, maximum)
contents, err := readBoundedRegularFile(file, maximum, beforeRead)
if err != nil {
return nil, ErrUnsafeFile
}