Conversation
|
Warning Review limit reachedNext included review available in 59 minutes. View limit detailsLimit details: You’ve used all 2 included reviews currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (3)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
b9876a9 to
450f859
Compare
|
The code is competent, but it hardens a 0o700 mkdtemp folder used only by an opt-in probe, which a same-user session could write to anyway. It adds a third unsynced copy of the hook writer, and we've already decided the probe stays in mkdtemp. Thanks for the effort, The pr's im closing while not used are still appreciated. |
What: Port the hardening primitives already used by the production hook writer into bmad_loop_probe_hook.py's _atomic_write: a symlink/junction check, O_NOFOLLOW/dir_fd-anchored create+rename, an explicit 0o600 mode, and a short-write-safe write loop.
Why: The probe hook's _atomic_write currently does a plain open()+json.dump()+os.replace() with no symlink check and no explicit permissions, unlike the production relay's writer; SECURITY.md explicitly lists hook/signal-file handling as in-scope.
How:
Testing: Run tests/test_probe_hook.py; new tests must fail against the pre-fix _atomic_write and pass after porting the hardening.
Changelog: "Security: hardened the probe-adapter capture writer against symlink-based file replacement, matching the production hook writer."
🤖 Generated with Claude Code