Skip to content

Commit de50237

Browse files
chore(copilot): re-sync the vendored core after #67
#67 added the mode parameter to core.atomic_write while this branch was open, so the copilot vendored copy was a version behind. Caught by the vendored-in-sync job against the merge with main, which is exactly what that check is for. Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
1 parent 12422a0 commit de50237

1 file changed

Lines changed: 11 additions & 1 deletion

File tree

  • copilot/engine/_vendor/agentrust_capture_core

‎copilot/engine/_vendor/agentrust_capture_core/state.py‎

Lines changed: 11 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -28,12 +28,17 @@ class StatePaths:
2828
latest: Path
2929

3030

31-
def atomic_write(path: Path, content: str) -> None:
31+
def atomic_write(path: Path, content: str, *, mode: int | None = None) -> None:
3232
"""Write via a temporary file and replace, so a crash cannot truncate state.
3333
3434
A half-written baseline is worse than a missing one: the engine would treat it
3535
as corrupt on every future session, and a user who sees a broken check often
3636
enough stops reading it.
37+
38+
``mode`` is applied to the temporary file before the replace, so the file is
39+
never briefly readable at wider permissions than intended. Callers that write
40+
a private key pass ``0o600``. Best-effort, since not every filesystem carries
41+
POSIX permissions.
3742
"""
3843
path.parent.mkdir(parents=True, exist_ok=True)
3944
handle, tmp_name = tempfile.mkstemp(dir=str(path.parent), prefix=path.name, suffix=".tmp")
@@ -43,6 +48,11 @@ def atomic_write(path: Path, content: str) -> None:
4348
fh.write(content)
4449
fh.flush()
4550
os.fsync(fh.fileno())
51+
if mode is not None:
52+
try:
53+
os.chmod(tmp, mode)
54+
except OSError:
55+
pass
4656
os.replace(tmp, path)
4757
except BaseException:
4858
tmp.unlink(missing_ok=True)

0 commit comments

Comments
 (0)