create the resumable index store with owner-only permissions#2281
Open
madib06ops wants to merge 1 commit into
Open
create the resumable index store with owner-only permissions#2281madib06ops wants to merge 1 commit into
madib06ops wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
PropertiesBasedResumableProcessor.save() writes the download index to the fixed path
$java.io.tmpdir/ahc/ResumableAsyncHandler.properties, creating the directory with mkdirs() and the file with createNewFile(), so both land with umask-default permissions in the shared temp directory and the write follows whatever is at that path. On a multi-user host any local user can then read the URLs being downloaded (userinfo and query tokens included), or plant a symlink at that predictable path before the shutdown hook fires and have the client truncate the file it points to; load() followed the same symlink on the way back in, so a planted file also feeds forged resume offsets to the handler. The store is now created 0700/0600 and reopened with CREATE_NEW after a delete, so a raced re-plant fails the open instead of being written through, and load() reads with NOFOLLOW_LINKS. Both checks live in the processor because it owns the path, and the new test fails on the current code with rw-r--r-- and with the symlink target overwritten.