Skip to content

security(attestation): decouple temporary receipt names from output leaf length #2310

Description

@seonghobae

Finding

Current #2300 hard-link publication names its temporary inode as .{filename}.{uuid}.tmp. A valid output leaf near the filesystem NAME_MAX can therefore pass the output-path checks but make temporary creation exceed NAME_MAX. The resulting os.open() OSError currently escapes the typed verifier boundary.

This is a current review finding on scripts/ci/verify_scientific_validation_evidence.py, not a reason to weaken no-clobber publication or the pinned-parent boundary.

Acceptance

  • Use a short, fixed temporary-name prefix independent of the final output leaf name.
  • Preserve descriptor-relative O_CREAT | O_EXCL | O_NOFOLLOW, fsync, mode setting, no-clobber hard-link publication, and cleanup.
  • Normalize temporary-file creation failures to EvidenceError with the original OSError as the cause.
  • Add a realistic RED for a valid near-NAME_MAX final leaf and for typed temporary-creation failure.
  • Keep 100% owned branch/docstring coverage and do not weaken final leaf validation.

Refs #2299 #2300 #2306 #2307 #2309.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: ci-cdCI, GitHub Actions, checks, release, or supply chainarea: securitySecurity boundary, hardening, or vulnerability preventionstatus: triagedOpen issue has an organization taxonomy assignment

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions