Finding
Current #2300 hard-link publication names its temporary inode as .{filename}.{uuid}.tmp. A valid output leaf near the filesystem NAME_MAX can therefore pass the output-path checks but make temporary creation exceed NAME_MAX. The resulting os.open() OSError currently escapes the typed verifier boundary.
This is a current review finding on scripts/ci/verify_scientific_validation_evidence.py, not a reason to weaken no-clobber publication or the pinned-parent boundary.
Acceptance
- Use a short, fixed temporary-name prefix independent of the final output leaf name.
- Preserve descriptor-relative
O_CREAT | O_EXCL | O_NOFOLLOW, fsync, mode setting, no-clobber hard-link publication, and cleanup.
- Normalize temporary-file creation failures to
EvidenceError with the original OSError as the cause.
- Add a realistic RED for a valid near-
NAME_MAX final leaf and for typed temporary-creation failure.
- Keep 100% owned branch/docstring coverage and do not weaken final leaf validation.
Refs #2299 #2300 #2306 #2307 #2309.
Finding
Current
#2300hard-link publication names its temporary inode as.{filename}.{uuid}.tmp. A valid output leaf near the filesystemNAME_MAXcan therefore pass the output-path checks but make temporary creation exceedNAME_MAX. The resultingos.open()OSErrorcurrently escapes the typed verifier boundary.This is a current review finding on
scripts/ci/verify_scientific_validation_evidence.py, not a reason to weaken no-clobber publication or the pinned-parent boundary.Acceptance
O_CREAT | O_EXCL | O_NOFOLLOW, fsync, mode setting, no-clobber hard-link publication, and cleanup.EvidenceErrorwith the originalOSErroras the cause.NAME_MAXfinal leaf and for typed temporary-creation failure.Refs #2299 #2300 #2306 #2307 #2309.