Skip to content

fix(security): isolate temporary scratch directory per user and restrict permissions - #66

Merged
ZhuchkaTriplesix merged 1 commit into
devfrom
issue/55-secure-scratch-directory
Sep 28, 2026
Merged

ZhuchkaTriplesix merged 1 commit into
devfrom
issue/55-secure-scratch-directory

Conversation

@ZhuchkaTriplesix

Copy link
Copy Markdown
Member

Summary

  • Isolated scratch/shadow directory per effective user UID (/tmp/clickhouse-query-ext-<uid>/shadow or via XDG_RUNTIME_DIR)
  • Configured directory creation mode strictly to 0700 (rwx------) preventing unauthorized local access
  • Validated directory ownership matches current process EUID and actively rejected insecure symlinks
  • Added unit tests for directory creation permissions, ownership, and symlink rejection

Closes #55

@ZhuchkaTriplesix
ZhuchkaTriplesix merged commit d56eca8 into dev Sep 28, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant