Skip to content

feat(cortex-x): Open backup + tmp paths with wx flag in hooks-register and claude-md-aug - #24

Draft
github-actions[bot] wants to merge 1 commit into
mainfrom
steward/2026-06-23-open-backup-tmp-paths-with-wx-flag-in-ho-j6xj
Draft

feat(cortex-x): Open backup + tmp paths with wx flag in hooks-register and claude-md-aug#24
github-actions[bot] wants to merge 1 commit into
mainfrom
steward/2026-06-23-open-backup-tmp-paths-with-wx-flag-in-ho-j6xj

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Open bin/cortex-hooks-register.cjs (lines 138 and 150) and bin/cortex-claude-md-augment.cjs (lines 139 and 153). At each fs.writeFile / fs.copyFile call that produces a tmp or backup file, add flag: 'wx' to the options object. The wx flag aborts the write if the target path already exists or is a symlink, providing defense-in-depth against TOCTOU symlink swaps. Target dir is user-owned so practical attack surface is low, but the fix is one option object change per call site. Add a fixture test per CJS that pre-creates a symlink at the expected backup path and asserts the apply step exits with a clear error rather than overwriting through the symlink.

Steward-Action-Id: 01KVSEHHY41WZY8FREJ6MGJ6XJ
Steward-Journal-Entry: ~/.cortex/journal/cortex-x/2026-06-23.jsonl
Steward-Trigger: cron
Steward-Recommendation-Source: cortex/recommendations.md#4-open-backup-tmp-paths-with-wx-flag-in
Co-Authored-By: Steward steward@cortex-x.local

…r and claude-md-aug

Open `bin/cortex-hooks-register.cjs` (lines 138 and 150) and `bin/cortex-claude-md-augment.cjs` (lines 139 and 153). At each `fs.writeFile` / `fs.copyFile` call that produces a tmp or backup file, add `flag: 'wx'` to the options object. The `wx` flag aborts the write if the target path already exists or is a symlink, providing defense-in-depth against TOCTOU symlink swaps. Target dir is user-owned so practical attack surface is low, but the fix is one option object change per call site. Add a fixture test per CJS that pre-creates a symlink at the expected backup path and asserts the apply step exits with a clear error rather than overwriting through the symlink.

Steward-Action-Id: 01KVSEHHY41WZY8FREJ6MGJ6XJ
Steward-Journal-Entry: ~/.cortex/journal/cortex-x/2026-06-23.jsonl
Steward-Trigger: cron
Steward-Recommendation-Source: cortex/recommendations.md#4-open-backup-tmp-paths-with-wx-flag-in
Co-Authored-By: Steward <steward@cortex-x.local>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants