Documentation
¶
Overview ¶
Package fixedtmp catches a path under the shared temp root whose name is CONSTANT or pid-predictable reaching a create/mkdir/exec or build sink: os.Mkdir / os.MkdirAll / os.Create / os.WriteFile / os.OpenFile(write flags) on it, an exec.Command / exec.CommandContext argument (`go build -o <path>` writes through whatever is at the path; argv[0] runs it), or an exec.Cmd Dir assignment (the child's cwd).
The bug class: 2026-09-03 adversarial pass round 4 (tests-only red probes, fixes still open) — TestDevServerRedUniqueBinaryPath (cmd/gofastr dev.go devServerBinaryPath: the rebuilt server is compiled to Join(os.TempDir(), "gofastr-dev-server-"+pid) with `go build -o` and exec'd, a fully deterministic name: a local co-user pre-plants a symlink there and the build writes through it (CWE-377 clobber) or the binary is swapped between build and exec) and TestKilnAdapterRedUniqueWorkDir (cmd/kiln adapters.go Dir constants /tmp/kiln-{omp,claude,pi,codex} consumed by agent_watcher.go's os.MkdirAll(Dir, 0o755) + cmd.Dir = Dir: MkdirAll no-ops on an existing dir regardless of mode, so a pre-created or symlinked name becomes the cwd of a bash-capable coding agent).
A PID IS NOT ENTROPY: os.Getpid(), uid, hostname, timestamps, runtime.GOOS and unknown helper results are all guessable or known before the fact; that is the whole of CWE-377. The only silence is PROVEN entropy. Silent postures, deliberately:
- the path (or a component of it, or its Join root) is bound to an os.MkdirTemp / os.CreateTemp / t.TempDir result: unique by construction (kiln/db EphemeralSQLite);
- the tail components' assembly provably involves crypto/rand, directly or through locals, same-package helper bodies, or the package-wide provenance of the struct fields feeding the path (processmodule's scratch dir derives from the InstanceID nonce mintInstanceID mints with crypto/rand);
- paths not rooted at the shared temp root: os.TempDir() or a "/tmp" literal as the Join/concat root, or a "/tmp/..." literal — anywhere else is another filesystem's problem;
- os.Remove and reads: an unlink follows no symlink target and leaks nothing, so dev.go's shutdown cleanup stays quiet;
- _test.go files.
Index ¶
Constants ¶
This section is empty.
Variables ¶
var Analyzer = &analysis.Analyzer{
Name: "fixedtmp",
Doc: "forbids constant/pid-named paths under the shared temp root reaching create/mkdir/exec/build sinks: mint the name with os.MkdirTemp/os.CreateTemp, or create it 0700 and refuse a name you do not own",
Run: run,
}
Functions ¶
This section is empty.
Types ¶
This section is empty.