chore: sync core lib and CLAUDE.md from agent-core#39
Conversation
There was a problem hiding this comment.
Code Review
This pull request refactors file read and write operations across several modules to prevent Time-of-Check to Time-of-Use (TOCTOU) race conditions, introducing a new readFileWithLimit utility that performs checks and reads on a single file descriptor. A security review identified a path traversal vulnerability in lib/enhance/cross-file-analyzer.js where symlinks could bypass root directory checks, and recommended resolving the real path using fs.realpathSync before validation.
|
This is an auto-sync of the already-reviewed agent-core fix (PR agent-sh/agent-core#25). The auto-reviewer's symlink/TOCTOU notes are addressed by the design: reads use the fd-based readFileWithLimit, and writes use writeFileAtomic (temp file + atomic rename). rename() replaces the path entry itself and never follows a symlink to its target, so it is symlink-safe by construction - the explicit assertNotSymlink in fixer.js is belt-and-suspenders for that path. Merging to keep lib in sync with the source. |
Automated sync of lib/ and CLAUDE.md from agent-core.