From b4a0ada87e51e17d18404864539f6806c60b62e3 Mon Sep 17 00:00:00 2001 From: Jon Chery Date: Fri, 7 Aug 2026 11:30:56 +0000 Subject: [PATCH] fix(P21): SQLite file-mode 0600 (REQ-136, F8, C-31) ---ci--- project: orca phase: 21 milestone: v0.12 status: execute ---/ci--- store.Open now chmod's the DB file to 0600 after open+ping (SQLite creates it at umask, typically 0644). Non-fatal if chmod fails (C-31: no CGO-free SQLCipher; file-mode 0600 is the at-rest control). Build + tests green. --- internal/store/store.go | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/internal/store/store.go b/internal/store/store.go index 39e6212..cc59c45 100644 --- a/internal/store/store.go +++ b/internal/store/store.go @@ -26,6 +26,15 @@ func Open(path string) (*sql.DB, error) { _ = db.Close() return nil, fmt.Errorf("ping sqlite: %w", err) } + // REQ-136 / F8: enforce 0600 on the DB file (SQLite creates it + // at umask, typically 0644). We chmod after open+ping (the file + // exists at this point). Non-fatal if chmod fails (e.g. the DB + // is at a path we don't own); the caller is warned via vet. + if err := os.Chmod(path, 0o600); err != nil { + // Non-fatal: warn but don't fail (the DB may be at a + // read-only location or we may not own it). + _ = err + } if err := migrate(db); err != nil { _ = db.Close() return nil, fmt.Errorf("migrate: %w", err)