Files
orca/internal/security/flock.go
T
Jon Chery 19b52f6c9b fix(P24): known_hosts tightening + transport hardening (REQ-139, F15, F25)
---ci---
project: orca
phase: 24
milestone: v0.12
status: execute
---/ci---

Flock now chmod's the file to 0600 after open (tightens pre-existing
looser perms; O_CREATE only sets mode on creation). REQ-139/F15.
classifyDialErr + SSH-exec rate limiting documented as v1.x follow-up
(the transport is deprecated; SSH-push is the primary). Build green.
2026-08-07 11:32:25 +00:00

41 lines
1.2 KiB
Go

package security
import (
"os"
"syscall"
)
// Flock acquires an exclusive advisory lock on the file at path, creating it
// if missing. Returns a release function that MUST be called (deferred) to
// release the lock and close the file descriptor. Used by the known_hosts
// read-modify-write paths (TOFUHostKeyCallback capture + ResetHostKey) to
// prevent concurrent writers under v0.9's parallel SSH fan-out (REQ-063,
// deferred P1 from REVIEW_v0.8 A2).
func Flock(path string) (release func(), err error) {
f, err := os.OpenFile(path, os.O_CREATE|os.O_RDWR, 0o600)
if err != nil {
return nil, err
}
// REQ-139 / F15: tighten pre-existing looser perms to 0600.
// OpenFile with O_CREATE only sets the mode on creation; if the
// file already exists with looser perms, they persist. Chmod
// ensures 0600 regardless.
_ = os.Chmod(path, 0o600)
if err := syscall.Flock(int(f.Fd()), syscall.LOCK_EX); err != nil {
f.Close()
return nil, err
}
return func() {
_ = syscall.Flock(int(f.Fd()), syscall.LOCK_UN)
_ = f.Close()
}, nil
}
func tryFlockEx(fd int) error {
return syscall.Flock(fd, syscall.LOCK_EX|syscall.LOCK_NB)
}
func releaseFlock(fd int) error {
return syscall.Flock(fd, syscall.LOCK_UN)
}