securetemp

package
v0.1.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 27, 2026 License: MIT Imports: 6 Imported by: 0

Documentation

Overview

Package securetemp resolves ctxcop's shared temp parent under a check that the current user controls it.

Index

Constants

View Source
const DirName = "ctxcop"

DirName is the shared parent under os.TempDir(). SessionEnd sweeps it for per-invocation subdirectories, so it has to stay a single known path.

Variables

This section is empty.

Functions

func Dir

func Dir(pattern string) (string, error)

Dir returns a fresh per-invocation directory for redacted copies.

It prefers the shared parent so SessionEnd can sweep it, but falls back to an unpredictable directory directly under os.TempDir() when that parent fails validation. The fallback matters: callers treat an error here as "skip the redaction" and pass the ORIGINAL file through, so failing closed on a hostile parent would hand the agent the raw secret — strictly worse than the redirection #82 is about. The fallback name is random, so it can't be pre-planted.

func Parent

func Parent() (string, error)

Parent returns the validated shared parent, creating it if absent.

The redacted copies written beneath it are the plaintext-minus-secrets view of files the agent read, so a parent another user controls redirects them. os.MkdirAll would silently accept a pre-planted symlink; os.Mkdir plus an Lstat rejects one. (#82)

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL