aboutsummaryrefslogtreecommitdiff
path: root/internal/apply/fs.go
diff options
context:
space:
mode:
Diffstat (limited to 'internal/apply/fs.go')
-rw-r--r--internal/apply/fs.go15
1 files changed, 7 insertions, 8 deletions
diff --git a/internal/apply/fs.go b/internal/apply/fs.go
index 56737e8..a8feccc 100644
--- a/internal/apply/fs.go
+++ b/internal/apply/fs.go
@@ -108,13 +108,12 @@ func moveFile(src, dst string) error {
if err := os.MkdirAll(filepath.Dir(dst), 0o755); err != nil {
return err
}
- // Item 16 (fix round 2026-09-12, plan 5 Task 2): this guard must hold
- // independently of runFileStep's own pre-check, layered rather than
- // moved - the exact arrangement that produced plan 4's Task 5 Critical,
- // where a helper that replaced silently was trusted because some caller
- // had checked. Placed immediately before the operation that would
- // otherwise clobber dst, the same way copyFile's own guard sits right
- // before its rename into place.
+ // This guard must hold independently of runFileStep's own pre-check,
+ // layered rather than moved: trusting that some caller already checked
+ // is exactly what lets a silently replacing helper cause harm. Placed
+ // immediately before the operation that would otherwise clobber dst,
+ // the same way copyFile's own guard sits right before its rename into
+ // place.
if err := refuseIfExists(dst); err != nil {
return err
}
@@ -132,7 +131,7 @@ func moveFile(src, dst string) error {
}
// renameFile renames src to dst, refusing on its own when dst already
-// exists rather than trusting that a caller checked first (item 16, same
+// exists rather than trusting that a caller checked first (the same
// reasoning as moveFile's guard above): a bare os.Rename silently replaces
// an occupied destination, and runFileStep's own pre-check must not be the
// only thing standing between a rename step and that.