split: harden output open path against TOCTOU target swaps#11401
Open
can1357 wants to merge 1 commit intouutils:mainfrom
Open
split: harden output open path against TOCTOU target swaps#11401can1357 wants to merge 1 commit intouutils:mainfrom
can1357 wants to merge 1 commit intouutils:mainfrom
Conversation
Merging this PR will improve performance by 3.16%
|
| Mode | Benchmark | BASE |
HEAD |
Efficiency | |
|---|---|---|---|---|---|
| ⚡ | Simulation | split_bytes |
429.8 µs | 416.7 µs | +3.16% |
Comparing can1357:split-harden-output-open-path-against-toctou-target-swaps (23b354d) with main (ef8e45c)
Footnotes
-
48 benchmarks were skipped, so the baseline results were used instead. If they were deleted from the codebase, click here and archive them to remove them from the performance reports. ↩
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
uutils
splitchecks input/output identity by path before opening the output and then opens with truncation, leaving a race window open on mutable path components. GNU opens first and compares the opened output inode against input before truncation.Reproduction Steps
Omitted due to nondeterministic TOCTOU
Impact
The race can cause split to truncate/write a file different from the one validated, including the input file or another file the process can access.