moe_trace: create the trace file 0644 and fail if it cannot be written - #153
Conversation
CodeQL cpp/world-writable-file-creation (alert 5): fopen("w") creates with
0666 and leaves the rest to the umask. Open with an explicit 0644, and stop
with a message instead of writing through a null FILE* when the path is bad.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Docs7 for 1bit-monster/engine
Commit |
PR Reviewer Guide 🔍Here are some key observations to aid the review process:
|
Fixes the high-severity alert #5 (
cpp/world-writable-file-creation) from the extended CodeQL suite, which is now on for this repo.fopen(path, "w")creates the file with mode 0666 and leaves the rest to the umask. The trace is now opened with an explicit 0644.FILE*.Checked with
g++ -std=c++17 -fsyntax-onlyagainst the pinned llama.cpp headers.Alert #4 (
cpp/path-injection,1bit comfyrunningONEBIT_COMFYUIor acomfyui_cppfound onPATH) is dismissed as a false positive.1bitisn't setuid, so whoever sets that environment is the user running it. The code already refuses world-writable binaries andfexecves the exact file it checked.🤖 Generated with Claude Code