.core/reference/fs.go (canonical) + pkg/lib/workspace/default/.core/reference/fs.go (embedded copy): - Write/WriteAtomic/Create/Append default to 0600 - Parent directories use 0700 (was 0755) - WriteMode reapplies the requested mode after writes so overwriting an existing file also tightens permissions Test (pkg/lib/lib_test.go) keeps embedded fs.go synced with canonical + asserts extracted workspaces carry the secure permission defaults. tests/cli/extract copy not hand-edited — that flows from regeneration. Co-authored-by: Codex <noreply@openai.com> Closes tasks.lthn.sh/view.php?id=324 |
||
|---|---|---|
| .. | ||
| .core/reference | ||
| CLAUDE.md.tmpl | ||
| CODEX-PHP.md.tmpl | ||
| CODEX.md.tmpl | ||
| CONTEXT.md.tmpl | ||
| go.work.tmpl | ||
| PROMPT.md.tmpl | ||
| TODO.md.tmpl | ||