.core/reference/fs.go (canonical) + pkg/lib/workspace/default/.core/reference/fs.go (embedded copy): - Write/WriteAtomic/Create/Append default to 0600 - Parent directories use 0700 (was 0755) - WriteMode reapplies the requested mode after writes so overwriting an existing file also tightens permissions Test (pkg/lib/lib_test.go) keeps embedded fs.go synced with canonical + asserts extracted workspaces carry the secure permission defaults. tests/cli/extract copy not hand-edited — that flows from regeneration. Co-authored-by: Codex <noreply@openai.com> Closes tasks.lthn.sh/view.php?id=324 |
||
|---|---|---|
| .. | ||
| agentic | ||
| brain | ||
| lib | ||
| messages | ||
| monitor | ||
| runner | ||
| setup | ||
| .DS_Store | ||