MCPcopy Create free account
hub / github.com/DeusData/codebase-memory-mcp / posix_directory_parent_secure

Function posix_directory_parent_secure

src/daemon/ipc.c:1379–1388  ·  view source on GitHub ↗

Source from the content-addressed store, hash-verified

1377}
1378
1379static bool posix_directory_parent_secure(int directory_fd) {
1380 struct stat status;
1381 if (directory_fd < 0 || fstat(directory_fd, &status) != 0 || !S_ISDIR(status.st_mode) ||
1382 !posix_directory_owner_trusted(status.st_uid) ||
1383 !cbm_macos_extended_acl_fd_is_deny_only(directory_fd)) {
1384 return false;
1385 }
1386 return (status.st_mode & 0022) == 0 ||
1387 (status.st_uid == (uid_t)0 && (status.st_mode & S_ISVTX) != 0);
1388}
1389
1390/* Validate a path transition only through the two already-open directory
1391 * handles. A group/other-writable parent is unsafe unless it is the standard

Callers 2

Tested by

no test coverage detected