MCPcopy Create free account
hub / github.com/DeusData/codebase-memory-mcp / diag_open_private_stats_file

Function diag_open_private_stats_file

src/foundation/diagnostics.c:152–187  ·  view source on GitHub ↗

Create the stats file at its fixed, discoverable path without ever writing * through something another process planted there. Exclusive creation IS the * guarantee, so the predictable name stays safe: the unlink drops a stale file * from an earlier run with this pid (and, if a local attacker pre-created a * symlink, removes the link itself — never its target), and the O_EXCL create * that fol

Source from the content-addressed store, hash-verified

150 * O_NOFOLLOW is belt-and-braces for the same window on POSIX. Mode 0600: the
151 * snapshot describes this process's heap layout, so it is owner-only. */
152static FILE *diag_open_private_stats_file(const char *path) {
153 (void)cbm_unlink(path);
154#ifdef _WIN32
155 /* _wopen mirrors cbm_mkstemp's Windows contract — the ANSI CRT interprets
156 * the UTF-8 bytes of a non-ASCII %TEMP% in the local codepage and fails. */
157 wchar_t *wide = cbm_path_to_wide(path);
158 if (!wide) {
159 return NULL;
160 }
161 int descriptor = _wopen(wide, _O_WRONLY | _O_CREAT | _O_EXCL | _O_BINARY | _O_NOINHERIT,
162 _S_IREAD | _S_IWRITE);
163 free(wide);
164 if (descriptor < 0) {
165 return NULL;
166 }
167 FILE *sink = _fdopen(descriptor, "wb");
168 if (!sink) {
169 (void)_close(descriptor);
170 }
171 return sink;
172#else
173 int flags = O_WRONLY | O_CREAT | O_EXCL | O_CLOEXEC;
174#ifdef O_NOFOLLOW
175 flags |= O_NOFOLLOW;
176#endif
177 int descriptor = open(path, flags, 0600);
178 if (descriptor < 0) {
179 return NULL;
180 }
181 FILE *sink = fdopen(descriptor, "wb");
182 if (!sink) {
183 (void)close(descriptor);
184 }
185 return sink;
186#endif
187}
188
189static void diag_write_allocator_stats(void) {
190 char flag[CBM_SZ_16];

Callers 1

Calls 2

cbm_unlinkFunction · 0.85
cbm_path_to_wideFunction · 0.85

Tested by

no test coverage detected