fix(utils): writers that published through mkstemp on main keep NEW files at 0600

0dfb4234 made every mode-less atomic write follow the process umask for NEW
targets, restoring what open("w")-based writers did. Ten of the folded sites
were not open("w") writers: they created the file through mkstemp and never
chmod'd, so on main a fresh file was 0600 regardless of umask (bot mailboxes,
relay inbox, turn markers, sessions.json, cron jobs/output, banner snapshot,
plugin toolset cache, presets, shell hooks, install id). CI caught the loosening
in tests/tools/test_bot_live_owner_delivery.py (st_mode 0o077 bits set).

Pass mode=0o600 explicitly at those ten sites; the umask default stays for the
sites that were open("w") on main. Invariant test exercises two real writers.
This commit is contained in:
teknium1
2026-09-13 00:26:43 -07:00
committed by Teknium
parent 602801baa1
commit 9b6dcad91d
11 changed files with 33 additions and 11 deletions
+1 -1
View File
@@ -1627,7 +1627,7 @@ def _persist_plugin_toolset_keys() -> None:
portable = sorted(get_plugin_manager().get_portable_mcp_servers())
except Exception:
portable = []
atomic_json_write(_plugin_toolset_keys_cache_path(), {"toolset_keys": keys, "portable_mcp": portable}, indent=None)
atomic_json_write(_plugin_toolset_keys_cache_path(), {"toolset_keys": keys, "portable_mcp": portable}, indent=None, mode=0o600)
except Exception:
logger.debug("plugin toolset key persist failed", exc_info=True)