Repository navigation
Fix descriptor-backed artifact thumbnail decoding - #10701
teamleaderleo merged 3 commits into
Conversation
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 4 minutes. View limit detailsLimit details: You’ve used all 10 included reviews currently available. Review configuration: ⚙️ Run configurationConfiguration used: Repository: manaflow-ai/cmux/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (4)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Greptile SummaryThis PR removes a thumbnail-decoding pathname race by retaining the verified regular-file descriptor and giving ImageIO a duplicated, positional-read-backed data provider.
Confidence Score: 5/5The PR appears safe to merge, with descriptor ownership and decode routing consistently preventing pathname replacement from redirecting thumbnail reads. The provider retains a duplicated verified descriptor for ImageIO’s lifetime, uses positional reads instead of reopening the path, and current production callers keep synchronous decoding off the main actor. Important Files Changed
Flowchart%%{init: {'theme': 'neutral'}}%%
flowchart LR
A[Authorized artifact path] --> B[Open nonblocking descriptor]
B --> C[fstat verifies regular file]
C --> D[Retain verified FileHandle]
D --> E[Duplicate descriptor with close-on-exec]
E --> F[CGDataProvider positional pread callbacks]
F --> G[ImageIO thumbnail decode]
G --> H[JPEG thumbnail]
A -. pathname replacement does not redirect decode .-> D
Reviews (1): Last reviewed commit: "fix: decode artifact thumbnails from ver..." | Re-trigger Greptile |
|
Review: no correctness findings in the descriptor-backed thumbnail path or its tests. Fixed: merged current main into the branch. Left: CI validation. |
|
All contributors have signed the CLA ✍️ ✅ |
|
Merge receipt for
|
Summary
ArtifactByteReader’s verified regular-file descriptor open through thumbnail classification and ImageIO decoding.CGDataProviderbacked by a duplicated descriptor and positional reads, so pathname replacement cannot redirect the decode or block on a FIFO.Fixes #8581
Testing
swift test --package-path Packages/Shared/CmuxAgentChat --filter ArtifactByteReaderTests— 18 passed.swift test --package-path Packages/Shared/CmuxAgentChat— 273 passed in 32 suites.de4823744b); the second contains the fix (ee04ffec6f).Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by cubic
Fixes thumbnail decoding to read directly from the verified file descriptor instead of reopening by path. This removes the TOCTOU window that allowed pathname swaps to FIFOs and could block or redirect decoding (fixes #8581).
Bug Fixes
CGDataProviderbacked by a duplicated descriptor with positional reads, usingArtifactImageDataProvider.Written for commit cb12a14. Summary will update on new commits.