Skip to content

fix: harden file operations against symlink races and fix preserve modes - #2689

Open
valoq wants to merge 4 commits into
gokcehan:masterfrom
valoq:symlink-race
Open

valoq wants to merge 4 commits into
gokcehan:masterfrom
valoq:symlink-race

Conversation

@valoq

@valoq valoq commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Addresses #2688

The copy operation used full path names and resolved them again at every step and also followed encountered symlinks.
Symlinks could be swapped between the checks (which is especially an issue when lf is running as root and coping to a user owned directory)

Copying now works through open directory handles and the symlink issues are avoided.

The solution is modeled after coreutils cp approach, with some (better) changes enabled by golang os.root

This should be tested for a while and get a critical review

Edit:

this also fixes the bug with the preserve=mode option since it touched a lot of related code and no longer made sense to split.

@valoq

valoq commented Oct 4, 2026

Copy link
Copy Markdown
Contributor Author
  • The selected file is now also opened through file descriptor
  • fixed a failed copy when the source is read only
  • error type checks now use errors.AsType
  • fixed the skipped-file error

@valoq

valoq commented Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

@CatsDeservePets I think this is now a solid and significant improvement of the file operations that make things more resilient

It would be great if you could help test this for a wile to make sure I didnt overlook anything.

I know its a larger change but this is the only clean solution that didnt open up new issues when trying o fix the preserver option.

@valoq
valoq marked this pull request as ready for review October 4, 2026 22:28
@valoq valoq changed the title fix: symlink race in file operations fix: harden file operations against symlink races and fix preserve modes Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant