Skip to content

capture-file: preserve artifact integrity - #1147

Draft
shunichironomura wants to merge 3 commits into
capture-file-project-containmentfrom
capture-file-audit-integrity
Draft

shunichironomura wants to merge 3 commits into
capture-file-project-containmentfrom
capture-file-audit-integrity

Conversation

@shunichironomura

@shunichironomura shunichironomura commented Jul 22, 2026 •

Copy link
Copy Markdown
Member

Warning

This content was written by an AI agent and must be verified by a human developer. After human verification, this alert may be removed.

Summary

  • Preserve each captured file's project-relative path under its hook artifact directory so same-basename files cannot overwrite each other.
  • Plan and validate all destinations before mutation, and refuse to overwrite existing artifacts.
  • Hash the completed archived bytes; implement move as copy, optional hash, then source removal so open writers cannot mutate the archived inode.
  • Add regression coverage for path collisions, existing destinations, archived hashes, and independent moved artifacts.
  • Update the capture-file documentation and output examples.

Closes #1081.

Validation:

  • just lint
  • just test

AI assistance

  • AI used: yes — an AI coding agent investigated the issue, implemented the changes, added tests, and drafted this description.
  • Human review of AI-assisted code: pending

Breaking changes

  • No breaking changes
  • Breaking changes; the breaking change label is applied

This is part 4 of 4 in a stack made with GitButler:

@codecov-commenter

codecov-commenter commented Jul 22, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 70.64220% with 32 lines in your changes missing coverage. Please review.
✅ Project coverage is 55.51%. Comparing base (1d0437b) to head (be37254).

Files with missing lines Patch % Lines
crates/capsula-capture-file/src/lib.rs 70.64% 32 Missing ⚠️
Additional details and impacted files
@@                         Coverage Diff                          @@
##           capture-file-project-containment    #1147      +/-   ##
====================================================================
+ Coverage                             55.33%   55.51%   +0.17%     
====================================================================
  Files                                    42       42              
  Lines                                  4384     4469      +85     
====================================================================
+ Hits                                   2426     2481      +55     
- Misses                                 1958     1988      +30     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@shunichironomura
shunichironomura force-pushed the capture-file-project-containment branch from 284bbe6 to 1d0437b Compare July 22, 2026 22:53
@shunichironomura
shunichironomura force-pushed the capture-file-audit-integrity branch from e86edc0 to be37254 Compare July 22, 2026 22:54
@shunsuke-shimomura shunsuke-shimomura mentioned this pull request Aug 4, 2026
1 of 2 tasks
@shunichironomura
shunichironomura added this pull request to stack #1271 October 1, 2026 07:53
@shunichironomura
shunichironomura removed this pull request from stack #1271 October 1, 2026 08:24

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

capture-file: hash/copy TOCTOU and flat destination silently corrupt the audit record

2 participants