dnd kitten: Create regular files with O_EXCL to avoid symlink attacks

This is not really needed as the terminal emulator should be de
duplicating directory entries anyway but no harm in defense in depth.
This commit is contained in:
Kovid Goyal
2026-06-03 12:17:38 +05:30
parent 4aa4a5c056
commit 8996aa798c
2 changed files with 7 additions and 1 deletions

View File

@@ -823,7 +823,7 @@ func (dnd *dnd) on_remote_drop_data(cmd DC) (err error) {
e.item_type = cmd.Xp
switch cmd.Xp {
case 0:
f, err := utils.CreateAt(e.base_dir.handle, e.name, 0o666)
f, err := utils.CreateExclusiveAt(e.base_dir.handle, e.name, 0o666)
if err != nil {
return err
}