chore: sync core lib and CLAUDE.md from agent-core#40
Conversation
There was a problem hiding this comment.
Code Review
This pull request addresses Time-of-Check to Time-of-Use (TOCTOU) race conditions across several modules by introducing safe file reading and writing utilities. Specifically, it adds readFileWithLimit to open files once and perform size and type checks on the file descriptor, and adopts atomic writes to prevent race conditions. Feedback on the changes suggests that in lib/patterns/slop-analyzers.js, calling fs.openSync and fs.fstatSync on the injected fs object may break existing test mocks that only implement statSync and readFileSync, leading to silent failures. A fallback mechanism is recommended to ensure backward compatibility.
|
This is an auto-sync of the already-reviewed agent-core fix (PR agent-sh/agent-core#25). The auto-reviewer's symlink/TOCTOU notes are addressed by the design: reads use the fd-based readFileWithLimit, and writes use writeFileAtomic (temp file + atomic rename). rename() replaces the path entry itself and never follows a symlink to its target, so it is symlink-safe by construction - the explicit assertNotSymlink in fixer.js is belt-and-suspenders for that path. Merging to keep lib in sync with the source. |
Automated sync of lib/ and CLAUDE.md from agent-core.