Skip to content

Create the host socket with mode 0600 from the start - #2

Merged
afif-reap merged 1 commit into
mainfrom
afif/chrome-web-store-release
Sep 28, 2026
Merged

afif-reap merged 1 commit into
mainfrom
afif/chrome-web-store-release

Conversation

@afif-reap

Copy link
Copy Markdown
Contributor

The v0.2.1 Release workflow failed on Linux CI in two host tests that pass on macOS:

  • Socket mode: the host set 0600 in its listening callback, so a test that checked the mode as soon as the socket appeared could see the creation mode, 0700. The socket directory is private (0700), so nothing was exposed. The host now binds under a 0o177 umask (the bind inside listen is synchronous), so the socket is 0600 from the moment it exists. The chmod stays as a second guard.
  • Test harness: it wrote to a host's stdin after killing the host, which raised EPIPE. It now ignores that error.

The extension package is unchanged, so the Chrome Web Store submission (0.2.1, pending review) is not affected.

The host set 0600 in its listening callback, so a client could briefly
see the socket at its creation mode. The directory is private, so
nothing was exposed, but Linux CI caught the window. A 0o177 umask
around the synchronous bind closes it. The test harness also ignores a
broken pipe to a host it has just killed.
@afif-reap
afif-reap merged commit 3d9e66a into main Sep 28, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant