From 3dbd1fb11a11eaf6b6d7417f855e61fa9c3caa27 Mon Sep 17 00:00:00 2001 From: Kartik Kenchi Date: Wed, 15 Jul 2026 13:21:48 +0530 Subject: [PATCH] fix: us secure randomized temporary directories in chart downloader Signed-off-by: Kartik Kenchi --- pkg/cmd/dependency_update_test.go | 11 ++++++++--- pkg/downloader/manager.go | 8 ++++++-- 2 files changed, 14 insertions(+), 5 deletions(-) diff --git a/pkg/cmd/dependency_update_test.go b/pkg/cmd/dependency_update_test.go index f9ff68097..978f7380a 100644 --- a/pkg/cmd/dependency_update_test.go +++ b/pkg/cmd/dependency_update_test.go @@ -206,9 +206,14 @@ func TestDependencyUpdateCmd_DoNotDeleteOldChartsOnError(t *testing.T) { } // Make sure tmpcharts-x is deleted - tmpPath := filepath.Join(dir(chartname), fmt.Sprintf("tmpcharts-%d", os.Getpid())) - if _, err := os.Stat(tmpPath); !errors.Is(err, fs.ErrNotExist) { - t.Fatal("tmpcharts dir still exists") + entries, err := os.ReadDir(dir(chartname)) + if err != nil { + t.Fatal(err) + } + for _, entry := range entries { + if entry.IsDir() && strings.HasPrefix(entry.Name(), "tmpcharts-") { + t.Fatalf("tmpcharts directory still exists: %s", entry.Name()) + } } } diff --git a/pkg/downloader/manager.go b/pkg/downloader/manager.go index 683f96007..cb25670e9 100644 --- a/pkg/downloader/manager.go +++ b/pkg/downloader/manager.go @@ -249,7 +249,6 @@ func (m *Manager) downloadAll(deps []*chart.Dependency) error { } destPath := filepath.Join(m.ChartPath, "charts") - tmpPath := filepath.Join(m.ChartPath, fmt.Sprintf("tmpcharts-%d", os.Getpid())) // Check if 'charts' directory is not actually a directory. If it does not exist, create it. if fi, err := os.Stat(destPath); err == nil { @@ -265,9 +264,14 @@ func (m *Manager) downloadAll(deps []*chart.Dependency) error { } // Prepare tmpPath - if err := os.MkdirAll(tmpPath, 0o755); err != nil { + tmpPath, err := os.MkdirTemp(m.ChartPath, "tmpcharts-*") + if err != nil { return err } + // Maintain compatibility with existing permissions + if err := os.Chmod(tmpPath, 0o755); err != nil && m.Debug { + fmt.Fprintf(m.Out, "warning: failed to set permissions on temporary directory %s: %v\n", tmpPath, err) + } defer os.RemoveAll(tmpPath) fmt.Fprintf(m.Out, "Saving %d charts\n", len(deps))