Skip to content

Conversation

@JanProvaznik
Copy link
Member

Merging tag v17.8.43 into vs17.8 branch

…directory on every build

Recreate temp on linux using CreateTempSubdirectory on every build

----
#### AI description  (iteration 1)
#### PR Classification
This pull request implements a security bug fix by revising the temporary folder creation mechanism on Linux.

#### PR Summary
The changes modify the creation of the MSBuild temporary folder to use .NET’s built-in Directory.CreateTempSubdirectory method on Linux, ensuring a new subdirectory is recreated on every build. This approach removes the custom native permission logic and fallback routines, thereby mitigating the risk of malicious folder creation.
- `src/Shared/TempFileUtilities.cs`: On Linux, the manual mkdir/chmod logic is replaced with Directory.CreateTempSubdirectory using a fixed prefix.
- `src/Shared/TempFileUtilities.cs`: For other platforms, the temporary path is now combined with the new folder prefix with explicit directory creation.
- `src/Shared/TempFileUtilities.cs`: The custom permission constant (`userRWX`) is removed in favor of secure, built-in directory handling.
<!-- GitOpsUserAgent=GitOps.Apps.Server.pullrequestcopilot -->

----
#### AI description  (iteration 2)
#### PR Classification
This pull request is a security fix addressing a vulnerability in the MSBuild temporary folder creation on Linux.

#### PR Summary
This pull request mitigates a security issue by revising the Linux temporary folder creation process to use a secure subdirectory creation method.
- **`src/Shared/TempFileUtilities.cs`**: Refactored the Linux branch to create a temporary folder with `Directory.CreateTempSubdirectory` using a designated prefix, removing unsafe custom permission checks.
- **`eng/Versions.props`**: Updated the version prefix from 17.8.42 to 17.8.43.

Related work items: #2541147
Copilot AI review requested due to automatic review settings October 15, 2025 12:35
@JanProvaznik JanProvaznik requested a review from a team as a code owner October 15, 2025 12:35
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

Merge of tag v17.8.43 into the vs17.8 branch updating version and adjusting temp directory creation logic.

  • Bumps VersionPrefix to 17.8.43.
  • Refactors temp folder creation logic on Linux to use Directory.CreateTempSubdirectory with a new constant prefix.

Reviewed Changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 4 comments.

File Description
src/Shared/TempFileUtilities.cs Replaces custom Linux temp dir creation logic with Directory.CreateTempSubdirectory and introduces msbuildTempFolderPrefix constant.
eng/Versions.props Updates VersionPrefix from 17.8.42 to 17.8.43.

@dotnet-policy-service
Copy link
Contributor

Hello! I noticed that you're targeting one of our servicing branches. Please consider updating the version.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants