You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Security
Journal entry operations now fail closed on symbolic links and Windows
junctions anywhere below the workspace root. The configured blog and
entries directories, the generated .vs-journal directory, the index.sqlite3 database and its .corrupt/-journal/-wal/-shm
siblings, every entry subdirectory, and every entry file must be a
real, non-symlink path of the expected type; a link is rejected even
when its target stays inside the workspace. Entry scanning no longer
follows linked files or directories and cannot be sent into a
directory-link cycle, activation reconciliation prunes rows for a
previously real subtree that has been replaced by a link, and the file
watcher, "Rescan All Entries", entry opening, and "New Blog Entry" all
revalidate the physical path immediately before they read, write, open,
index, move, or delete. Passive activation still never creates missing
directories; deliberate creation flows validate each parent and
revalidate each component they create. Linked entry trees remain
unsupported rather than resolved.