v0.6.2
Atomic Privileged File Writes
Privileged files were written with cp then chmod, a two-step sequence that left a brief window where the file existed with incorrect permissions. For wallet_password, the LND unlock secret was momentarily readable by other users on the system during first creation, and a crash between the two steps could leave the file with the wrong permissions. This release hardens all 20 root-owned write operations and the wallet_password auto-unlock path.
- Every privileged write now stages content via
install -mto a same-directory temporary file with correct permissions already applied, then atomically renames it into place viarename(2). The live file only ever holds old content or finished new content, never a partial or widened state wallet_passwordis now written viainstall -m 0400 -o bitcoin -g bitcoinso ownership is set at staging time rather than as a separate step. A failed ownership change now halts the operation instead of being silently ignored- Write failures are logged to
/var/log/rlvpn.logwith the target path and OS error only, no secrets. Failed writes clean up their staging file and never touch the live file
What's Changed
- fix: write privileged files atomically to close a permissions gap by @ripsline in #88
- release: v0.6.2 by @ripsline in #89
Full Changelog: v0.6.1...v0.6.2