Restrict configuration file permissions on POSIX

- Set configuration permissions to 0600 before reading and log adjustments.
- Log chmod failures and continue loading; leave Windows permissions unchanged.
This commit is contained in:
Dominik Jain authored and Dominik Jain committed 2026-09-17 16:12:58 +02:00
1 parent 5a2063fc3a
commit b2f8f14b2e
1 file changed
+12
+12
View File
@@ -7,6 +7,7 @@ import dataclasses
import os
import re
import shutil
import stat
import threading
from collections.abc import Iterator, Sequence
from copy import deepcopy
@@ -1122,6 +1123,17 @@ class SerenaConfig(SharedConfig, ModeSelectionDefinitionWithBaseModes):
log.info(f"Serena configuration file not found at {config_file_path}, autogenerating...")
cls._generate_config_file(config_file_path)
# restrict access to the owner's read/write permissions (as the config file contains secrets)
if os.name == "posix":
current_mode = stat.S_IMODE(os.stat(config_file_path).st_mode)
if current_mode != 0o600:
try:
os.chmod(config_file_path, 0o600)
except Exception as e:
log.error("Failed to restrict permissions of Serena configuration %s to 0600: %s", config_file_path, e)
else:
log.info("Changed permissions of Serena configuration %s from %04o to 0600", config_file_path, current_mode)
# load the configuration
log.info(f"Loading Serena configuration from {config_file_path}")
try: