davsclaus commented on code in PR #27162:
URL: https://github.com/apache/camel/pull/27162#discussion_r4153202630


##########
core/camel-support/src/main/java/org/apache/camel/support/processor/state/FileStateRepository.java:
##########
@@ -200,19 +202,43 @@ private void appendToStore(String key, String value) {
      */
     protected void trunkStore() {
         LOG.info("Trunking state filestore: {}", fileStore);
+        // write the 1st level cache to a temporary file and then replace the 
file store with it, so the file store
+        // is never left truncated or half written (such as if writing fails, 
or the JVM crashes while writing)
+        Path target = fileStore.toPath();
+        File tmp = null;
+        boolean written = false;
         FileOutputStream fos = null;
         try {
-            fos = new FileOutputStream(fileStore);
+            if (Files.exists(target)) {
+                // replace the real file of a symlinked store (so the link is 
kept, and the temporary file is on the
+                // same file system as the store)
+                target = target.toRealPath();
+            }
+            tmp = new File(target + ".tmp");
+            fos = new FileOutputStream(tmp);
             for (Map.Entry<String, String> entry : cache.entrySet()) {
-                fos.write(entry.getKey().getBytes());
-                fos.write(KEY_VALUE_DELIMITER.getBytes());
-                fos.write(entry.getValue().getBytes());
-                fos.write(STORE_DELIMITER.getBytes());
+                fos.write((entry.getKey() + KEY_VALUE_DELIMITER + 
entry.getValue() + STORE_DELIMITER).getBytes());
+            }
+            fos.getFD().sync();
+            fos.close();
+            fos = null;
+            // keep the permissions of the store
+            if (Files.exists(target) && Files.getFileAttributeView(target, 
PosixFileAttributeView.class) != null) {
+                Files.setPosixFilePermissions(tmp.toPath(), 
Files.getPosixFilePermissions(target));
+            }

Review Comment:
   The permissions are copied only after the full state has been written to 
`tmp`. Until then the temp file has the umask default (often `rw-r--r--`), so a 
store kept at `rw-------` (for example holding offsets) is briefly readable by 
others. Consider applying the store's permissions to the empty temp file right 
after creating it (before writing), e.g. create the file first, set the 
permissions, then open the stream.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to