Skip to content

Commit 6ccb875

Browse files
fix: eliminate TOCTOU race in yamlio.load_yaml()
Remove exists() pre-check and catch FileNotFoundError from read_text() to provide a clear BundlerError even under race conditions.
1 parent 5e2f9bc commit 6ccb875

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

‎src/specify_cli/bundler/lib/yamlio.py‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -54,10 +54,10 @@ def load_yaml(path: Path) -> Any:
5454
caller to reject.
5555
"""
5656
path = Path(path)
57-
if not path.exists():
58-
raise BundlerError(f"File not found: {path}")
5957
try:
6058
text = path.read_text(encoding="utf-8")
59+
except FileNotFoundError:
60+
raise BundlerError(f"File not found: {path}") from None
6161
except (OSError, UnicodeError) as exc:
6262
# A non-UTF-8 file raises UnicodeDecodeError, which is a ValueError --
6363
# NOT an OSError -- so it escaped this module's "IO failures degrade

0 commit comments

Comments
 (0)