Skip to content

Commit e1617ce

Browse files
fix: use missing_ok=True in extension ZIP cleanup (#3870)
Replace check-then-act pattern with unlink(missing_ok=True) to eliminate TOCTOU race condition in finally blocks.
1 parent 0a70e5b commit e1617ce

1 file changed

Lines changed: 5 additions & 7 deletions

File tree

‎src/specify_cli/extensions/_commands.py‎

Lines changed: 5 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1144,8 +1144,7 @@ def extension_add(
11441144
force=force,
11451145
)
11461146
finally:
1147-
if archive_path.exists():
1148-
archive_path.unlink()
1147+
archive_path.unlink(missing_ok=True)
11491148

11501149
console.print("\n[green]✓[/green] Extension installed successfully!")
11511150
console.print(f"\n[bold]{_escape_markup(str(manifest.name))}[/bold] (v{_escape_markup(str(manifest.version))})")
@@ -2410,11 +2409,10 @@ def backup_extension_skills(skill_names, *, skills_dir=None):
24102409
# Archive cleanup is housekeeping: never replace an install
24112410
# error or roll back an already committed update because a
24122411
# scanner temporarily locks the download on Windows.
2413-
if archive_path.exists():
2414-
try:
2415-
archive_path.unlink()
2416-
except OSError as error:
2417-
zip_cleanup_error = error
2412+
try:
2413+
archive_path.unlink(missing_ok=True)
2414+
except OSError as error:
2415+
zip_cleanup_error = error
24182416

24192417
# 10. Clean up backup on success. The update has committed at
24202418
# this point, so a locked backup file must not trigger rollback

0 commit comments

Comments
 (0)