If chmod fails (e.g., permission denied, read-only filesystem), the operation silently continues with incorrect permissions
If chown fails (e.g., not running as root), the operation silently continues with wrong ownership
Users will not be notified that metadata restoration failed, which could lead to security issues (wrong file permissions)
Fix: Check return values and log warnings/errors when metadata restoration fails.
Severity: high
In `src/shared/metadata.c`, the return values of security-critical system calls are silently discarded:
**Line 99:** `chmod()` return value ignored
```c
chmod(path, metadata->mode & 07777);
```
**Line 100-101:** `chown()` return value explicitly suppressed
```c
int chown_ret = chown(path, metadata->uid, metadata->gid);
(void)chown_ret;
```
This means:
1. If `chmod` fails (e.g., permission denied, read-only filesystem), the operation silently continues with incorrect permissions
2. If `chown` fails (e.g., not running as root), the operation silently continues with wrong ownership
3. Users will not be notified that metadata restoration failed, which could lead to security issues (wrong file permissions)
**Fix:** Check return values and log warnings/errors when metadata restoration fails.
**Severity:** high
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
In
src/shared/metadata.c, the return values of security-critical system calls are silently discarded:Line 99:
chmod()return value ignoredLine 100-101:
chown()return value explicitly suppressedThis means:
chmodfails (e.g., permission denied, read-only filesystem), the operation silently continues with incorrect permissionschownfails (e.g., not running as root), the operation silently continues with wrong ownershipFix: Check return values and log warnings/errors when metadata restoration fails.
Severity: high