Skip to content

🔒 Fix unhandled directory creation failure in PluginResourceLoader#247

Merged
RoiSoleil merged 2 commits into
masterfrom
fix-plugin-resource-loader-mkdir-vuln-10781214918023215248
Apr 28, 2026
Merged

🔒 Fix unhandled directory creation failure in PluginResourceLoader#247
RoiSoleil merged 2 commits into
masterfrom
fix-plugin-resource-loader-mkdir-vuln-10781214918023215248

Conversation

@RoiSoleil
Copy link
Copy Markdown
Contributor

🎯 What: The vulnerability fixed
Addressed an issue where ensureStateExists ignored the return value of mkdir(), which could silently fail to create necessary state directories for user templates.

⚠️ Risk: The potential impact if left unfixed
A directory creation failure would fail silently. The caller would wrongly assume the directory exists, which could lead to exceptions later or undefined behavior, putting operations depending on the user template state at risk.

🛡️ Solution: How the fix addresses the vulnerability
Updated the directory creation code to capture the return value. To improve robustness, mkdirs() is used instead. If the directory creation fails, it handles race conditions by checking !exists(), and logs a descriptive error if the failure persists, returning false to notify the caller of the failure.


PR created automatically by Jules for task 10781214918023215248 started by @RoiSoleil

Co-authored-by: RoiSoleil <3462260+RoiSoleil@users.noreply.github.com>
@google-labs-jules
Copy link
Copy Markdown
Contributor

👋 Jules, reporting for duty! I'm here to lend a hand with this pull request.

When you start a review, I'll add a 👀 emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down.

I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job!

For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with @jules. You can find this option in the Pull Request section of your global Jules UI settings. You can always switch back!

New to Jules? Learn more at jules.google/docs.


For security, I will only act on instructions from the user who triggered this task.

@codecov
Copy link
Copy Markdown

codecov Bot commented Apr 27, 2026

Codecov Report

❌ Patch coverage is 95.83333% with 1 line in your changes missing coverage. Please review.
✅ Project coverage is 73.42%. Comparing base (056906c) to head (f14e152).
⚠️ Report is 14 commits behind head on master.

Files with missing lines Patch % Lines
...ck/src/org/moreunit/mock/PluginResourceLoader.java 75.00% 0 Missing and 1 partial ⚠️
Additional details and impacted files
@@             Coverage Diff              @@
##             master     #247      +/-   ##
============================================
+ Coverage     73.28%   73.42%   +0.14%     
- Complexity     3234     3247      +13     
============================================
  Files           420      422       +2     
  Lines         14435    14489      +54     
  Branches       1266     1268       +2     
============================================
+ Hits          10578    10639      +61     
+ Misses         3325     3316       -9     
- Partials        532      534       +2     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Updated the directory creation code to capture the return value. To improve robustness, `mkdirs()` is used instead. If the directory creation fails, it handles race conditions by checking `!exists()`, and logs a descriptive error if the failure persists, returning `false` to notify the caller of the failure.

Co-authored-by: RoiSoleil <3462260+RoiSoleil@users.noreply.github.com>
@RoiSoleil RoiSoleil merged commit 5ceff50 into master Apr 28, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant