Skip to content

chore(cli): --output silently truncates an existing CSV (A10-010) [cli part] #2050

Description

@cristim

Summary

One low-severity correctness defect confirmed against the audited commit: --output silently truncates an existing CSV.

Findings

  • --output silently truncates an existing CSV (A10-010)
    • Location: cmd/multi_service_csv.go:198 (os.Create); validateFilePaths at cmd/validators.go:213-222 stats only the parent directory; generateCSVFilename returns cfg.CSVOutput verbatim at cmd/multi_service_helpers.go:162-165 at 3c0f8ac
    • Note: Verifier downgraded from medium to low: the audit log remains as the durable purchase record on the main path.
    • Failure scenario: An operator runs cudly --purchase --output run.csv, then re-runs with the same --output while iterating on filters. os.Create truncates the first run's purchase report. The auto-generated filename is timestamped and safe, so the hazard is confined to the explicit-path case. Scope note from the verifier: on the main purchase path the durable record of what was bought is the append-only audit log (cmd/multi_service.go:401-404, pkg/common/audit.go:28, LeanerCloud/cloud-commitments-go), so the CSV is not the only record; the harm holds fully only on the --input-csv path, which writes no audit records.
    • Evidence:
      file, err := os.Create(filepath) // #nosec G304 -- CLI tool: filepath is an operator-supplied output path argument
    • Suggested fix: In validateFilePaths, os.Stat the --output path and refuse when it exists, or open with os.O_CREATE|os.O_EXCL and surface the collision.

Found by the 2026-09-02 codebase audit, finding A10-010, reported by one reviewer and independently confirmed by a second. Full report: docs/audits/codebase-audit-2026-09-02.md.

Scope after the split

Monorepo split: this repo is now CLI-only (cmd/*.go). A05-015, A06-009, A06-019 lived in internal/purchase, internal/server, internal/analytics, which are not in this repo, so they were split out. A06-022 lived in internal/reporter, which moved to pkg/reporter in the go repo, so it was split out too. This issue is now scoped to A10-010 only, which remains this repo's own code.

Sibling issues:

Activity

  1. changed the title [-]chore(purchase/server/analytics/cli): low correctness findings from the 2026-09-02 audit[/-] [+]chore(cli): --output silently truncates an existing CSV (A10-010) [cli part][/+] on Sep 27, 2026
  2. cristim commented on Sep 27, 2026

    @cristim
    MemberAuthor

    Split as part of the CUDly monorepo split. This issue is now scoped to A10-010 only (cmd/multi_service_csv.go, still in this repo). The other findings live outside this repo:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions