mirror of
https://github.com/daijro/camoufox.git
synced 2026-10-04 08:00:19 +00:00
The fpgen model was staged in tempfile.mkdtemp() and os.replace'd into fpgen's data directory, and an extracted GeoIP database was unpacked in tempfile.TemporaryDirectory() and shutil.move'd into the cache. Since Python 3.13, mkdtemp() on Windows creates an owner-only directory, and a file moved out of it on the same volume keeps that ACL. So a model or database installed from an elevated shell (or over SSH, which is elevated) could not be read by the same user unelevated, or by any other account: the launch failed with "fpgen's model directory is not writable by this user", though the failure was a read. Found on Windows 11 with camoufox 0.5.7b5 under Python 3.14. Add pkgman.write_atomic(): write a temporary file beside the destination, so it takes the directory's permissions, then os.replace it into place. The model's members are all verified before any is written, as before. The permission error now names the file and says how to recover from a model another account installed. Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>