CL-9386: runtime-denylist the active --config path holding skip - #1187
Open
TheGreatAxios wants to merge 4 commits into
Open
TheGreatAxios wants to merge 4 commits into
TheGreatAxios wants to merge 4 commits into
Conversation
Contributor
|
Thank you for your contribution to Corbits Code. Before it can be merged, please read our Contributor License Agreement and sign it by posting a new comment on this pull request containing exactly the line below (nothing else): I have read the CLA Document and I hereby sign the CLA corbits-builder seems not to be a GitHub user. You need a GitHub account to be able to sign the CLA. If you have already a GitHub account, please add the email address used for this commit to your account. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Implements CL-9386 (warden finding on PR #1169): an operator-chosen
--configpath inside the workspace is model-readable/writable while carrying standing skip-permissions. The docs honestly disclosed this; now it is enforced.Chosen shape
Runtime exact-path extras on the secret-guard plugin, not a warning and not a new static pattern:
secretGuardPlugin({ extraDeniedPaths })hard-denies path-keyed reads AND writes (both middleware loops), lexical + realpath legs (CL-6971 floor), even under--dangerously-skip-permissions— the active custom path is treated exactly like the default settings file. The static denylist is untouched (default machine-wide behavior unchanged and pinned by test).buildCorePosixToolPlugins({ secretGuardExtraDeniedPaths })forwards it; TUI (session.ts) and exec (runner.ts) entry points pass[config.globalSettingsPath]; workers inherit it down the dispatch chain (tools.tsfleet deps →agent-fleet.tsnested dispatch + run params →run.ts).createCodexReadRawFileenforces the same list for apply_patch's Update-File raw-read leg, which bypasses the plugin middleware chain by design.ARCHITECTURE.md,IMPLEMENTATION.md,PRODUCT.md) move past disclosure into guarantee.Deliberate non-goals (parity with the default file, not new systems): shell references to the custom path follow the existing permission gate (ask unless yolo) — under persisted yolo, shell can already show the default settings file, so this is at parity;
@mentionstays operator-consented per-read; content-search exfiltration of in-workspace secret files is a pre-existing accepted residual of the static guard and is unchanged.Verification
src/plugins/secret-guard-config-denylist.test.tscommitted red (6 fail: custom config readable/writable in yolo+normal; 2 pins passed throughout).bun run typecheck— exit 0bun test ./src ./tests ./evals ./scripts --randomize --seed 424242— 8039 pass, 0 fail, exit 0bun run lint(oxfmt + oxlint) — exit 0Related: PR #1169 (open) makes /yolo persist the active settings source, which is the live persistence path this protects; this PR is based on main and touches no #1169 code. Do not merge per dispatch (leave for review).