Skip to content

feat(files): configure a trusted upload and output root - #935

Closed
ratovarius wants to merge 3 commits into
googleworkspace:mainfrom
ratovarius:feat/scoped-file-roots
Closed

feat(files): configure a trusted upload and output root#935
ratovarius wants to merge 3 commits into
googleworkspace:mainfrom
ratovarius:feat/scoped-file-roots

Conversation

@ratovarius

@ratovarius ratovarius commented Sep 11, 2026

Copy link
Copy Markdown

Description

File flags currently confine files to the process working directory, making it awkward to export or upload from a separate review workspace. Add trusted environment setting GOOGLE_WORKSPACE_CLI_FILE_ROOT to select the allowed boundary for --output and --upload. Relative arguments still resolve from the current directory, and the default remains current-directory confinement. Canonicalization rejects escapes, dangling symlinks, and invalid parents.

Related to #743.

Fixes ratovarius#5.

Scope and dependencies

This setting is optional: callers that keep input/output files under the current directory retain existing behavior. It does not require the review-bundle companion or any other feature PR. Combining the current branch with #931 conflicts at shared helper/test insertion points in main.rs; preserve both independent helpers and their tests when refreshing the branch.

The only common code included from another contribution is the two-file Clippy fix proposed separately in #930. This PR contains its own copy, so it is self-contained against the current upstream base; it is not a zero-overlap diff. Prefer merging #930 first, then refreshing this branch to remove the duplicate. Each feature has its own changeset.

Validation

Focused validator and real-CLI regressions, all 803 Rust workspace tests under normal, valid-root, and invalid-root environments, formatting, and strict Clippy passed. Coverage includes default confinement, configured roots, symlinks, sibling prefixes, invalid roots, inherited environment, escaped paths, and actual loopback binary output.

Local independent agent review found no outstanding findings; upstream maintainer approval is still pending. Combined validation with the other contributions passed 859 Rust tests, 86 Python tests, 20 CLI acceptance checks, formatting, strict Clippy, and build.

Dry-run output: not applicable to this change.

Limits

The setting applies to explicit file flags, not directory helpers or a process-wide sandbox. Path validation still has the existing validation/open race boundary. Native Windows execution was not available; unsupported canonical path encoding fails explicitly instead of losing an explicit argument.

Checklist

  • Follows AGENTS.md; no generated Google client crates.
  • Formatting check passed.
  • Required strict Clippy check passed.
  • Added regression tests for accepted and rejected cases.
  • Includes a changeset.

@changeset-bot

changeset-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: eea3687

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@googleworkspace/cli Minor

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@google-cla

google-cla Bot commented Sep 11, 2026

Copy link
Copy Markdown

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

@ratovarius

Copy link
Copy Markdown
Author

Closing this proposal by author request to focus the initial upstream contribution on #937 (preserve saved credentials after authentication failures).

This work remains implemented and maintained in the public fork, https://github.com/ratovarius/cli, with tracking in ratovarius#5 and integration in ratovarius#10. Further development of this item will continue in the fork. This closure does not indicate rejection by upstream maintainers.

@ratovarius ratovarius closed this Sep 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: core Core CLI parsing, commands, error handling, utilities area: docs crate: google-workspace

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Configure an explicit trusted root for exported/uploaded files

2 participants