fix: create abcd's home private to the account whichever command runs first - #817
Merged
Merged
Conversation
… first abcd's home was created at 0o700 by the credential store and the routing writers but at 0o755 by the path-entry record, the history registry and the status-line setting, and the hook's bootstrap made it with the umask, so whichever ran first decided whether other accounts could list it. - internal/abcdhome gains DirMode (0o700) and FileMode (0o600). Every fsutil.EnsureHomeScope writer, and every EnsureRealDir(All) whose base is the home, hands abcdhome.DirMode; the path-entry record and the registry's index are written abcdhome.FileMode. - hooks/bootstrap.sh creates the home with `mkdir -p -m 0700` for the cache attestation and the path-entry refresh, and sets the refreshed and the re-stamped path-entry to 0600 before moving them into place. - A folder that already exists keeps its mode, as EnsureHomeScope always has. - TestEveryHomeWriterMakesTheHomePrivate holds every writer to the one mode (watched fail naming the eight writers, then the three home-based store creators once the scanner reached them), with its armed twin; TestHomeWritersMakeTheHomePrivate and TestBootstrapMakesTheHomePrivate watched fail at 755/644 before the fix. - The ahoy brief chapter states the home's mode. Refs: iss-2610032205304585 Assisted-by: Claude:claude-opus-5-5
…ach, the re-stamp temp From the security review of the previous commit (verdict NEEDS_WORK): - The voyage, transcript, worktree and lab stores declare their folder mode as abcdhome.DirMode rather than a local 0o700. - The registry's index is written abcdhome.FileMode instead of keeping the mode it had, so an index an earlier version wrote 0o644 is narrowed at its next write; an existing home keeps its mode (DECISIONS.md, 2026-10-04). - The bootstrap's plugin_root re-stamp writes its temp through an in-directory mktemp, as the attestation's does, not a predictable "$path_entry.rewrite.$$". - TestEveryHomeWriterMakesTheHomePrivate judges every folder-creating call (EnsureHomeScope, EnsureRealDir(All), CreateRunDir, MkdirAll, Mkdir) whose base is a home value, a home local, abcdhome.Path or a local assigned from it; it accepts a package name declared as abcdhome.DirMode, and fails if it judges fewer than the eleven writers the tree holds. A scratch copy with voyageDirPerm = 0o755 and a planted MkdirAll(abcdhome.Path(home, "x"), 0o755) failed it naming both; TestAnEarlierIndexIsNarrowedAtItsNextWrite failed at 644 on a copy without the index change. Refs: iss-2610032205304585 Assisted-by: Claude:claude-opus-5-5
…anner's floor From the re-verification of the previous commit: history.Resolve created ~/.abcd as the first level of a chain it walked with its store constant, which the scanner could not judge, so a widened constant there passed. The home is now created first and on its own with abcdhome.DirMode, where the scanner judges it (a scratch copy handing 0o755 there failed naming location.go:161). The floor is the measured count of judged writers, 14. Refs: iss-2610032205304585 Assisted-by: Claude:claude-opus-5-5
Assisted-by: Claude:claude-opus-5-5
…r command creates it Resolves: iss-2610032205304585 Assisted-by: Claude:claude-opus-5-5
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes iss-2610032205304585: abcd's home folder was created 0700 by some writers and 0755 by others, the hook's bootstrap included, so whichever command ran first decided whether other accounts on the computer could list it.
What changes
internal/abcdhomegainsDirMode(0700) andFileMode(0600).abcdhome.DirMode: the eightfsutil.EnsureHomeScopewriters, theEnsureRealDir(All)writers whose base is the home, and the voyage, transcript, worktree and lab stores' mode constants.hooks/bootstrap.shcreates the home withmkdir -p -m 0700, for the cache attestation and the path-entry refresh.plugin_rootre-stamp's temp comes from an in-directorymktemp, as the attestation's does, rather than a predictable name.Tests
Each test below was watched fail first:
TestEveryHomeWriterMakesTheHomePrivate: an AST scan of every folder-creating call whose base is the home, failing below a floor of the 14 writers it judges. Its armed twin isTestHomeModeScannerIsArmed.TestHomeWritersMakeTheHomePrivate: 755/644 before the fix.TestBootstrapMakesTheHomePrivate: 755/644 before the fix.TestAnEarlierIndexIsNarrowedAtItsNextWrite.Planted regressions on scratch copies each fail the scan, naming file and line: a store constant widened to 0755, a home-led
MkdirAllat 0755, and the transcript store's home created at 0755.Review
Two security reviews (Fable).
Lands before #815 (noindex steps 3-4), which touches the same files and merges this in.
Resolves: iss-2610032205304585
Assisted-by: Claude:claude-opus-5-5