Skip to content

fix: create abcd's home private to the account whichever command runs first - #817

Merged
REPPL merged 5 commits into
mainfrom
fix/home-dir-mode
Oct 4, 2026
Merged

REPPL merged 5 commits into
mainfrom
fix/home-dir-mode

Conversation

@REPPL

@REPPL REPPL commented Oct 4, 2026

Copy link
Copy Markdown
Collaborator

Fixes iss-2610032205304585: abcd's home folder was created 0700 by some writers and 0755 by others, the hook's bootstrap included, so whichever command ran first decided whether other accounts on the computer could list it.

What changes

  • internal/abcdhome gains DirMode (0700) and FileMode (0600).
    • Every writer that can create the home or a folder in it hands abcdhome.DirMode: the eight fsutil.EnsureHomeScope writers, the EnsureRealDir(All) writers whose base is the home, and the voyage, transcript, worktree and lab stores' mode constants.
    • The transcript store creates the home on its own, where the scan can judge it.
  • hooks/bootstrap.sh creates the home with mkdir -p -m 0700, for the cache attestation and the path-entry refresh.
    • It sets both path-entry writes to 0600 before moving them into place.
    • The plugin_root re-stamp's temp comes from an in-directory mktemp, as the attestation's does, rather than a predictable name.
  • The path-entry record and the registry's index are written 0600.
    • The index no longer keeps its earlier mode, so one an earlier version wrote 0644 is narrowed at its next write.
  • An existing home keeps its mode, as every home-scope writer's contract says. The residual, recorded in DECISIONS.md, is that other accounts can list an old 0755 home's names, never read a record in it.
  • The ahoy brief chapter states the home's mode.

Tests

Each test below was watched fail first:

  • TestEveryHomeWriterMakesTheHomePrivate: an AST scan of every folder-creating call whose base is the home, failing below a floor of the 14 writers it judges. Its armed twin is TestHomeModeScannerIsArmed.
  • TestHomeWritersMakeTheHomePrivate: 755/644 before the fix.
  • TestBootstrapMakesTheHomePrivate: 755/644 before the fix.
  • TestAnEarlierIndexIsNarrowedAtItsNextWrite.

Planted regressions on scratch copies each fail the scan, naming file and line: a store constant widened to 0755, a home-led MkdirAll at 0755, and the transcript store's home created at 0755.

Review

Two security reviews (Fable).

  • First pass: NEEDS_WORK.
    • The scanner could not see four store writers.
    • Existing installs kept their 0644 records.
    • The re-stamp temp had a predictable name.
  • Re-verification: closed all of these but one, the transcript store's home created inside a loop the scan could not judge. That is fixed here, with the scan's floor pinned to the measured count.

Lands before #815 (noindex steps 3-4), which touches the same files and merges this in.

Resolves: iss-2610032205304585

Assisted-by: Claude:claude-opus-5-5

REPPL added 5 commits October 4, 2026 09:34
… first

abcd's home was created at 0o700 by the credential store and the routing
writers but at 0o755 by the path-entry record, the history registry and the
status-line setting, and the hook's bootstrap made it with the umask, so
whichever ran first decided whether other accounts could list it.

- internal/abcdhome gains DirMode (0o700) and FileMode (0o600). Every
  fsutil.EnsureHomeScope writer, and every EnsureRealDir(All) whose base is
  the home, hands abcdhome.DirMode; the path-entry record and the
  registry's index are written abcdhome.FileMode.
- hooks/bootstrap.sh creates the home with `mkdir -p -m 0700` for the cache
  attestation and the path-entry refresh, and sets the refreshed and the
  re-stamped path-entry to 0600 before moving them into place.
- A folder that already exists keeps its mode, as EnsureHomeScope always has.
- TestEveryHomeWriterMakesTheHomePrivate holds every writer to the one mode
  (watched fail naming the eight writers, then the three home-based store
  creators once the scanner reached them), with its armed twin;
  TestHomeWritersMakeTheHomePrivate and TestBootstrapMakesTheHomePrivate
  watched fail at 755/644 before the fix.
- The ahoy brief chapter states the home's mode.

Refs: iss-2610032205304585
Assisted-by: Claude:claude-opus-5-5
…ach, the re-stamp temp

From the security review of the previous commit (verdict NEEDS_WORK):
- The voyage, transcript, worktree and lab stores declare their folder mode
  as abcdhome.DirMode rather than a local 0o700.
- The registry's index is written abcdhome.FileMode instead of keeping the
  mode it had, so an index an earlier version wrote 0o644 is narrowed at its
  next write; an existing home keeps its mode (DECISIONS.md, 2026-10-04).
- The bootstrap's plugin_root re-stamp writes its temp through an
  in-directory mktemp, as the attestation's does, not a predictable
  "$path_entry.rewrite.$$".
- TestEveryHomeWriterMakesTheHomePrivate judges every folder-creating call
  (EnsureHomeScope, EnsureRealDir(All), CreateRunDir, MkdirAll, Mkdir) whose
  base is a home value, a home local, abcdhome.Path or a local assigned from
  it; it accepts a package name declared as abcdhome.DirMode, and fails if it
  judges fewer than the eleven writers the tree holds. A scratch copy with
  voyageDirPerm = 0o755 and a planted MkdirAll(abcdhome.Path(home, "x"),
  0o755) failed it naming both; TestAnEarlierIndexIsNarrowedAtItsNextWrite
  failed at 644 on a copy without the index change.

Refs: iss-2610032205304585
Assisted-by: Claude:claude-opus-5-5
…anner's floor

From the re-verification of the previous commit: history.Resolve created
~/.abcd as the first level of a chain it walked with its store constant,
which the scanner could not judge, so a widened constant there passed. The
home is now created first and on its own with abcdhome.DirMode, where the
scanner judges it (a scratch copy handing 0o755 there failed naming
location.go:161). The floor is the measured count of judged writers, 14.

Refs: iss-2610032205304585
Assisted-by: Claude:claude-opus-5-5
Assisted-by: Claude:claude-opus-5-5
…r command creates it

Resolves: iss-2610032205304585
Assisted-by: Claude:claude-opus-5-5
@REPPL
REPPL enabled auto-merge October 4, 2026 11:56
@REPPL
REPPL added this pull request to the merge queue Oct 4, 2026
Merged via the queue into main with commit fe528bf Oct 4, 2026
13 checks passed
@REPPL
REPPL deleted the fix/home-dir-mode branch October 4, 2026 13:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant