Skip to content

CL-9386: runtime-denylist the active --config path holding skip - #1187

Merged
TheGreatAxios merged 4 commits into
mainfrom
cl-9386-runtime-denylist-the-active-config-path-holding-skip
Sep 27, 2026
Merged

TheGreatAxios merged 4 commits into
mainfrom
cl-9386-runtime-denylist-the-active-config-path-holding-skip

Conversation

@TheGreatAxios

Copy link
Copy Markdown
Collaborator

Implements CL-9386 (warden finding on PR #1169): an operator-chosen --config path inside the workspace is model-readable/writable while carrying standing skip-permissions. The docs honestly disclosed this; now it is enforced.

Chosen shape

Runtime exact-path extras on the secret-guard plugin, not a warning and not a new static pattern:

  • secretGuardPlugin({ extraDeniedPaths }) hard-denies path-keyed reads AND writes (both middleware loops), lexical + realpath legs (CL-6971 floor), even under --dangerously-skip-permissions — the active custom path is treated exactly like the default settings file. The static denylist is untouched (default machine-wide behavior unchanged and pinned by test).
  • buildCorePosixToolPlugins({ secretGuardExtraDeniedPaths }) forwards it; TUI (session.ts) and exec (runner.ts) entry points pass [config.globalSettingsPath]; workers inherit it down the dispatch chain (tools.ts fleet deps → agent-fleet.ts nested dispatch + run params → run.ts).
  • createCodexReadRawFile enforces the same list for apply_patch's Update-File raw-read leg, which bypasses the plugin middleware chain by design.
  • Docs (ARCHITECTURE.md, IMPLEMENTATION.md, PRODUCT.md) move past disclosure into guarantee.

Deliberate non-goals (parity with the default file, not new systems): shell references to the custom path follow the existing permission gate (ask unless yolo) — under persisted yolo, shell can already show the default settings file, so this is at parity; @mention stays operator-consented per-read; content-search exfiltration of in-workspace secret files is a pre-existing accepted residual of the static guard and is unchanged.

Verification

  • RED first: src/plugins/secret-guard-config-denylist.test.ts committed red (6 fail: custom config readable/writable in yolo+normal; 2 pins passed throughout).
  • bun run typecheck — exit 0
  • Targeted suites (secret-guard x5, posix-tool-plugins, apply-patch-diff, agent-fleet, config) — green
  • Full bun test ./src ./tests ./evals ./scripts --randomize --seed 424242 — 8039 pass, 0 fail, exit 0
  • bun run lint (oxfmt + oxlint) — exit 0

Related: PR #1169 (open) makes /yolo persist the active settings source, which is the live persistence path this protects; this PR is based on main and touches no #1169 code. Do not merge per dispatch (leave for review).

@github-actions

github-actions Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA.
Posted by the CLA Assistant Lite bot.

@linear-code

linear-code Bot commented Sep 26, 2026

Copy link
Copy Markdown

CL-9386

@TheGreatAxios
TheGreatAxios force-pushed the cl-9386-runtime-denylist-the-active-config-path-holding-skip branch from 4c9de52 to e3b27a0 Compare September 27, 2026 22:34
@TheGreatAxios
TheGreatAxios force-pushed the cl-9386-runtime-denylist-the-active-config-path-holding-skip branch from e3b27a0 to b600e99 Compare September 27, 2026 22:40
@TheGreatAxios
TheGreatAxios enabled auto-merge (squash) September 27, 2026 22:41
@TheGreatAxios
TheGreatAxios merged commit 21e9a1a into main Sep 27, 2026
12 of 13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant