Skip to content

feat: preserve protected native file permissions - #221

Closed
roodboi wants to merge 2 commits into
nextfrom
feat/native-file-permissions
Closed

roodboi wants to merge 2 commits into
nextfrom
feat/native-file-permissions

Conversation

@roodboi

@roodboi roodboi commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Native private file delivery now preserves the requested 0444 config policy and supports protected 0400/0600 secret copies. Snapshot version 1 remains exactly 0444; version 2 must include a protected member and binds its exact saved mode. Unknown versions and permission drift refuse. Original source ownership, permissions and bytes are never changed to make delivery pass.

The current head normally merges next at 7c810a5. Nine of the ten original permission blobs remain byte-identical to 562e8c0; the owner test carries only canonical fixed-stage diagnostics. Current runtime/recovery code and the canonical owned-resource relay test oracle are retained. The historical 562 macOS port-absence failure is preserved; the test correction does not establish a product leak or crash fix.

Validation: original 562 focused/static qualification remains historical evidence. On this reconciliation, the affected owner case passed with diagnostics enabled (1 pass, 31 filtered, 4 assertions); CLI typecheck, nine-file lint, staged privacy, diff and commit-message checks passed. The qualified existing compiler was reused after checking unchanged owning inputs. No unchanged full suite, compiler/CLI build or real engine probe ran. Fresh exact-head CI remains required.

Actual guest UID/GID, granted and ungranted access, read-only writes, linked isolation and retained file adoption/lifecycle/recovery remain separate required gates. This PR grants no retained-file authority. Release intent: optional native snapshot permission support.

Support exact 0444, 0400 and 0600 modes on exclusive private file snapshots.
Keep version 1 limited to 0444 and require protected members for version 2.
Original source permissions remain unchanged; guest and retained-bind
acceptance are separate gates.
Preserve the closed snapshot permission implementation and carry current
canonical ownership, recovery, diagnostics and relay-test corrections.
The prior port-absence failure remains historical test evidence.
@blacksmith-sh

blacksmith-sh Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Found 2 test failures on Blacksmith runners:

Failures

Test View Logs
native-compose-adoption-job-worktrees (22.3s) — Completed-job worktree acceptance refus
ed; values omitted./
native-compose-adoption-job-worktrees (22.3s) — Completed-job worktree acceptance refus
ed; values omitted.
View Logs
native-config-process-policy (7.1s) — Native --profile must succeed/
native-config-process-policy (7.1s) — Native --profile must succeed
View Logs

Fix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need.

@roodboi

roodboi commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

Closing as source consolidation into #227 through #226. The feature commit and all production changes are preserved; the remaining test changes retain their assertions with formatting and an explicit outer allowance. Historical failures remain recorded. Retained-file acceptance remains open in #227, separate from new VM transport #250. Branch retained.

@roodboi roodboi closed this Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant