Repository navigation
S8/P2.1: path-scoped filesystem grants (read/write roots) - #116
Merged
Merged
Conversation
Close the filesystem half of S8: -allow-caps accepts filesystem:read=<root> and filesystem:write=<root> (repeatable), with coarse filesystem remaining unrestricted. Roots Abs/Clean at parse; VM and AST interpreter deny out-of-root and .. escapes with CAPABILITY_DENIED before I/O; EvalSymlinks on longest existing ancestor. file:// stores need read (and write for put/delete). Process/network/env scoping and SPAWN attenuation remain open; gogen/JS stay coarse; no prod -compile-bc/HFIR flip; #90 stays Partial. Journal: docs/journals/2026-10-06_path_scoped_filesystem.md Co-authored-by: howlcipher <howlcipher@users.noreply.github.com>
howlcipher
commented
Oct 6, 2026
howlcipher
left a comment
Owner
Author
There was a problem hiding this comment.
Dev-lead review (COMMENT only) — Motoko / S8 path-scoped filesystem
Head reviewed: 4a8c5f40d84d7207ac355cd609797f174b386898
Base: a5b7ad941ec269943282897a75952de82be81344 (main)
PR state: draft (left draft; no APPROVE / REQUEST_CHANGES / merge / undraft)
Scope vs claim
Diff matches claimed S8 filesystem half:
internal/capability/grants.go:ParseGrantaccepts repeatablefilesystem:read=<root>/filesystem:write=<root>(Abs/Clean at parse); barefilesystemremains unrestricted alias viaHasUnrestrictedFilesystem.- Fail-closed containment:
filepath.Rel+EvalSymlinks/resolveAncestor; denials return false /CAPABILITY_DENIEDbefore I/O. - Enforcement in
internal/vm/vm.gofor VM + interpreter (requireFilesystemon read/write/mkdir) andfile://stores (open/get/keys need read; put/delete need read+write) viastoreHandle/OpStoreOpen. - Tests present as claimed:
TestParseGrant,TestFilesystemGrantContainment,TestFilesystemScopesVMAndInterpreter,TestFileStoreFilesystemScopes,TestFilesystemScopeReceiptDecision,TestCLIPathScopedFilesystemGrants. - Journal + docs honesty: S8 PARTIAL-closed (process/network still OPEN); Go/JS backends remain coarse; TOCTOU caveat documented.
Hard nos
- Intact. No prod
-compile-bc/ HFIR default flip; journal explicitly keeps #90 Partial. - No live LLM / H1 PASS/KILL claims.
- Expected
internal/grant+VM paths for this slice — not treated as hard-no.
CI
list_check_runs_for_ref / workflow runs for head SHA: none reported yet (empty). Not green from Checks API at review time.
Merge readiness
Conditionally merge-ready on scope/hard-nos. Okabe may undraft and squash-merge when CI green. No code blockers found in this COMMENT pass; do not merge while Checks are absent/red.
Non-blockers / notes
- Write grants intentionally do not imply read (covered by tests).
- Generated backends still coarse — correctly called out as remaining work.
- Symlink TOCTOU called out honestly; not a merge blocker for this slice.
- Receipt path records scoped deny/allow after path checks (spot-checked).
— Motoko (Dev-lead, COMMENT-only)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes the filesystem half of finding S8 / roadmap P2.1: resource-scoped
filesystemgrants so programs cannot read/write outside declared roots.-allow-caps:filesystem:read=<root>,filesystem:write=<root>(repeatable); coarsefilesystemremains the unrestricted alias.internal/capability(ParseGrant,Grants.AllowsRead/AllowsWrite).CAPABILITY_DENIED); path Abs/Clean +filepath.Relcontainment; symlink hardening viaEvalSymlinkson longest existing ancestor.file://stores: open/get/keys need read coverage; put/delete need read and write.docs/journals/2026-10-06_path_scoped_filesystem.md. S8 marked PARTIAL-closed (process/network still OPEN).Out of scope (hard nos)
-compile-bc/ HFIR flip; Write flagged http_server bytecode and stop #90 stays PartialhowlFrameGrantHas("filesystem"))Test plan
gofmt -l .cleango vet ./...go test ./...(passed locally)TestParseGrant,TestFilesystemGrantContainment,TestFilesystemScopesVMAndInterpreter,TestFileStoreFilesystemScopes,TestFilesystemScopeReceiptDecision,TestCLIPathScopedFilesystemGrantsBase tip:
a5b7ad941ec269943282897a75952de82be81344. Do not merge without review.