Skip to content

security: bound and validate discovered project configuration - #419

Merged
codeforester merged 65 commits into
mainfrom
security/385-20261003-security-validate-trust-of-ancestor-discovered-project-confi
Oct 5, 2026
Merged

codeforester merged 65 commits into
mainfrom
security/385-20261003-security-validate-trust-of-ancestor-discovered-project-confi

Conversation

@codeforester

@codeforester codeforester commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

The convenience profile now bounds ancestor discovery, stops at project/filesystem boundaries, and validates discovered configuration permissions and path components before loading. Project environment files receive the same gate. An explicit opt-out supports knowingly shared workspaces; the Windows ACL limitation is documented.

YAML input is capped at 1 MiB and its composed graph is bounded before constructors expand merge aliases. Generic-profile behavior and merge precedence remain unchanged.

Fixes #385.

Branch maintenance

Refs #426. Targets the branch for #418. Retarget and refresh after that parent is squash-merged; preserve the ordered stack.

The branch was refreshed without rewriting history to include main at a576cc279739eae5e4cfc33ffab2a7fb56de24de.

Current-head validation

At 9012457f37a30f73ef54074cc65a3d85298f2580: uv lock freshness and baseline, runtime, strict typing, style, and contracts passed locally with all declared extras. Runtime result: 626 passed, 1 warning, 262 subtests passed in 9.20s.

Hosted checks: 7/7 required checks passed; 0 checks pending; 0 unsuccessful checks at 2026-10-04T14:19:40.760978+00:00. See the PR Checks tab and #426 for subsequent results.

…07-us-record-about-20x-stdlib' into bug/378-20261003-bug-run-bundle-retention-is-inoperative-on-native-windows
…e-on-native-windows' into enhancement/386-20261003-perf-retention-serializes-concurrent-invocations-on-an-untim
…urrent-invocations-on-an-untim' into security/385-20261003-security-validate-trust-of-ancestor-discovered-project-confi
…ff-check-and-mypy-do-not-cover-the-compatibility-consum
…-compatibility-consum' into bug/387-20261003-bug-configure-logger-closes-consumer-owned-handlers-and-forc
…wned-handlers-and-forc' into enhancement/381-20261003-perf-lifecycle-logging-costs-107-us-record-about-20x-stdlib
…07-us-record-about-20x-stdlib' into bug/378-20261003-bug-run-bundle-retention-is-inoperative-on-native-windows
…e-on-native-windows' into enhancement/386-20261003-perf-retention-serializes-concurrent-invocations-on-an-untim
…urrent-invocations-on-an-untim' into security/385-20261003-security-validate-trust-of-ancestor-discovered-project-confi
…07-us-record-about-20x-stdlib' into bug/378-20261003-bug-run-bundle-retention-is-inoperative-on-native-windows
…e-on-native-windows' into enhancement/386-20261003-perf-retention-serializes-concurrent-invocations-on-an-untim
…urrent-invocations-on-an-untim' into security/385-20261003-security-validate-trust-of-ancestor-discovered-project-confi
…-compatibility-consum' into bug/387-20261003-bug-configure-logger-closes-consumer-owned-handlers-and-forc
…wned-handlers-and-forc' into enhancement/381-20261003-perf-lifecycle-logging-costs-107-us-record-about-20x-stdlib
…07-us-record-about-20x-stdlib' into bug/378-20261003-bug-run-bundle-retention-is-inoperative-on-native-windows
…e-on-native-windows' into enhancement/386-20261003-perf-retention-serializes-concurrent-invocations-on-an-untim
…urrent-invocations-on-an-untim' into security/385-20261003-security-validate-trust-of-ancestor-discovered-project-confi
…fecycle-logging-costs-107-us-record-about-20x-stdlib' into bug/378-20261003-bug-run-bundle-retention-is-inoperative-on-native-windows
…ff-check-and-mypy-do-not-cover-the-compatibility-consum
…d-mypy-do-not-cover-the-compatibility-consum' into bug/387-20261003-bug-configure-logger-closes-consumer-owned-handlers-and-forc

# Conflicts:
#	docs/integrations.md
…ogger-closes-consumer-owned-handlers-and-forc' into enhancement/381-20261003-perf-lifecycle-logging-costs-107-us-record-about-20x-stdlib
…fecycle-logging-costs-107-us-record-about-20x-stdlib' into bug/378-20261003-bug-run-bundle-retention-is-inoperative-on-native-windows
…retention-is-inoperative-on-native-windows' into enhancement/386-20261003-perf-retention-serializes-concurrent-invocations-on-an-untim
…tention-serializes-concurrent-invocations-on-an-untim' into security/385-20261003-security-validate-trust-of-ancestor-discovered-project-confi
@codeforester

Copy link
Copy Markdown
Contributor Author

Re-verified at 5e8e01f: both threads addressed ✅. The permission check is now st_mode & 0o002 (other-write only), so umask 002 repos (0775 directories, 0664 files) are accepted. The switch is renamed verify_discovered_config / verify_project_config, so True now means verify, and the error message points to the trust policy. Full suite passes at the tip. The threads can be resolved.

Base automatically changed from enhancement/386-20261003-perf-retention-serializes-concurrent-invocations-on-an-untim to main October 5, 2026 15:31
@codeforester

Copy link
Copy Markdown
Contributor Author

Resolved the merge conflicts by merging current main, including merged PR #418, into this branch in commit 2c2dc2f. Preserved the #385 project-configuration trust-boundary changes and current main logging recovery and tests. Local validation passed: full pytest, focused security/configuration tests (46), Ruff check and format, strict mypy, and documentation validation. GitHub reports the PR as conflict-free; hosted checks are running on the new head. The PR remains open and unmerged.

@codeforester
codeforester merged commit fc15496 into main Oct 5, 2026
117 checks passed
@codeforester
codeforester deleted the security/385-20261003-security-validate-trust-of-ancestor-discovered-project-confi branch October 5, 2026 15:45
codeforester added a commit that referenced this pull request Oct 5, 2026
JSON invocations now capture process descriptor 1 as well as Python
stdout, so inherited subprocess output remains inside the single
envelope. A concurrent drain avoids pipe deadlocks, the native path
enforces the JSON capture limit, and descriptor restoration precedes
envelope emission.

The guides state the boundaries: wait for children, flush native stdio
before returning, and use NDJSON for large output. A child retaining
stdout causes a bounded capture error.

Fixes #379.

## Branch maintenance

Refs #426. Targets the branch for #419. Retarget and refresh after that
parent is squash-merged; preserve the ordered stack.

The branch was refreshed without rewriting history to include `main` at
`a576cc279739eae5e4cfc33ffab2a7fb56de24de`.

## Current-head validation

At `0441cec3b3098425d8c87aa9c8eaeee6e5496969`: uv lock freshness and
baseline, runtime, strict typing, style, and contracts passed locally
with all declared extras. Runtime result: 629 passed, 1 warning, 262
subtests passed in 9.37s.

Hosted checks: 7/7 required checks passed; 0 checks pending; 0
unsuccessful checks at 2026-10-04T14:19:40.760978+00:00. See the PR
Checks tab and #426 for subsequent results.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

security: validate trust of ancestor-discovered project configuration

1 participant