Observed behavior: At d1e126707fc2424ea83258564cc2b7b5ea80b809, bin/lcm.ts:3838 (lcm promote --all) and bin/lcm.ts:3948 (lcm export --all) parse project meta.json with raw readFileSync before consuming cwd. They lack regular-file, owner, single-link and finite-size admission. This is confirmed source evidence, not a demonstrated live exploit.
Expected behavior: Authenticate and bound the metadata leaf before parsing or using cwd. Preserve valid sibling discovery and each command's existing best-effort skip behavior.
Root cause: Both CLI enumeration loops retained raw reads while other project metadata consumers adopted readBoundedRegularFile with the established 1 MiB limit, expected UID and single-link checks.
How to reproduce safely: In a worker-private HOME, create a harmless valid JSON metadata file with a fictional cwd, hardlink it as projects//meta.json, and invoke the public command with downstream services mocked. Assert the cwd currently reaches promote/reconciliation dispatch. For oversized or nonregular leaves use bounded child processes or deterministic seams; do not block the live daemon. Current source alone establishes raw-read admission; caller-level regression is still required.
Relationship: Pre-existing distinct CLI callers found by GLM planning review for #1106. That issue's body explicitly scopes four src/ consumers; one was already fixed, and its current remediation covers the remaining import, batch and daemon scanner consumers. This CLI pair is outside that acceptance scope and the frozen S5 inventory. No native parenting under campaign #968/#1131. No implementation candidate or PR exists yet.
Environment:
- Agent: Codex Astra owner / GLM-5.3 planning reviewer
- Connector: local read-only source inspection
- OS: Fedora Linux
Observed behavior: At
d1e126707fc2424ea83258564cc2b7b5ea80b809,bin/lcm.ts:3838(lcm promote --all) andbin/lcm.ts:3948(lcm export --all) parse projectmeta.jsonwith rawreadFileSyncbefore consumingcwd. They lack regular-file, owner, single-link and finite-size admission. This is confirmed source evidence, not a demonstrated live exploit.Expected behavior: Authenticate and bound the metadata leaf before parsing or using cwd. Preserve valid sibling discovery and each command's existing best-effort skip behavior.
Root cause: Both CLI enumeration loops retained raw reads while other project metadata consumers adopted
readBoundedRegularFilewith the established 1 MiB limit, expected UID and single-link checks.How to reproduce safely: In a worker-private HOME, create a harmless valid JSON metadata file with a fictional cwd, hardlink it as projects//meta.json, and invoke the public command with downstream services mocked. Assert the cwd currently reaches promote/reconciliation dispatch. For oversized or nonregular leaves use bounded child processes or deterministic seams; do not block the live daemon. Current source alone establishes raw-read admission; caller-level regression is still required.
Relationship: Pre-existing distinct CLI callers found by GLM planning review for #1106. That issue's body explicitly scopes four src/ consumers; one was already fixed, and its current remediation covers the remaining import, batch and daemon scanner consumers. This CLI pair is outside that acceptance scope and the frozen S5 inventory. No native parenting under campaign #968/#1131. No implementation candidate or PR exists yet.
Environment: