Skip to content

Journal listing silently skips non-regular leaves #1166

Description

@bcdonadio

Observed behavior: listWorktreeReconciliationJournals filters entries using entry.isFile() before readJournal. Hash-named symlinks, directories, and FIFOs are silently omitted instead of being authenticated and refused, contrary to the fail-closed listing documentation.

Expected behavior: Filter by journal filename, then apply authenticated leaf admission to every matching entry; listing should report refusal rather than partial state.

Root cause: Static owner confirmation in src/worktree-reconciliation.ts at PR head 3971ac0. Existing admission short circuits precede the new descriptor authentication.

How to reproduce: Create a private fixture ~/.lcm/reconciliations directory containing a 64-hex-character .json directory or symlink. Call listWorktreeReconciliationJournals(homeDir). It returns an empty or partial array without reporting that unsafe journal-shaped entry. Static control-flow confirmation; no hostile host fixture was used.

Severity and disposition: P2. Requires a journal-shaped local entry in the owner-controlled reconciliation directory. No unsafe contents are parsed. Accepted external review finding deferred after the originating candidate completed all three reviewed rounds; outside frozen S5 scope. Preserve source reader hardening and existing recovery-writer follow-up #1151.

Origin: #1109 / #1107; #1149 (comment); candidate 3971ac0.

Environment:

  • Agent: Codex Astra recovery owner
  • Connector: CLI
  • OS: Fedora Linux

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    Fields

    Priority

    Medium

    Effort

    None yet

    Projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions