Observed behavior: ensureProjectDirForIdentity authenticates and retains the private ~/.lcm root, but creates projects/<id> through ensurePrivateDirectory. A pre-existing project-directory symlink is followed and its target is chmodded instead of being rejected; the leaf's ownership and inode topology are not witnessed.
Expected behavior: The shared project-directory seam should reject a symlink, foreign owner, unexpected type, or concurrently replaced projects/<id> leaf while preserving its current private-root and metadata contracts.
Root cause: ensurePrivateDirectory uses recursive mkdirSync followed by path-based chmodSync; ensureProjectDirForIdentity retains and revalidates only the ~/.lcm root descriptor, not the projects or per-project directory descriptors.
How to reproduce: Under an owner-held mode-0700 ~/.lcm, create projects/<64-hex-id> as a symlink to another directory and call ensureProjectDirForIdentity for that id. The helper follows the link and applies mode 0700 to the target rather than failing closed.
Environment:
- Agent: Codex Desktop task
- Connector: local Codex workspace tools
- OS: Fedora Linux
Observed behavior:
ensureProjectDirForIdentityauthenticates and retains the private~/.lcmroot, but createsprojects/<id>throughensurePrivateDirectory. A pre-existing project-directory symlink is followed and its target is chmodded instead of being rejected; the leaf's ownership and inode topology are not witnessed.Expected behavior: The shared project-directory seam should reject a symlink, foreign owner, unexpected type, or concurrently replaced
projects/<id>leaf while preserving its current private-root and metadata contracts.Root cause:
ensurePrivateDirectoryuses recursivemkdirSyncfollowed by path-basedchmodSync;ensureProjectDirForIdentityretains and revalidates only the~/.lcmroot descriptor, not theprojectsor per-project directory descriptors.How to reproduce: Under an owner-held mode-0700
~/.lcm, createprojects/<64-hex-id>as a symlink to another directory and callensureProjectDirForIdentityfor that id. The helper follows the link and applies mode 0700 to the target rather than failing closed.Environment: