Skip to content

Reject unsafe project-directory leaf topology #828

Description

@bcdonadio

Observed behavior: ensureProjectDirForIdentity authenticates and retains the private ~/.lcm root, but creates projects/<id> through ensurePrivateDirectory. A pre-existing project-directory symlink is followed and its target is chmodded instead of being rejected; the leaf's ownership and inode topology are not witnessed.

Expected behavior: The shared project-directory seam should reject a symlink, foreign owner, unexpected type, or concurrently replaced projects/<id> leaf while preserving its current private-root and metadata contracts.

Root cause: ensurePrivateDirectory uses recursive mkdirSync followed by path-based chmodSync; ensureProjectDirForIdentity retains and revalidates only the ~/.lcm root descriptor, not the projects or per-project directory descriptors.

How to reproduce: Under an owner-held mode-0700 ~/.lcm, create projects/<64-hex-id> as a symlink to another directory and call ensureProjectDirForIdentity for that id. The helper follows the link and applies mode 0700 to the target rather than failing closed.

Environment:

  • Agent: Codex Desktop task
  • Connector: local Codex workspace tools
  • OS: Fedora Linux

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    Fields

    Priority

    High

    Effort

    None yet

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions