Skip to content

profile: @cwd-rw is @target-rw, because the grant was always {target} - #579

Merged
vyskocilm merged 3 commits into
mainfrom
profile/target-rw
Sep 17, 2026
Merged

vyskocilm merged 3 commits into
mainfrom
profile/target-rw

Conversation

@vyskocilm

Copy link
Copy Markdown
Contributor

One rename out of #578's roster review: @cwd-rw -> @target-rw. @sys and @git-ro are NOT touched here — see the ticket comment for why @sys stays and why @git-ro is a separate ruling.

Why the name was wrong

Grant is rw = ["{target}"]. Sibling is ro = ["{target_parent}"].

Measured, not assumed: Resolve sets Chdir: target unconditionally and bwrap.go emits --chdir, so the payload's cwd IS the target at exec. That is what kept "cwd" from being false INSIDE — and it is still the wrong noun:

  • Chdir is a consequence of the grant, not the grant. A payload that cd / keeps the target writable and its cwd not.
  • The name is read on the HOST side, where cwd != target whenever snug <dir> names one. README carried that misreading already: # cwd is read write because of @cwd-rw.
  • Every other user-facing noun is target: {target}, {target_parent}, Policy.Target, SNUG_TARGET.

Retirement, not alias

@cwd-rw joins retiredProfiles beside @null, so the old spelling names the fix rather than reading as a typo. Pre-alpha, no alias table: two correct spellings forever is worse than one wrong name.

Control pinned in TestRetiredCwdRwNamesTargetRw: a user's OWN cwd-rw in profiles.d is not preempted by the retirement notice — the @null table already learned that one.

Golden diff, the review artifact

Exactly two things move:

-SNUG_PROFILES    @cwd-rw,@home,@sys
+SNUG_PROFILES    @home,@sys,@target-rw

the spelling, and that sort position (Selected is a set, sorted for rendering). 24 golden files, 39 insertions, 39 deletions. Verified no third thing moved:

git diff -U0 -- '*/testdata/*' | grep '^[+-]' | grep -v '^[+-][+-]' | grep -v 'target-rw\|cwd-rw'   # empty

Redteam

None owed. No grant, mount, env var or refusal semantics change; the golden diff above is the evidence.

Drive-by

NameHint's comment claimed "eight of snug's own profiles are hyphenated". Five are: cwd-rw, parent-ro, git-ro, podman-socket, podman-build.

make gate exit 0. make integration running on this host; will report.

Refs #578

🤖 Generated with Claude Code

… (refs #578)

The grant is `rw = ["{target}"]` and its sibling is spelled `{target_parent}`.
"cwd" named a side effect rather than the grant: `Resolve` sets `Chdir: target`
unconditionally and `bwrap.go` emits `--chdir`, so the payload's cwd IS the
target at exec — but a payload that `cd /` still has the target writable and its
cwd not, and the name is read on the HOST side, where cwd and target differ
whenever `snug <dir>` names one. README's own example carried that misreading:
"# cwd is read write because of @cwd-rw".

Every other user-facing noun is already `target`: {target}, {target_parent},
Policy.Target, SNUG_TARGET, @parent-ro's own comment. After this @target-rw and
@parent-ro share it.

@cwd-rw joins retiredProfiles beside @null, so the old spelling names the fix
instead of reading as a typo — it is in every shipped README example and in
whatever `defaults = [...]` anyone wrote. NOT an alias: snug is pre-alpha and two
correct spellings forever is worse than one wrong name.

Golden diff is the review artifact and it changes exactly two things: the
spelling, and SNUG_PROFILES' sort position (@cwd-rw,@home,@sys becomes
@home,@sys,@target-rw — Selected is a set, sorted for rendering). 24 golden
files, 39 insertions and 39 deletions; no other line moves.

No grant, mount, env var or refusal semantics change, so no redteam round is
owed.

Drive-by, measured while editing it: NameHint's comment said "eight of snug's
own profiles are hyphenated". Five are — cwd-rw, parent-ro, git-ro,
podman-socket, podman-build.

Refs #578

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… the old name

`TestProfileFlagAddsToTheDefaultRatherThanReplacingIt`'s control asserts the
whole default list as one string. The rename moved `@target-rw` past `@home` and
`@sys` alphabetically, so the control failed on order after the spelling was
already right:

    fixture: `snug -p @sys` resolved "@home,@sys,@target-rw",
    want "@target-rw,@home,@sys"

Selected is a set; the string is sorted for rendering. Measured on this host with
SNUG_REQUIRE_SANDBOX=1, the narrow case passes after the edit.

Refs #578

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@vyskocilm

Copy link
Copy Markdown
Contributor Author

make integration green on this host.

SNUG_REQUIRE_SANDBOX=1 SNUG_SANDBOX_TIMEOUT=25m make integration
  .integration-sandbox.log   212 PASS, 2 SKIP, 0 FAIL   321.9s
  .integration-signals.log     3 PASS, 0 FAIL            69.6s
  snug-engine-ran: 46, floor 46

First run was red and one of the two failures was real: TestProfileFlagAddsToTheDefaultRatherThanReplacingIt pins the whole default list as ONE STRING, so the rename moved the position as well as the spelling —

fixture: `snug -p @sys` resolved "@home,@sys,@target-rw", want "@target-rw,@home,@sys"

fixed in 3a9f7a2.

Second failure was TestContainerEgressFollowsNetProfile, connect: network is unreachable, under load ~10 with two other agents and a second suite on the host. Not this branch: it passes at origin/main, and 3/3 on this branch at load 0.62. A rename reaches no networking code and the golden diff above proves no grant moved.

@vyskocilm
vyskocilm merged commit e2e43d8 into main Sep 17, 2026
5 checks passed
@vyskocilm
vyskocilm deleted the profile/target-rw branch September 17, 2026 13:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant