Skip to content

Confine Dream reconciliation writes to the shadow tree - #40

Merged
Xingdi (Eric) Yuan (xingdi-eric-yuan) merged 2 commits into
mainfrom
fix/reconcile-path-containment
Sep 24, 2026
Merged

Xingdi (Eric) Yuan (xingdi-eric-yuan) merged 2 commits into
mainfrom
fix/reconcile-path-containment

Conversation

@xingdi-eric-yuan

Copy link
Copy Markdown
Collaborator

Summary

Fixes #36.

Treat paths from remote Dream manifests as untrusted before using them as output destinations:

  • Validate discovery anchors and cross-cutting reference file parts as relative paths, rejecting absolute paths, traversal components, Windows drive/UNC/stream forms, and invalid separators.
  • Check resolved containment for the shadow root, parent directories, and final output files, including existing and dangling symlinks.
  • Preflight the complete manifest batch before any discovery, back-pointer, archive, or metadata publication. Invalid paths stop the CLI with an actionable error and nonzero exit, including in dry runs.
  • Require the trusted repository root in lower-level writers so direct calls cannot bypass containment.

Legitimate Unicode, spaces, dotted filenames, and contained directory aliases remain supported. Existing discovery metadata, duplicate handling, reference merging, and coherent-lineage behavior remain unchanged.

Verification

440 focused tests passed, including real local-remote CLI cases, outside-file sentinels, multi-entry/batch rollback-before-write checks, symlinked output paths, direct writer entry points, normal Unicode/space paths, pinned tools, and installed skill layouts.

This is a filesystem-output boundary for reconciliation. It does not authenticate discovery text, sandbox experiment code, or promise protection against a concurrent local process changing filesystem aliases while reconciliation runs.

Based directly on current main; independent of the Python setup port in #33 and the HTML-rendering fix for #37.

Validate untrusted manifest paths and symlink-resolved destinations before publication, including lower-level writers and archive/metadata outputs. Preserve valid Unicode and spaced relative paths and fail explicitly on unsafe destinations.

Fixes #36

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Prevent reserved Windows device basenames from being treated as contained shadow files, and extend path-validation coverage across anchors, refs, slugs, and dream IDs.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 9876beba-3398-40e7-a556-b76e7aed9327

@chisingh Chinmay Singh (chisingh) left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added another commit with Windows device name checks. Approved!

@xingdi-eric-yuan
Xingdi (Eric) Yuan (xingdi-eric-yuan) merged commit 93ed92e into main Sep 24, 2026
5 checks passed
@xingdi-eric-yuan
Xingdi (Eric) Yuan (xingdi-eric-yuan) deleted the fix/reconcile-path-containment branch September 24, 2026 00:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

dream-reconcile.py: unvalidated anchor paths allow writes outside the repo

2 participants