Confine Dream reconciliation writes to the shadow tree - #40
Merged
Xingdi (Eric) Yuan (xingdi-eric-yuan) merged 2 commits intoSep 24, 2026
Merged
Conversation
Validate untrusted manifest paths and symlink-resolved destinations before publication, including lower-level writers and archive/metadata outputs. Preserve valid Unicode and spaced relative paths and fail explicitly on unsafe destinations. Fixes #36 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Xingdi (Eric) Yuan (xingdi-eric-yuan)
requested a review
from Chinmay Singh (chisingh)
September 23, 2026 13:31
Prevent reserved Windows device basenames from being treated as contained shadow files, and extend path-validation coverage across anchors, refs, slugs, and dream IDs. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 9876beba-3398-40e7-a556-b76e7aed9327
Chinmay Singh (chisingh)
approved these changes
Sep 24, 2026
Chinmay Singh (chisingh)
left a comment
Contributor
There was a problem hiding this comment.
Added another commit with Windows device name checks. Approved!
Xingdi (Eric) Yuan (xingdi-eric-yuan)
deleted the
fix/reconcile-path-containment
branch
September 24, 2026 00:18
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes #36.
Treat paths from remote Dream manifests as untrusted before using them as output destinations:
Legitimate Unicode, spaces, dotted filenames, and contained directory aliases remain supported. Existing discovery metadata, duplicate handling, reference merging, and coherent-lineage behavior remain unchanged.
Verification
440 focused tests passed, including real local-remote CLI cases, outside-file sentinels, multi-entry/batch rollback-before-write checks, symlinked output paths, direct writer entry points, normal Unicode/space paths, pinned tools, and installed skill layouts.
This is a filesystem-output boundary for reconciliation. It does not authenticate discovery text, sandbox experiment code, or promise protection against a concurrent local process changing filesystem aliases while reconciliation runs.
Based directly on current
main; independent of the Python setup port in #33 and the HTML-rendering fix for #37.