Repository navigation
feat(config): narrowing-only 的 .prayu 项目级配置 - #76
Merged
Merged
Conversation
project_config.v1(.prayu/config.yaml):严格 YAML 节点树校验(拒绝 alias/anchor、深度>32、节点>4096、symlink/junction/reparse、>64KiB),KnownFields 严格解码(未知字段/重复键/类型错误/尾随文档 fail closed)。 字段全部只缩不放:budget 只能严格降低、allowed_profiles 只能收缩、read_only 禁止 write-capable profile(code/script)、exclude_paths 相对无逃逸、skill_suggestions 对齐签名 Skill 合同、test/format_command_id 只能引用 Tool Gateway 注册 typed action。任何放宽生成带字段名的 Rejection 并整体拒绝。 Run 创建时把 Effective 视图 + SHA-256 fingerprint 固化进 run config 快照,运行中修改文件不影响现有 Run;run create 自动加载(--ignore-project-config 跳过),新增 project-config show|validate CLI。fuzz 种子 + 单测覆盖。
narrowing-only 合并规则、Run 快照不可变性、fail-closed 边界的决策记录;示例配置与 JSON schema 供团队参考。
Qiyuanqiii
force-pushed
the
codex/issue-54-prayu-project-config
branch
from
August 16, 2026 05:13
5ef6b9b to
729f08d
Compare
5 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
背景
Issue #54(epic #36):为 Prayu 增加 .prayu/ 项目级配置入口。项目文件属于不可信输入:只能缩小全局权限、提供非敏感默认值,不能提权或执行代码。
本次改动
internal/projectconfig:project_config.v1(<workspace>/.prayu/config.yaml)。加载链 fail closed:必须为普通文件(symlink/junction/reparse-point 拒绝)、≤64KiB;YAML 先走节点树校验(拒绝任何 alias/anchor、深度>32、节点>4096),再 KnownFields 严格解码(未知字段/重复键/类型错误/尾随文档拒绝)。budget{max_turns,max_tool_calls}只能严格低于 ceiling;allowed_profiles只能收缩且非空;read_only只能开启(并禁止 write-capable 的 code/script profile);exclude_paths为工作区相对路径(无 ..、无绝对路径);skill_suggestions对齐 feat(skills): 签名 Skill 包、团队 Catalog 与安全 URL/Git 导入 #53 签名 Skill 合同(name@version);test_command_id/format_command_id只能引用 Tool Gateway 注册的 typed action ID,绝不包含 Shell 文本。任何放宽尝试生成带字段名的 Rejection 并整体拒绝(Run 创建失败关闭)。run create自动加载(--ignore-project-config跳过),新增cyberagent project-config show|validate。测试覆盖
FuzzLoadNeverAcceptsHostileConfigfuzz 种子(anchor、路径逃逸、超大、合法样本)运行通过。验证结果
go build ./...、go vet ./...、go test -timeout 30m ./...全绿;projectconfig包-race通过。安全边界与非目标
Closes #54