Skip to content

feat(config): narrowing-only 的 .prayu 项目级配置 - #76

Merged
Qiyuanqiii merged 2 commits into
mainfrom
codex/issue-54-prayu-project-config
Aug 16, 2026
Merged

Qiyuanqiii merged 2 commits into
mainfrom
codex/issue-54-prayu-project-config

Conversation

@Qiyuanqiii

Copy link
Copy Markdown
Member

背景

Issue #54(epic #36):为 Prayu 增加 .prayu/ 项目级配置入口。项目文件属于不可信输入:只能缩小全局权限、提供非敏感默认值,不能提权或执行代码。

本次改动

  • internal/projectconfig:project_config.v1(<workspace>/.prayu/config.yaml)。加载链 fail closed:必须为普通文件(symlink/junction/reparse-point 拒绝)、≤64KiB;YAML 先走节点树校验(拒绝任何 alias/anchor、深度>32、节点>4096),再 KnownFields 严格解码(未知字段/重复键/类型错误/尾随文档拒绝)。
  • 只缩不放的字段集:budget{max_turns,max_tool_calls} 只能严格低于 ceiling;allowed_profiles 只能收缩且非空;read_only 只能开启(并禁止 write-capable 的 code/script profile);exclude_paths 为工作区相对路径(无 ..、无绝对路径);skill_suggestions 对齐 feat(skills): 签名 Skill 包、团队 Catalog 与安全 URL/Git 导入 #53 签名 Skill 合同(name@version);test_command_id/format_command_id 只能引用 Tool Gateway 注册的 typed action ID,绝不包含 Shell 文本。任何放宽尝试生成带字段名的 Rejection 并整体拒绝(Run 创建失败关闭)。
  • Run 快照不可变:Run 创建时把规范化 Effective 视图 + SHA-256 fingerprint 固化进 run config 快照;之后修改配置文件不影响已存在的 Run。run create 自动加载(--ignore-project-config 跳过),新增 cyberagent project-config show|validate。

测试覆盖

  • 未知字段/重复键/类型错误/alias/锚点/深度/节点数/超大文件/路径逃逸/绝对路径/坏 skill 引用/负预算均 fail closed;symlink 配置拒绝;fingerprint 跨加载稳定。
  • FuzzLoadNeverAcceptsHostileConfig fuzz 种子(anchor、路径逃逸、超大、合法样本)运行通过。
  • application 层:项目预算收缩生效、快照 fingerprint 落库且重读不变、read_only 拒绝 write-capable profile、allowed_profiles 外 profile 拒绝。

验证结果

  • go build ./...、go vet ./...、go test -timeout 30m ./... 全绿;projectconfig 包 -race 通过。

安全边界与非目标

  • 无 API key/raw credential/任意 executable/argv/Docker flags/网络放宽/权限档位字段;不执行 hooks/plugins/scripts/表达式;不把其他工具的配置当可信设置。
  • 后续 PR:Desktop 的 global/user/project/Run 分层来源展示、被忽略/拒绝字段列表与 HTTP/OpenAPI(ADR 0106 已记录)。

Closes #54

project_config.v1(.prayu/config.yaml):严格 YAML 节点树校验(拒绝 alias/anchor、深度>32、节点>4096、symlink/junction/reparse、>64KiB),KnownFields 严格解码(未知字段/重复键/类型错误/尾随文档 fail closed)。

字段全部只缩不放:budget 只能严格降低、allowed_profiles 只能收缩、read_only 禁止 write-capable profile(code/script)、exclude_paths 相对无逃逸、skill_suggestions 对齐签名 Skill 合同、test/format_command_id 只能引用 Tool Gateway 注册 typed action。任何放宽生成带字段名的 Rejection 并整体拒绝。

Run 创建时把 Effective 视图 + SHA-256 fingerprint 固化进 run config 快照,运行中修改文件不影响现有 Run;run create 自动加载(--ignore-project-config 跳过),新增 project-config show|validate CLI。fuzz 种子 + 单测覆盖。
narrowing-only 合并规则、Run 快照不可变性、fail-closed 边界的决策记录;示例配置与 JSON schema 供团队参考。
@Qiyuanqiii
Qiyuanqiii force-pushed the codex/issue-54-prayu-project-config branch from 5ef6b9b to 729f08d Compare August 16, 2026 05:13
@Qiyuanqiii
Qiyuanqiii merged commit 6264721 into main Aug 16, 2026
5 checks passed
@Qiyuanqiii
Qiyuanqiii deleted the codex/issue-54-prayu-project-config branch August 16, 2026 05:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(config): narrowing-only 的 .prayu 项目级配置

1 participant