Skip to content

P0: Restricted users cannot compact because internal handoff storage uses project file permissions #150

Description

@akemmanuel

Evidence and scope

Based on a private support handover dated 2026-10-02 and a follow-up report dated 2026-10-06. Customer identities, deployment coordinates, project paths, session identifiers, and raw attachments are deliberately omitted. Code references are pinned to current public master (3f90286), not the reporter's deployed build or uncommitted local changes. Production was not accessed or modified during this triage.

Impact and reported behavior

Long-running restricted-user Sessions fail before answering the next user request. In the earlier diagnosed incident, the Harness requested a write to an internal temporary HANDOFF.md outside the user's granted project root. The normal file Tool correctly returned outside_allowed_roots. A fallback summary in the project did not satisfy the Harness's exact-path check, producing Compaction did not create .

The October 6 report shows the same missing-handoff symptom in a newer Session. Its current Run has not been fully analyzed; do not assume the earlier root cause is independently proven for that Run. A new chat and a repaired shell broker do not resolve this underlying storage contract.

Code evidence

  • Compaction paths and prompt explicitly require model Tools to write outside the Project.
  • #performCompaction executes these Tools under the revalidated normal execution policy, then reads only paths.handoffPath.
  • Resume prompt asks the model to read the same internal folder, so fixing writes alone may leave resume reads denied.

Reproduction to automate

  1. Create a restricted test Account with write access only to a temporary Project; retain access to an entitled model.
  2. Build a long Session exceeding the compaction threshold (default ratio 0.7).
  3. Drive the real Harness with a deterministic model fixture that follows the requested handoff write.
  4. Assert the internal write denial and missing-handoff failure on the affected implementation, then assert successful compaction and continuation after the fix.

This exact regression has not been executed during ticket triage; the production handover supplies the observed failure.

Required change

Let the Harness own internal handoff persistence and supply the validated summary back to model context. Prefer structured summary output or a narrowly scoped internal submission capability; do not grant arbitrary internal filesystem access. Ensure both storage and subsequent resume work under unchanged user permissions.

  • Scope internal state to Host, principal, Session, and Run.
  • Validate nonempty content and enforce a size limit; reject malformed or incomplete output.
  • Publish a completed compaction only after durable validation/persistence.
  • Preserve append-oriented transcript history and existing Project files on failure.
  • Do not widen /tmp, shared data, foreign-Session, or customer-Project permissions.
  • If a temporary exact-path exception is unavoidable, bind it to the current Run and defend against traversal, symlinks, and cross-Session use.

Acceptance

  • Restricted-user manual and automatic compaction succeed and answer/continue the intended task.
  • Resume requires no normal Tool access to a shared internal handoff directory.
  • Empty/oversized summaries and injected storage failure cannot create a false completed entry.
  • Concurrent Accounts/Sessions cannot overwrite or read one another's internal state.
  • Grant revocation, cancellation, and Host restart retain consistent authorization and durable state.
  • Tests still deny writes to foreign Projects and internal directories.

Related failure recovery and error classification: #151.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions