docs: row 41 round 4 in review, build-log and session line (filbert)

Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
2026-10-09 22:31:20 -05:00
co-authored by Claude Opus 5.5
parent 6f102777a6
commit 21e0f1a31c
2 changed files with 25 additions and 0 deletions
+24
View File
@@ -3857,3 +3857,27 @@ Both round 3 reviews approve candidate d0aa0ded: Filbert (comment 27011, rev 260
### 2026-10-10 — Filbert, row 41 slice 1 S6 round 4 started (#1523)
Before: Darkwing's round 3 asked for changes (#1523 comment 27032, rev 271, packet 974da6ed). R4 is verified fixed. R5: `insideWorkspace` in `gate.mjs` resolves a relative path against the workspace path as given, but Pi resolves it against its cwd, and both adapters `cd` into the workspace, so the cwd is the real path. With the workspace or the dataRoot behind a symlink, `..` climbs different parents. Darkwing's probe had a real Pi session read a file outside the workspace and write a new one there. Sage ruled R5 is fixed in this row as round 4: resolve a relative path against the real path of Pi's cwd; tests with a symlinked workspace and a symlinked dataRoot, each covering read and write and refusing the `../..` escape, plus one relative path through the symlinked root that stays inside and is allowed; rerun Darkwing's repro against real Pi; state in BUILD.md why Claude Code is unaffected; leave R1 to R4 alone, no other scope. Row 41 is in-progress again (rev 272, 0b855ae1). Plan: a relative path must resolve inside against both the real path and the given path; the survivor mutants Mw to Mz and the seat `workspaceDir` realpath go to follow-ups. No push; landing target 2026-10-13, after the Q14 hold.
### 2026-10-10 — Filbert, row 41 slice 1 S6 round 4 in review (#1523)
After: R5 is fixed in `insideWorkspace` (`packages/harness/src/gate.mjs`). A relative path must now resolve inside from both the workspace's real path, which is Pi's cwd after the adapter's `cd`, and the path as given. The given-path check is stricter than Pi: a path that is inside for Pi but climbs out of the given path is refused. BUILD.md records that choice. Claude Code is unaffected: it makes `file_path` absolute against its real cwd before the `PreToolUse` hook, so the gate already sees the path it will open. Darkwing's probe and my rerun both show the hook refusing `<R>/deep/data/ws/...`.
Tests:
- `gate.test.mjs`: a symlinked workspace and a symlinked dataRoot (the launcher's `workspaces/<b>/<i>` shape), in both harnesses. Read and write of the `../..` escape are refused. A climb out and back in through the symlinked root is allowed. A path that is inside for Pi but outside as given is refused.
- `pi-session.test.mjs`: a real Pi 0.85.1 session in each layout. The escape read and write are refused, the secret never reaches stdout, and nothing is written outside. The inside read and write work.
Mutants: the round 3 code (given path only) fails 3 tests, and real-path-only fails 1. The first draft let real-path-only survive, so the stricter case was added for it.
Darkwing's `r3/probe/pi-cwd-dotdot.sh` and `claude-cwd-dotdot.sh`, rerun unchanged against the build, refuse read and write in both harnesses.
Four files changed. Candidate manifest 08a78972 (42 files). Gate at 0a4c8f13: all green except test-task's two Docker recall checks; the unpatched base fails the same two. Harness is 56/0.
Follow-ups, not done per Sage's no-other-scope: the Mw to Mz survivors, realpath in the seat's `workspaceDir`, and the Ma leftover.
Records:
- packet 55bff3b2
- revs 272 (0b855ae1) and 274-275 (6f102777)
- request comment 27033
- REQUEST to Darkwing
No push. The landing target stays 2026-10-13, after the Q14 hold.
+1
View File
@@ -562,3 +562,4 @@ are never rewritten or removed; corrections are new entries.
2026-10-10T03:01:18Z | Dewey (T3 Claude Code, thread 84fb346c) | row 40 slice 1 S5 (#1522) round 3 approved | Filbert approve 27011 (rev 260), Darkwing approve 27013 (rev 264) on manifest d0aa0ded; Darkwing note 1 (mutant Mr, stacked hold not re-drained) covered by a follow-up flows test drafted in scratch (~/dewey-scratch/s5/mr-test.patch): passes on the candidate, kills Mr, flows 28/28; not in the candidate; no push
2026-10-10T03:10:48Z | Sage (T3 Claude Code, lead) | land row 40 (#1522) slice 1 S5 | candidate d0aa0ded landed as 08b428ec (temporary index; shared index has ~150 unrelated staged files); gate on 8cad7722 green, test-task 98/0; row 40 done rev 265; follow-up rows 47 (Mr flows test, shim cleanup, Dewey, #1533), 48 (test hygiene, #1534), 49 (bus comment cursor after S6, #1535), revs 266-268 (e345640e); #1530-#1532 filed as jason.woltje by mistake and closed as duplicates
2026-10-10T03:19:34Z | darkwing | review row 41 (#1523) slice 1 S6 round 3 | changes, comment 27032, rev 271 (43909c20), packet 974da6ed; R4 fixed (28/28 spelling edges, real Pi pi-variant 4/4 refused), Mr killed, Mv no hang; new blocker R5: a relative Pi path resolves against the given workspace in the gate and the real path in Pi, so a symlinked workspace lets .. read and write outside (real Pi, round 2 too; Claude Code refuses); 25 of 29 mutants killed, Mw Mx My Mz survive; scope question to Sage
2026-10-10T03:31:19Z | filbert | row 41 (#1523) slice 1 S6 round 4 | R5 fix: relative paths checked from the real workspace path and the given one; gate and real-Pi tests for symlinked workspace and dataRoot; mutants killed; Darkwing r3 probes refuse in pi and claude; packet agents/filbert/work/s6/ (55bff3b2), manifest 08a78972; gate at 0a4c8f13 green but test-task Docker recall (same on base); revs 272, 274-275, #1523 comment 27033; REQUEST to darkwing; no push