Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Explicit permissions object replaces the secure default instead of merging over it (drops binding auto-grant)

オープン
#1,960 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

  • #1964 @roli-lpci による — マージされずにクローズ

評価

難易度
3/5
見積もり時間
1〜2日
初心者へのやさしさ
78/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
typescript
領域
security

調査の方向性

packages/core/src/agent-os.ts の 3276 行付近から始め、docs/content/docs/permissions.mdx の 32 行付近と動作を比較してください。明示的な権限がベースラインとどのように組み合わされるか、また binding の登録が binding scope にどのような影響を与えるかを確認してください。ドキュメントに記載されたベースラインを維持する明示的な network-only policy と、bindings が引き続き許可されることについてのテストカバレッジを追加し、その後、関連する core テストを実行してください。

索引モデルが issue の本文から書いたものです。

説明

Split out from #1884 so that #1958 (which fixes the other half of that report — network rule patterns never matching the URI-formatted resource) can close cleanly without silently closing this one.

Problem

The permissions docs state that a partial policy is merged over a secure default:

Your policy is merged over this baseline. Omitted scopes keep their default; they are not denied. So { network: "allow" } grants the network while keeping the execution essentials.

— docs/content/docs/permissions.mdx:32

The implementation does a wholesale replacement instead:

// packages/core/src/agent-os.ts:3276
const hostPermissions = options?.permissions ?? {
    ...allowAll,
    binding: "allow",
};

The ?? only supplies the default when permissions is entirely absent. Any explicit object replaces it in full.

Consequences

  1. Omitted scopes are denied, not defaulted. { network: "allow" } leaves fs, childProcess, process, and env undefined. Whatever the sidecar treats as the missing-scope default applies — not the documented baseline — so the documented one-liner for "grant the network, leave everything else alone" silently removes the execution essentials.

  2. The binding auto-grant is lost. The docs say binding is auto-granted when bindings are registered. Because the binding: "allow" in the fallback lives inside the branch that only runs when no policy is passed, registering bindings alongside any explicit policy leaves binding undefined → denied.

  3. It masks unrelated bugs. Verifying #1958's fix end-to-end requires spelling out all six scopes in the repro, otherwise { network: { default: "deny", rules: [...] } } alone also denies fs/process and the failure looks like a network-policy bug. The original reporter in #1884 hit exactly this.

Reproduction

import { AgentOs } from '@rivet-dev/agentos';

// Documented as: grant network, keep execution essentials.
const vm = await AgentOs.create({ permissions: { network: 'allow' } });
await vm.filesystem.writeFile('/tmp/t.js', 'console.log("hi")');
// fs/process operations do not behave as the documented baseline implies

Reported against 0.2.15 and 0.2.16-rc.1 in #1884.

Suggested fix

Merge scope-by-scope over the baseline rather than replacing:

const hostPermissions = {
    ...allowAll,
    binding: "allow",
    ...(options?.permissions ?? {}),
};

…with the binding auto-grant applied whenever bindings are registered, independent of whether an explicit policy was supplied. Either that, or update permissions.mdx to document replacement semantics — but the merge behavior is the one the docs promise and the safer default, since the failure mode of replacement is silent over-denial.

Worth a test asserting that { network: "allow" } leaves fs at its documented baseline, and that registering a binding with an explicit policy still grants binding.

/cc @Scorpion197 — this is the half of #1884 your PR intentionally doesn't cover.

主要言語
Rust
スター
4.7k
フォーク
263
平均マージ
8時間 57分
マージ済み PR(30日)
30

環境構築

このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

rivet-dev/agentos のほかの issue

rivet-dev/agentos の issue をすべて見る

似ている issue

Rust の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。