Explicit permissions object replaces the secure default instead of merging over it (drops binding auto-grant)
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
- #1964 @roli-lpci による — マージされずにクローズ
評価
- 難易度
- 3/5
- 見積もり時間
- 1〜2日
- 初心者へのやさしさ
- 78/100
- issue の種類
- バグ
- 明瞭さ
- 明確に書かれている
- 活発さ
- 活発
- 技術スタック
- typescript
- 領域
- security
調査の方向性
packages/core/src/agent-os.ts の 3276 行付近から始め、docs/content/docs/permissions.mdx の 32 行付近と動作を比較してください。明示的な権限がベースラインとどのように組み合わされるか、また binding の登録が binding scope にどのような影響を与えるかを確認してください。ドキュメントに記載されたベースラインを維持する明示的な network-only policy と、bindings が引き続き許可されることについてのテストカバレッジを追加し、その後、関連する core テストを実行してください。
索引モデルが issue の本文から書いたものです。
説明
Split out from #1884 so that #1958 (which fixes the other half of that report — network rule patterns never matching the URI-formatted resource) can close cleanly without silently closing this one.
Problem
The permissions docs state that a partial policy is merged over a secure default:
Your policy is merged over this baseline. Omitted scopes keep their default; they are not denied. So
{ network: "allow" }grants the network while keeping the execution essentials.
— docs/content/docs/permissions.mdx:32
The implementation does a wholesale replacement instead:
// packages/core/src/agent-os.ts:3276
const hostPermissions = options?.permissions ?? {
...allowAll,
binding: "allow",
};
The ?? only supplies the default when permissions is entirely absent. Any explicit object replaces it in full.
Consequences
-
Omitted scopes are denied, not defaulted.
{ network: "allow" }leavesfs,childProcess,process, andenvundefined. Whatever the sidecar treats as the missing-scope default applies — not the documented baseline — so the documented one-liner for "grant the network, leave everything else alone" silently removes the execution essentials. -
The
bindingauto-grant is lost. The docs saybindingis auto-granted when bindings are registered. Because thebinding: "allow"in the fallback lives inside the branch that only runs when no policy is passed, registering bindings alongside any explicit policy leavesbindingundefined → denied. -
It masks unrelated bugs. Verifying #1958's fix end-to-end requires spelling out all six scopes in the repro, otherwise
{ network: { default: "deny", rules: [...] } }alone also deniesfs/processand the failure looks like a network-policy bug. The original reporter in #1884 hit exactly this.
Reproduction
import { AgentOs } from '@rivet-dev/agentos';
// Documented as: grant network, keep execution essentials.
const vm = await AgentOs.create({ permissions: { network: 'allow' } });
await vm.filesystem.writeFile('/tmp/t.js', 'console.log("hi")');
// fs/process operations do not behave as the documented baseline implies
Reported against 0.2.15 and 0.2.16-rc.1 in #1884.
Suggested fix
Merge scope-by-scope over the baseline rather than replacing:
const hostPermissions = {
...allowAll,
binding: "allow",
...(options?.permissions ?? {}),
};
…with the binding auto-grant applied whenever bindings are registered, independent of whether an explicit policy was supplied. Either that, or update permissions.mdx to document replacement semantics — but the merge behavior is the one the docs promise and the safer default, since the failure mode of replacement is silent over-denial.
Worth a test asserting that { network: "allow" } leaves fs at its documented baseline, and that registering a binding with an explicit policy still grants binding.
/cc @Scorpion197 — this is the half of #1884 your PR intentionally doesn't cover.
- 主要言語
- Rust
- スター
- 4.7k
- フォーク
- 263
- 平均マージ
- 8時間 57分
- マージ済み PR(30日)
- 30
環境構築
このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
rivet-dev/agentos のほかの issue
-
Python edits to filesystem.writeFile-created files are reverted by shadow reconciliation対応中かも @ankssjain が 3 日前に担当しました。 オープン
難易度 4/5 3〜5日 初心者へのやさしさ 20/100
rivet-dev/agentos#2022 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 3/5 半日 初心者へのやさしさ 32/100
メンテナーはふだん 1 日以内に返信
-
難易度 4/5 3〜5日 初心者へのやさしさ 45/100
メンテナーはふだん 1 日以内に返信
-
難易度 4/5 3〜5日 初心者へのやさしさ 66/100
rivet-dev/agentos#1994 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 5/5 1週間以上 初心者へのやさしさ 42/100
メンテナーはふだん 1 日以内に返信
rivet-dev/agentos の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
antithesishq/bombadil#361 ·
メンテナーはふだん 1 日以内に返信
-
test(executor_l0): assert execute() TaskOutcome, not only bus events / 断言 execute() 返回的 TaskOutcomeオープンtype:debt
難易度 2/5 1〜3時間 初心者へのやさしさ 62/100
skaiy/wild_agentos#425 ·
メンテナーはふだん 1 日以内に返信
-
Default-import note suggests `import * as process` for velt:process, which does not name the builtinオープン
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
メンテナーはふだん 1 日以内に返信
-
bug ticket
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
cratestack/cratestack#1154 ·
メンテナーはふだん 1 日以内に返信
-
status:needs-triage
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
メンテナーはふだん 1 日以内に返信