Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Explicit permissions object replaces the secure default instead of merging over it (drops binding auto-grant)

Đang mở
#1,960 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

  • #1964 của @roli-lpci — đã đóng, không merge

Đánh giá

Độ khó
3/5
Thời gian dự kiến
1-2 ngày
Mức phù hợp với người mới
78/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
typescript
Lĩnh vực
security

Hướng nghiên cứu

Bắt đầu tại packages/core/src/agent-os.ts, khoảng dòng 3276, sau đó so sánh hành vi với docs/content/docs/permissions.mdx, khoảng dòng 32. Xác minh cách các quyền rõ ràng được kết hợp với baseline và việc đăng ký binding ảnh hưởng như thế nào đến binding scope. Bổ sung coverage cho một policy network-only rõ ràng vẫn giữ nguyên baseline được tài liệu hóa, đồng thời kiểm tra rằng các binding vẫn được cho phép, sau đó chạy các core test liên quan.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Split out from #1884 so that #1958 (which fixes the other half of that report — network rule patterns never matching the URI-formatted resource) can close cleanly without silently closing this one.

Problem

The permissions docs state that a partial policy is merged over a secure default:

Your policy is merged over this baseline. Omitted scopes keep their default; they are not denied. So { network: "allow" } grants the network while keeping the execution essentials.

— docs/content/docs/permissions.mdx:32

The implementation does a wholesale replacement instead:

// packages/core/src/agent-os.ts:3276
const hostPermissions = options?.permissions ?? {
    ...allowAll,
    binding: "allow",
};

The ?? only supplies the default when permissions is entirely absent. Any explicit object replaces it in full.

Consequences

  1. Omitted scopes are denied, not defaulted. { network: "allow" } leaves fs, childProcess, process, and env undefined. Whatever the sidecar treats as the missing-scope default applies — not the documented baseline — so the documented one-liner for "grant the network, leave everything else alone" silently removes the execution essentials.

  2. The binding auto-grant is lost. The docs say binding is auto-granted when bindings are registered. Because the binding: "allow" in the fallback lives inside the branch that only runs when no policy is passed, registering bindings alongside any explicit policy leaves binding undefined → denied.

  3. It masks unrelated bugs. Verifying #1958's fix end-to-end requires spelling out all six scopes in the repro, otherwise { network: { default: "deny", rules: [...] } } alone also denies fs/process and the failure looks like a network-policy bug. The original reporter in #1884 hit exactly this.

Reproduction

import { AgentOs } from '@rivet-dev/agentos';

// Documented as: grant network, keep execution essentials.
const vm = await AgentOs.create({ permissions: { network: 'allow' } });
await vm.filesystem.writeFile('/tmp/t.js', 'console.log("hi")');
// fs/process operations do not behave as the documented baseline implies

Reported against 0.2.15 and 0.2.16-rc.1 in #1884.

Suggested fix

Merge scope-by-scope over the baseline rather than replacing:

const hostPermissions = {
    ...allowAll,
    binding: "allow",
    ...(options?.permissions ?? {}),
};

…with the binding auto-grant applied whenever bindings are registered, independent of whether an explicit policy was supplied. Either that, or update permissions.mdx to document replacement semantics — but the merge behavior is the one the docs promise and the safer default, since the failure mode of replacement is silent over-denial.

Worth a test asserting that { network: "allow" } leaves fs at its documented baseline, and that registering a binding with an explicit policy still grants binding.

/cc @Scorpion197 — this is the half of #1884 your PR intentionally doesn't cover.

Ngôn ngữ chính
Rust
Star
4.7k
Fork
263
Merge trung bình
8 giờ 57 phút
Pull request đã merge (30 ngày)
30

Chuẩn bị môi trường

Dự án này không cung cấp dev container, Dockerfile hay hướng dẫn đóng góp, nên bạn cần tự thiết lập môi trường: hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của rivet-dev/agentos

Tất cả issue của rivet-dev/agentos

Issue tương tự

Thêm issue về Rust

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.