Explicit permissions object replaces the secure default instead of merging over it (drops binding auto-grant)
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
- #1964 của @roli-lpci — đã đóng, không merge
Đánh giá
- Độ khó
- 3/5
- Thời gian dự kiến
- 1-2 ngày
- Mức phù hợp với người mới
- 78/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- typescript
- Lĩnh vực
- security
Hướng nghiên cứu
Bắt đầu tại packages/core/src/agent-os.ts, khoảng dòng 3276, sau đó so sánh hành vi với docs/content/docs/permissions.mdx, khoảng dòng 32. Xác minh cách các quyền rõ ràng được kết hợp với baseline và việc đăng ký binding ảnh hưởng như thế nào đến binding scope. Bổ sung coverage cho một policy network-only rõ ràng vẫn giữ nguyên baseline được tài liệu hóa, đồng thời kiểm tra rằng các binding vẫn được cho phép, sau đó chạy các core test liên quan.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Split out from #1884 so that #1958 (which fixes the other half of that report — network rule patterns never matching the URI-formatted resource) can close cleanly without silently closing this one.
Problem
The permissions docs state that a partial policy is merged over a secure default:
Your policy is merged over this baseline. Omitted scopes keep their default; they are not denied. So
{ network: "allow" }grants the network while keeping the execution essentials.
— docs/content/docs/permissions.mdx:32
The implementation does a wholesale replacement instead:
// packages/core/src/agent-os.ts:3276
const hostPermissions = options?.permissions ?? {
...allowAll,
binding: "allow",
};
The ?? only supplies the default when permissions is entirely absent. Any explicit object replaces it in full.
Consequences
-
Omitted scopes are denied, not defaulted.
{ network: "allow" }leavesfs,childProcess,process, andenvundefined. Whatever the sidecar treats as the missing-scope default applies — not the documented baseline — so the documented one-liner for "grant the network, leave everything else alone" silently removes the execution essentials. -
The
bindingauto-grant is lost. The docs saybindingis auto-granted when bindings are registered. Because thebinding: "allow"in the fallback lives inside the branch that only runs when no policy is passed, registering bindings alongside any explicit policy leavesbindingundefined → denied. -
It masks unrelated bugs. Verifying #1958's fix end-to-end requires spelling out all six scopes in the repro, otherwise
{ network: { default: "deny", rules: [...] } }alone also deniesfs/processand the failure looks like a network-policy bug. The original reporter in #1884 hit exactly this.
Reproduction
import { AgentOs } from '@rivet-dev/agentos';
// Documented as: grant network, keep execution essentials.
const vm = await AgentOs.create({ permissions: { network: 'allow' } });
await vm.filesystem.writeFile('/tmp/t.js', 'console.log("hi")');
// fs/process operations do not behave as the documented baseline implies
Reported against 0.2.15 and 0.2.16-rc.1 in #1884.
Suggested fix
Merge scope-by-scope over the baseline rather than replacing:
const hostPermissions = {
...allowAll,
binding: "allow",
...(options?.permissions ?? {}),
};
…with the binding auto-grant applied whenever bindings are registered, independent of whether an explicit policy was supplied. Either that, or update permissions.mdx to document replacement semantics — but the merge behavior is the one the docs promise and the safer default, since the failure mode of replacement is silent over-denial.
Worth a test asserting that { network: "allow" } leaves fs at its documented baseline, and that registering a binding with an explicit policy still grants binding.
/cc @Scorpion197 — this is the half of #1884 your PR intentionally doesn't cover.
- Ngôn ngữ chính
- Rust
- Star
- 4.7k
- Fork
- 263
- Merge trung bình
- 8 giờ 57 phút
- Pull request đã merge (30 ngày)
- 30
Chuẩn bị môi trường
Dự án này không cung cấp dev container, Dockerfile hay hướng dẫn đóng góp, nên bạn cần tự thiết lập môi trường: hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của rivet-dev/agentos
-
Python edits to filesystem.writeFile-created files are reverted by shadow reconciliationCó thể đã có người làm @ankssjain đã nhận 2 ngày trước. Đang mở
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 20/100
rivet-dev/agentos#2022 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 3/5 Nửa ngày Mức phù hợp với người mới 32/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 45/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 66/100
rivet-dev/agentos#1994 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 42/100
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của rivet-dev/agentos
Issue tương tự
-
status:needs-triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
agentic-os-org/ANOLISA#6742 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 67/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 90/100
Kc1t/alethe-agents#312 ·
Maintainer thường phản hồi trong vòng 3 ngày
-
api: storage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 74/100
googleapis/google-cloud-rust#7153 ·
Maintainer thường phản hồi trong vòng 1 ngày