Skip to content

docs(security): document the inbox symlink-containment guard - #333

Merged
glifocat merged 1 commit into
mainfrom
drift/security-inbox-guard
Jul 2, 2026
Merged

glifocat merged 1 commit into
mainfrom
drift/security-inbox-guard

Conversation

@glifocat

@glifocat glifocat commented Jul 2, 2026

Copy link
Copy Markdown
Owner

What

Adds a paragraph to Security model → Container isolation documenting the shared inbox symlink-containment guard, newly modularized upstream as src/inbox-safety.ts in v2.1.22.

Why

Upstream PR nanocoai/nanoclaw#2880 (commits dd1d0e5, 36afa40) contained channel-inbound attachments and agent-to-agent forwarded files via a shared guard: lstat of the inbox root and the per-message subdir (reject symlinks), realpath containment check, and exclusive-create write flags (wx / COPYFILE_EXCL). The security page already documents the sibling symlink defense in the mount allowlist, but this host-write vector (CWE-59) was uncovered.

Verification

  • Read src/inbox-safety.ts in full at origin/main and both call-site diffs over 2afbd182..cb6e3d1
  • All other page claims re-verified at cb6e3d1 (v2.1.23); verified-against bumped with src/inbox-safety.ts, src/session-manager.ts, and agent-route.ts added to citations
  • mint validate passes

Part of the v2.1.21→v2.1.23 drift sweep.

🤖 Generated with Claude Code

Upstream v2.1.22 promoted the inline inbox-containment checks into a
dedicated module, src/inbox-safety.ts (PR #2880, commits dd1d0e5 and
36afa40), and hardened them: the inbox ROOT is now lstat'd too, and
both write paths (channel attachments and agent-to-agent forwards) go
through the shared guard with exclusive-create flags.

The security page covered the mount-allowlist symlink defense but not
this host-write containment — add a paragraph under Container
isolation and cite the new module.

Re-verified all cited files at cb6e3d1 (v2.1.23); anchor bumped.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@glifocat glifocat added the update-existing Requires updating an existing page label Jul 2, 2026
@mintlify

mintlify Bot commented Jul 2, 2026 •

Copy link
Copy Markdown
Contributor

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated (UTC)
nanoclaw-docs 🟢 Ready View Preview Jul 2, 2026, 11:33 AM

💡 Tip: Enable Workflows to automatically generate PRs for you.

@glifocat
glifocat merged commit b8ab2a2 into main Jul 2, 2026
3 checks passed
@glifocat
glifocat deleted the drift/security-inbox-guard branch July 2, 2026 11:35
glifocat added a commit that referenced this pull request Jul 2, 2026
…t, tag hygiene (#336)

- Bump verified-against anchors site-wide: trunk 2afbd182 -> cb6e3d1
  (v2.1.23), channels fdbfb6a -> 90dd87d. Every page's cited files were
  classified against the range diffs; the dirty set was re-verified
  claim-by-claim (content fixes landed separately in #333/#334/#335),
  the rest had no cited-file changes.
- Fix transposed providers-branch anchor on extend/providers
  (c576766 -> c570766; branch head unchanged since 2026-06-23).
- Token count 199k -> 204k in introduction and concepts/contributing
  (contributing still said 195k — missed by the previous sweep).
- Product changelog: add v2.1.22 (inbox symlink containment #2828,
  ncl messaging-groups instance default) and v2.1.23 (container
  claude-code/agent-SDK/Anthropic-SDK bumps). Slack Socket Mode setup
  (cf8478f) is post-2.1.23 and intentionally not listed yet.
- Docs changelog: v2.1.23 drift sweep entry.
- Sidebar tag hygiene: UPDATED capped at 10 — stripped from 7 pages
  whose 2026-06-29 sweep changes were least substantive.

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
glifocat added a commit that referenced this pull request Jul 4, 2026
…333)

Upstream v2.1.22 promoted the inline inbox-containment checks into a
dedicated module, src/inbox-safety.ts (PR #2880, commits dd1d0e5 and
36afa40), and hardened them: the inbox ROOT is now lstat'd too, and
both write paths (channel attachments and agent-to-agent forwards) go
through the shared guard with exclusive-create flags.

The security page covered the mount-allowlist symlink defense but not
this host-write containment — add a paragraph under Container
isolation and cite the new module.

Re-verified all cited files at cb6e3d1 (v2.1.23); anchor bumped.

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
glifocat added a commit that referenced this pull request Jul 4, 2026
…t, tag hygiene (#336)

- Bump verified-against anchors site-wide: trunk 2afbd182 -> cb6e3d1
  (v2.1.23), channels fdbfb6a -> 90dd87d. Every page's cited files were
  classified against the range diffs; the dirty set was re-verified
  claim-by-claim (content fixes landed separately in #333/#334/#335),
  the rest had no cited-file changes.
- Fix transposed providers-branch anchor on extend/providers
  (c576766 -> c570766; branch head unchanged since 2026-06-23).
- Token count 199k -> 204k in introduction and concepts/contributing
  (contributing still said 195k — missed by the previous sweep).
- Product changelog: add v2.1.22 (inbox symlink containment #2828,
  ncl messaging-groups instance default) and v2.1.23 (container
  claude-code/agent-SDK/Anthropic-SDK bumps). Slack Socket Mode setup
  (cf8478f) is post-2.1.23 and intentionally not listed yet.
- Docs changelog: v2.1.23 drift sweep entry.
- Sidebar tag hygiene: UPDATED capped at 10 — stripped from 7 pages
  whose 2026-06-29 sweep changes were least substantive.

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

This branch was successfully deployed

1 active deployment
staging — 6a9b6288 Deployed Jul 2, 2026 by mintlify[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

update-existing Requires updating an existing page

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant