fix(spawn): stage launch commands in a private per-spawn file and pin COMPACT_ADVISER_DISABLE - #139
Merged
Merged
Conversation
…ps with upstream Stage the launch command in a task temp root created 0700, refusing a pre-existing root that is not a real directory owned by this user or that others can write, and tightening one this user owns. Name each launch file for its spawn incarnation and never reuse or replace one, so a source line still buffered from an earlier incarnation cannot run a relaunch's command. Pin COMPACT_ADVISER_DISABLE=1 at the env -i boundary of the cleared launch environment, and keep the name in its operational floor, so the wrapping /bin/sh holds the switch before the launch command's own export.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Intent
Port two upstream firstmate improvements (upstream repository kunchenguid/firstmate) into this fork as our own changes. This fork is a hard fork: do not merge, rebase onto, or cherry-pick from upstream; read the upstream commits only as reference.
Both edit bin/fm-spawn.sh, so they ship in one pass.
What Changed
The main ports were already delivered before this PR: #95 (bac8c60) stages the launch command in a file and types only a short line sourcing it, and #115 (fdbd6e7) launches every spawned agent with
COMPACT_ADVISER_DISABLE=1through the pane export and the launch command's own export.This PR closes the remaining gap with upstream kunchenguid/firstmate#4994 and kunchenguid/firstmate#4877:
config/launch-env-allowlist,COMPACT_ADVISER_DISABLEjoins theenv -ioperational floor and a literalCOMPACT_ADVISER_DISABLE=1is pinned last on theenvprefix, so the wrapping/bin/shholds the switch before the launch command's own export and it overrides a forwarded pane value./tmp/fm-<id>is created withumask 077(0700). A pre-existing root is reused only as a real directory owned by this user that nobody else can write, and is tightened to 0700; anything else refuses the spawn before any launch, closing the endpoint a fresh spawn created.launch.<spawn_gen>.sh(0600) and refuses to replace an existing one, so a source line still buffered from an earlier incarnation cannot run a relaunch's command. Teardown already removes the whole temp root.Tests, each confirmed to fail by name under its mutant:
test_env_boundary_carries_the_switch_on_its_own(dropping theenv -iliteral reads0).test_spawn_stages_its_launch_in_a_private_root(root created withoutumask 077lands 755).test_spawn_refuses_a_task_temp_root_others_can_write(dropping the writable check launches from an open root; droppingchmod 700leaves a reused root 755).test_relaunch_never_reuses_a_launch_file(a fixed file name leaves one overwritten file).Risk Assessment
✅ Low: The change satisfies both intent items (launch file sourced from a short line, COMPACT_ADVISER_DISABLE carried three ways), the hardening of the temp root is bounded, and the new tests execute the emitted launch rather than grepping source.
Testing
Ran the three spawn tests this diff touches, each end to end against fm-spawn.sh. All passed. The launch-confirm test covers the 4772-byte command typed as lines of at most 86 bytes. Output of the last 25 lines of each run is in tests.log.
Evidence: test output
Source: test output
Pipeline
Updates from git push no-mistakes
✅ **intent** - passed
✅ No issues found.
✅ **Rebase** - passed
✅ No issues found.
✅ **Review** - passed
✅ No issues found.
✅ **Test** - passed
✅ No issues found.
bash tests/fm-spawn-launch-confirm.test.shbash tests/fm-spawn-compact-adviser-disable.test.shbash tests/fm-spawn-compact-adviser-disable-remote.test.sh✅ **Document** - passed
✅ No issues found.
✅ **Lint** - passed
✅ No issues found.
✅ **Push** - passed
✅ No issues found.