mirror of
https://github.com/garrytan/gstack.git
synced 2026-09-27 07:01:54 +02:00
v1.88.1.0 fix: harden credential boundaries and owned state (#2942)
* fix(settings): preserve symlinked settings targets
Resolve the selected target for locking, mutation, backup, and rollback; refuse target changes and preserve private modes. Addresses #2830.
* fix(redact): bind masking to original detected spans
Inspired by #2929's anchored-span diagnosis; independently implemented using normalization offsets. Addresses #2930 and the relocation portion of #2912 without changing detection sensitivity.
* fix(evals): exclude operator credentials from prefix admission
Adapts the credential-suffix screen proposed in #2636, with real launched-child regression coverage and deliberate provider-auth exceptions.
* fix(artifacts): retain custom allowlist rules on reinitialization
Preserve the exact user-owned suffix and publish only a successfully assembled replacement. Independently implements the repair reported in #2907.
* test(cso): verify exact masked reads and unmaskable payload refusal
* fix(cso): preserve exact filesystem identities through lease recovery
Preserve 64-bit device/inode identity and nanosecond race checks. Add native NTFS lifecycle coverage for #2927; retain ambiguous legacy-state refusal without claiming Windows PID-reuse recovery is resolved.
* fix(redact): bind pre-push scans to destination and preserve seam context
Uses #2935 (bd07318) as source evidence for push-target range and slice-overlap defects. Independently implemented; no cherry-pick or release metadata adoption.
* test(ci): gate native agent ownership and settings links on macOS
* fix(browse): bind agent lifetimes and cleanup to owned generations
Uses #2931 by Chris Hutton / Claude Fable 5.1 as attributed design input; independently implemented without broad sweeps or copied code. Keep uncertain children and locks rather than deleting foreign state.
* test(ci): include concurrent shutdown controls in the native macOS gate
* v1.88.1.0 fix: harden credential boundaries and owned state
* fix(redact): preserve target provenance and scan boundary semantics
* test(artifacts): read managed rules from atomic allowlist assembly
* fix: preserve native exit observations and fixture prerequisites
* fix: preserve UTF-16 offsets through redaction normalization
This commit is contained in:
@@ -277,7 +277,13 @@ cat > "$GSTACK_HOME/.gitignore" <<'EOF'
|
||||
*
|
||||
EOF
|
||||
|
||||
cat > "$GSTACK_HOME/.brain-allowlist" <<'EOF'
|
||||
ALLOWLIST="$GSTACK_HOME/.brain-allowlist"
|
||||
ALLOWLIST_TMP=$(mktemp "$GSTACK_HOME/.brain-allowlist.XXXXXX")
|
||||
ALLOWLIST_ASSEMBLED=$(mktemp "$GSTACK_HOME/.brain-allowlist.XXXXXX")
|
||||
trap 'rm -f "$ALLOWLIST_TMP" "$ALLOWLIST_ASSEMBLED"' EXIT
|
||||
ALLOWLIST_MARKER='# ---- USER ADDITIONS BELOW ---- (survives re-init; above is managed)'
|
||||
|
||||
cat > "$ALLOWLIST_TMP" <<'EOF'
|
||||
# Canonical allowlist of paths that gstack-brain-sync will publish.
|
||||
# One glob per line. Anything not matching stays local.
|
||||
# Do not edit directly; managed by gstack-artifacts-init. User additions go
|
||||
@@ -325,6 +331,33 @@ transcripts/run-*/**/*.md
|
||||
# ---- USER ADDITIONS BELOW ---- (survives re-init; above is managed)
|
||||
EOF
|
||||
|
||||
if [ -s "$ALLOWLIST" ]; then
|
||||
if marker_count=$(grep -Fxc "$ALLOWLIST_MARKER" "$ALLOWLIST"); then
|
||||
:
|
||||
else
|
||||
grep_status=$?
|
||||
if [ "$grep_status" -gt 1 ]; then
|
||||
echo "gstack-artifacts-init: could not read $ALLOWLIST; refusing to replace it" >&2
|
||||
exit 1
|
||||
fi
|
||||
marker_count=0
|
||||
fi
|
||||
if [ "$marker_count" -ne 1 ]; then
|
||||
if [ "$marker_count" -eq 0 ]; then reason="has no managed marker"; else reason="has multiple managed markers"; fi
|
||||
echo "gstack-artifacts-init: $ALLOWLIST $reason; refusing to replace ambiguous user data" >&2
|
||||
exit 1
|
||||
fi
|
||||
marker_line=$(grep -nFx "$ALLOWLIST_MARKER" "$ALLOWLIST" | cut -d: -f1)
|
||||
suffix_start=$(head -n "$marker_line" "$ALLOWLIST" | wc -c)
|
||||
cp -p "$ALLOWLIST" "$ALLOWLIST_ASSEMBLED"
|
||||
: > "$ALLOWLIST_ASSEMBLED"
|
||||
cat "$ALLOWLIST_TMP" >> "$ALLOWLIST_ASSEMBLED"
|
||||
tail -c +"$((suffix_start + 1))" "$ALLOWLIST" >> "$ALLOWLIST_ASSEMBLED"
|
||||
else
|
||||
cat "$ALLOWLIST_TMP" > "$ALLOWLIST_ASSEMBLED"
|
||||
fi
|
||||
mv -f "$ALLOWLIST_ASSEMBLED" "$ALLOWLIST"
|
||||
|
||||
cat > "$GSTACK_HOME/.brain-privacy-map.json" <<'EOF'
|
||||
[
|
||||
{"pattern": "projects/*/learnings.jsonl", "class": "artifact"},
|
||||
|
||||
Reference in New Issue
Block a user