Repository navigation
fix(memory): write the pending-deletion queue owner-only - #7147
Conversation
The pending deletion queue now creates its directory and writes its temp file through the private file helpers, matching the owner-only permissions used by the other memory files. The doc comment was updated to note this. Auto-committed-on: macbook Co-authored-by: Medulla <medulla@tinyhumans.ai>
Add a Unix-only test verifying the pending deletion queue file is created with no group or other permissions, guarding against accidental exposure of queued thread ids. Auto-committed-on: macbook Co-authored-by: Medulla <medulla@tinyhumans.ai>
Tiny Sweeper reviewTiny Sweeper reviewed this change across 6 lane(s) and found 0 active actionable finding(s). Detailed lane evidence and any incomplete work are listed below. State: Reviewing pending checks Review snapshot
Completeness: Complete What changedThe review could not produce a supported behavioral summary; inspect the cited changed surface and lane details below. FeaturesNone identified with supported citations. TestsNo supported feature-to-test mapping was produced. Test execution is not inferred. FindingsNo active actionable findings. Pending checks: Rust E2E (mock backend), Build Playwright E2E Artifact, E2E (Playwright / web lane), Desktop E2E (full suite, 3 OS) Before merge
Agent review detailscritique
security
tests
commits
description
e2e
Evidence and run details
|
|
Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configuration
📒 Files selected for processing (2)
Comment |
There was a problem hiding this comment.
tinysweeper found nothing blocking. Approving.
$0.0013 · 39,583 in / 3,230 out · 0 cached (0%) · gpt-5.6-luna, glm-5.3-flash
critique: $0.0006 · 8,775 in / 575 out · 0 cached (0%) · gpt-5.6-luna
security: $0.0005 · 8,531 in / 510 out · 0 cached (0%) · gpt-5.6-luna
tests: $0.0001 · 10,554 in / 661 out · 0 cached (0%) · glm-5.3-flash
description: $0.0000 · 3,836 in / 224 out · 0 cached (0%) · glm-5.3-flash
e2e: $0.0001 · 5,213 in / 344 out · 0 cached (0%) · glm-5.3-flash
Follow-up to #7144/#7142: pending_deletions.json was written with std::fs::write, so it was not owner-only while every other memory file goes through memory::files (0600). It now uses create_private_dir_all and write_private. Test: the_pending_queue_is_owner_only.
Thread-delete forget and connector erasure go through the bound engine, which reads the retired user: root while legacy_user_segment_read is on, so they already cover the legacy path.
Co-authored-by: Medulla medulla@tinyhumans.ai