Skip to content

fix(memory): write the pending-deletion queue owner-only - #7147

Merged
senamakel merged 2 commits into
tinyhumansai:mainfrom
senamakel:memory-deletion-private-queue
Oct 8, 2026
Merged

senamakel merged 2 commits into
tinyhumansai:mainfrom
senamakel:memory-deletion-private-queue

Conversation

@senamakel

Copy link
Copy Markdown
Member

Follow-up to #7144/#7142: pending_deletions.json was written with std::fs::write, so it was not owner-only while every other memory file goes through memory::files (0600). It now uses create_private_dir_all and write_private. Test: the_pending_queue_is_owner_only.

Thread-delete forget and connector erasure go through the bound engine, which reads the retired user: root while legacy_user_segment_read is on, so they already cover the legacy path.

Co-authored-by: Medulla medulla@tinyhumans.ai

senamakel and others added 2 commits October 9, 2026 00:50
The pending deletion queue now creates its directory and writes its temp file through the private file helpers, matching the owner-only permissions used by the other memory files. The doc comment was updated to note this.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Add a Unix-only test verifying the pending deletion queue file is created
with no group or other permissions, guarding against accidental exposure
of queued thread ids.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
@tinysweeper

tinysweeper Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Tiny Sweeper review

Tiny Sweeper reviewed this change across 6 lane(s) and found 0 active actionable finding(s). Detailed lane evidence and any incomplete work are listed below.

State: Reviewing pending checks
Priority: low
Reviewed head: a4bc702d405e
Updated: 1791487597 (Unix time)

Review snapshot

Change surface Files Review signal Count
Production 1 Active findings 0
Tests 1 Noted findings 0
Documentation 0 Resolved findings 0
Configuration 0 Pending checks/questions 4

Completeness: Complete
Test assessment: No supported feature-to-test mapping was available; this does not mean tests are absent or passed.

What changed

The review could not produce a supported behavioral summary; inspect the cited changed surface and lane details below.

Features

None identified with supported citations.

Tests

No supported feature-to-test mapping was produced. Test execution is not inferred.

Findings

No active actionable findings.

Pending checks: Rust E2E (mock backend), Build Playwright E2E Artifact, E2E (Playwright / web lane), Desktop E2E (full suite, 3 OS)

Before merge

  • Wait for Rust E2E (mock backend), Build Playwright E2E Artifact, E2E (Playwright / web lane), Desktop E2E (full suite, 3 OS).
Agent review details

critique

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: The change makes the pending-deletion directory, temporary file, and queue file owner-only while preserving the existing atomic write flow. The accompanying Unix test covers the resulting queue-file permissions, and the change looks safe to merge. _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._

security

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: The change consistently writes the pending-deletion queue and its temporary file through the repository’s private-file helpers, and the accompanying Unix test verifies the resulting permissions. It looks safe to merge. _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._

tests

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: The change routes the pending-deletion queue through create_private_dir_all/write_private so the file and its directory are owner-only, and adds a unix test that fails if the file mode regresses. The behaviour is genuinely pinned. One minor point: the parent directory is created twice, since write_private already creates it. _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._

commits

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: Nothing sensitive found in what this pull request commits.

description

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: The change makes the pending-deletion queue write through memory::files' owner-only helpers (create_private_dir_all, write_private) exactly as described, and the named test the_pending_queue_is_owner_only is present and asserts the file mode. Description matches the diff; looks sound. _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._

e2e

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: The change hardens the pending-deletion queue file to owner-only permissions (create_private_dir_all/write_private) plus a Unix unit test asserting the mode. This is filesystem-permission hardening of internal state with no user-, client- or operator-facing surface an E2E harness drives; the new unit test covers it directly. No E2E test change was needed and none was made; the behavioural change looks sound and safe to merge from the end-to-end coverage perspective. Waiting on end-to-end jobs: `Rust E2E (mock backend)`, `Build Playwright E2E Artifact`, `E2E (Playwright / web lane)`, `Desktop E2E (full suite, 3 OS)`.
  • Unresolved questions/checks: Rust E2E (mock backend), Build Playwright E2E Artifact, E2E (Playwright / web lane), Desktop E2E (full suite, 3 OS)
Evidence and run details
  • Models: gpt-5.6-luna, glm-5.3-flash
  • Spend: $0.001331
  • Tokens: 39583 input · 3230 output · 0 cached · 0 embedding
Head State Pass summary
a4bc702d405e pending 0 active finding(s), 0 resolved finding(s) (at 1791487597)

tinysweeper 0.1.0

@senamakel
senamakel merged commit 40d6c50 into tinyhumansai:main Oct 8, 2026
11 of 14 checks passed
@coderabbitai

coderabbitai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: d31c3e9c-e039-46d7-a3f8-eb8ef772ca4f
📥 Commits

Reviewing files that changed from the base of the PR and between e0481a4 and a4bc702.

📒 Files selected for processing (2)
  • crates/openhuman-core/src/memory/deletion.rs
  • crates/openhuman-core/src/memory/deletion_tests.rs
 _______________________________________________________
< Once upon a dream, I found all the bugs in your code. >
 -------------------------------------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tinysweeper found nothing blocking. Approving.

             $0.0013 · 39,583 in / 3,230 out · 0 cached (0%) · gpt-5.6-luna, glm-5.3-flash
critique:    $0.0006 · 8,775 in  / 575 out   · 0 cached (0%) · gpt-5.6-luna
security:    $0.0005 · 8,531 in  / 510 out   · 0 cached (0%) · gpt-5.6-luna
tests:       $0.0001 · 10,554 in / 661 out   · 0 cached (0%) · glm-5.3-flash
description: $0.0000 · 3,836 in  / 224 out   · 0 cached (0%) · glm-5.3-flash
e2e:         $0.0001 · 5,213 in  / 344 out   · 0 cached (0%) · glm-5.3-flash

@tinysweeper tinysweeper Bot added the priority: p3 Whenever. Cosmetic, a nicety, or a cleanup with no user visible effect. label Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

priority: p3 Whenever. Cosmetic, a nicety, or a cleanup with no user visible effect.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant