Skip to content

Document agent.configScope and the agent's filesystem scopes, including what every scope refuses - #717

Open
DavidCockerill wants to merge 6 commits into
mainfrom
david/agent-config-scope
Open

DavidCockerill wants to merge 6 commits into
mainfrom
david/agent-config-scope

Conversation

@DavidCockerill

@DavidCockerill DavidCockerill commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

⊙ Problem

HarperFast/harper#3041 narrows the built-in agent's read-only config filesystem scope from the whole Harper root to the config file. It also adds agent.configScope, and makes the agent's filesystem tools refuse key material in every scope. The reference still says read_file covers "the log and configuration directories", and it documents neither the new key nor the refusal rules. Refs HarperFast/harper#3041 · Refs #674 · Feature PR: HarperFast/harper#3098

❓ Your call: Is a docs change warranted? Yes as specified: an operator judging the agent's privilege boundary reads these two pages, and both would be wrong after the code PR lands.

💡 Solution

❓ Your call: Before merging, reconcile with #712 (Document agent.maxTokens…): it edits the same agent option list and the set_agent_config accepted/rejected keys.

❓ Your call: The badges say v5.4.0, because the code PR lands on main (milestone v5.4) with no 5.3.x cherry-pick. The section badge is type="changed", because the config scope existed and was narrowed.

❓ Your call: It adds a 5.4.md release-notes entry, because the narrowed default changes what an existing agent can read on upgrade.

✅ Verification

  • Every claim was checked against the code branch. Three review rounds, each adjudicated by the Harper-domain pass, verified each claim against the implementation (agent/agent.ts resolveScopes, agent/tools/fsTools.ts resolveScoped, agent/operations.ts) and its unit tests.
  • Prettier passes with the shared @harperfast/code-guidelines config.

🤖 Generated by Claude Opus 5.5 (Claude Code); posted via @DavidCockerill.

Related PRs: #712 overlaps (same agent option list and set_agent_config accepted/rejected keys; reconcile on rebase), #709 overlaps (both add a 5.4.md release-notes section; textual), #671 overlaps (agent wording near the privilege-boundary bullets; textual), #676 independent, #683 independent, #691 independent, #697 independent, #713 independent, #710 independent, #707 independent
Complexity: easy

Review-Coverage: authored=claude; ran=gemini,codex; adjudicated=domain; blocked=cursor-composer(not-installed); declined=cursor-grok,cursor-kimi,cursor-muse; rounds=3; full=1 @ 2f14755

Review-Attention: skim ~2m (decisions: configscope-replaces-default, release-notes-placement, scopes-section-home, tail-edge-precision) @ 2f14755

DavidCockerill and others added 5 commits October 6, 2026 11:39
…ng the key-material refusal

Refs HarperFast/harper#3041

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…dened scopes reach further, and the badge marks a change

Refs HarperFast/harper#3041

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…instead of claiming all key material

Refs HarperFast/harper#3041

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…4 release notes

Refs HarperFast/harper#3041

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…er than adding to it

Refs HarperFast/harper#3041

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the documentation and release notes for version 5.4.0 to reflect security-focused changes to the agent's filesystem scopes. Specifically, it documents the new configScope option, details how the default config scope is now restricted to the configuration file itself rather than its parent directory, and outlines how the agent refuses access to sensitive key directories, key files, and PEM private keys. It also specifies that componentsScope and configScope are read at startup only and cannot be modified at runtime. The review feedback suggests refactoring a dense security warning in the operations API documentation into shorter, distinct sentences to improve readability and ensure critical risks are easily scannable.

Comment thread reference/operations-api/operations.md Outdated
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

🚀 Preview Deployment

Your preview deployment is ready!

🔗 Preview URL: https://preview.harper-documentation.harperfabric.com/pr-717

This preview will update automatically when you push new commits.

Refs HarperFast/harper#3041

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

🚀 Preview Deployment

Your preview deployment is ready!

🔗 Preview URL: https://preview.harper-documentation.harperfabric.com/pr-717

This preview will update automatically when you push new commits.

@DavidCockerill
DavidCockerill marked this pull request as ready for review October 8, 2026 14:02
@DavidCockerill
DavidCockerill requested a review from a team as a code owner October 8, 2026 14:02

@kriszyp kriszyp left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Reviewed with Codex


- **Harper's key directories**, `<rootPath>/keys` (TLS and JWT keys) and `<rootPath>/ssh` (git deploy keys): nothing in them is read, listed, or written. Paths are compared after resolving symlinks.
- **Key file names**, `*.pem`, `*.key`, and `.jwtPass`: not read. `list_dir` still shows the names, and `write_file` can still create such a file outside the key directories.
- **Text holding a PEM private key** (`-----BEGIN ... PRIVATE KEY-----`), such as an inline `tls.privateKey` in the config file: `read_file` refuses the file, `tail_file` refuses lines that hold one or a file that ends partway through one, and `grep_files` skips the file.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could we fix the core tail_file boundary before promising that a file ending partway through a PEM private key is refused? Its implementation scans only the final 1 MiB plus 64 bytes for the BEGIN marker. If a PEM block in a non-key-named file such as log.txt starts earlier and continues to EOF, tail_file can return trailing base64 key text. This is a code-trace finding; I did not execute a test. A focused check is such a file with BEGIN more than 1 MiB before EOF: tail_file should refuse it. Please make core fail closed for that case, or state the actual limit here and in the release note.

This branch was successfully deployed

1 active deployment
pr-717 — 2f147550 Deployed Oct 7, 2026 by github-actions[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants