Repository navigation
Document agent.configScope and the agent's filesystem scopes, including what every scope refuses - #717
Document agent.configScope and the agent's filesystem scopes, including what every scope refuses#717DavidCockerill wants to merge 6 commits into
Conversation
…ng the key-material refusal Refs HarperFast/harper#3041 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…dened scopes reach further, and the badge marks a change Refs HarperFast/harper#3041 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…instead of claiming all key material Refs HarperFast/harper#3041 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…4 release notes Refs HarperFast/harper#3041 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…er than adding to it Refs HarperFast/harper#3041 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
Code Review
This pull request updates the documentation and release notes for version 5.4.0 to reflect security-focused changes to the agent's filesystem scopes. Specifically, it documents the new configScope option, details how the default config scope is now restricted to the configuration file itself rather than its parent directory, and outlines how the agent refuses access to sensitive key directories, key files, and PEM private keys. It also specifies that componentsScope and configScope are read at startup only and cannot be modified at runtime. The review feedback suggests refactoring a dense security warning in the operations API documentation into shorter, distinct sentences to improve readability and ensure critical risks are easily scannable.
🚀 Preview DeploymentYour preview deployment is ready! 🔗 Preview URL: https://preview.harper-documentation.harperfabric.com/pr-717 This preview will update automatically when you push new commits. |
Refs HarperFast/harper#3041 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
🚀 Preview DeploymentYour preview deployment is ready! 🔗 Preview URL: https://preview.harper-documentation.harperfabric.com/pr-717 This preview will update automatically when you push new commits. |
|
|
||
| - **Harper's key directories**, `<rootPath>/keys` (TLS and JWT keys) and `<rootPath>/ssh` (git deploy keys): nothing in them is read, listed, or written. Paths are compared after resolving symlinks. | ||
| - **Key file names**, `*.pem`, `*.key`, and `.jwtPass`: not read. `list_dir` still shows the names, and `write_file` can still create such a file outside the key directories. | ||
| - **Text holding a PEM private key** (`-----BEGIN ... PRIVATE KEY-----`), such as an inline `tls.privateKey` in the config file: `read_file` refuses the file, `tail_file` refuses lines that hold one or a file that ends partway through one, and `grep_files` skips the file. |
There was a problem hiding this comment.
Could we fix the core tail_file boundary before promising that a file ending partway through a PEM private key is refused? Its implementation scans only the final 1 MiB plus 64 bytes for the BEGIN marker. If a PEM block in a non-key-named file such as log.txt starts earlier and continues to EOF, tail_file can return trailing base64 key text. This is a code-trace finding; I did not execute a test. A focused check is such a file with BEGIN more than 1 MiB before EOF: tail_file should refuse it. Please make core fail closed for that case, or state the actual limit here and in the release note.
⊙ Problem
HarperFast/harper#3041 narrows the built-in agent's read-only
configfilesystem scope from the whole Harper root to the config file. It also addsagent.configScope, and makes the agent's filesystem tools refuse key material in every scope. The reference still saysread_filecovers "the log and configuration directories", and it documents neither the new key nor the refusal rules. Refs HarperFast/harper#3041 · Refs #674 · Feature PR: HarperFast/harper#3098💡 Solution
reference/configuration/options.md:configScopeoption.componentsScopeaccepts absolute paths and, withhttpFetchandconfigScope, is read at startup only.config, and howconfigScopereplaces the default.release-notes/v5-lincoln/5.4.md: an Agent entry for the narrowed default,configScope, and the refusal rules.reference/operations-api/operations.md:read_filereaches by default, what it reached before v5.4.0, and that widened scopes reach further.set_agent_configlistscomponentsScopeandconfigScopeas rejected with a 400.✅ Verification
agent/agent.tsresolveScopes,agent/tools/fsTools.tsresolveScoped,agent/operations.ts) and its unit tests.@harperfast/code-guidelinesconfig.🤖 Generated by Claude Opus 5.5 (Claude Code); posted via @DavidCockerill.
Related PRs: #712 overlaps (same agent option list and set_agent_config accepted/rejected keys; reconcile on rebase), #709 overlaps (both add a 5.4.md release-notes section; textual), #671 overlaps (agent wording near the privilege-boundary bullets; textual), #676 independent, #683 independent, #691 independent, #697 independent, #713 independent, #710 independent, #707 independent
Complexity: easy
Review-Coverage: authored=claude; ran=gemini,codex; adjudicated=domain; blocked=cursor-composer(not-installed); declined=cursor-grok,cursor-kimi,cursor-muse; rounds=3; full=1 @ 2f14755
Review-Attention: skim ~2m (decisions: configscope-replaces-default, release-notes-placement, scopes-section-home, tail-edge-precision) @ 2f14755