Skip to content

fix(deploy): keep local config.toml mirror inside the Config folder (studio#135) - #166

Open
Reese-max wants to merge 2 commits into
openabdev:mainfrom
Reese-max:devin/issue-135
Open

Reese-max wants to merge 2 commits into
openabdev:mainfrom
Reese-max:devin/issue-135

Conversation

@Reese-max

Copy link
Copy Markdown

Refs #135

Summary

The studio#135 mirror (write_local_agent_config → <config folder>/<name>/config.toml, wired in #136) joined a caller-controlled name straight into the Config-folder path. deploy_provision_agent is a public MCP tool — the console wizard's free-text Agent-name field or a direct MCP/"admin agent" call — so name = "../x", a/b, or an absolute path escaped the folder and wrote config.toml wherever the sidecar can reach, before the deploy could reject the bad name. This also weakened the local-first ordering the feature promises: the local write could "succeed" on a name the deploy later refuses.

  • studio_cp::write_local_agent_config now refuses anything that isn't a single normal path component (.., ., embedded /, absolute paths) before any filesystem write; \ is refused explicitly since Path::components only treats it as a separator on Windows.
  • Same guard on the sibling read path read_local_agent_config (src-tauri) — review flagged it performing the same unsanitized join.
  • The function is pub and exercised by a new integration test (crates/studio-cp/tests/local_agent_config.rs) covering plain names, every traversal shape, and that a refused name writes nothing anywhere.
  • deploy_provision_agent's local_config_folder schema description now documents the refusal.

Also includes a separate chore: commit normalizing workspace formatting + satisfying clippy under the current stable toolchain (same precondition the #104/#163 branches needed for these gates).

Test plan

  • cargo test -p studio-cp --test local_agent_config — 2/2 pass
  • cargo fmt --all -- --check, cargo test --workspace (225 tests), cargo clippy --workspace --all-targets -- -D warnings — all clean
  • fleet verify_issue.py — all five gates pass (incl. red replay: test fails compile on base because the fn was private)

Generated with Devin

cognition-team and others added 2 commits September 30, 2026 22:50
Precondition work so the rust toolchain gates pass at all — the workspace
was written before this box's rustfmt/clippy, and the current toolchain
reformats it and fires lints on the existing code:

- cargo fmt --all (mechanical, no semantic change)
- studio-compose: implement std::iter::FromIterator for SkillsLibrary
  instead of an inherent from_iter (should_implement_trait)
- studio-cp: derive Default for FleetRuntime (derivable_impls); use `?` in
  role_identity (question_mark); crate-level allow too_many_arguments for
  the flat dispatch-arg provision/observe API — same class of allowance
  already used on this call surface's callers.

Same normalization the still-open openabdev#163 branch landed for the same gates;
no behavior change intended.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
…studio#135)

The studio#135 mirror writes `<folder>/<name>/config.toml` from inside the
sidecar before anything touches S3, but `name` went straight into
`Path::join` — and `deploy_provision_agent` is a public MCP tool any caller
(the console wizard's free-text Agent-name field, or a direct "admin agent"
call) can drive. A `name` of `../x`, `a/b`, or an absolute path escaped the
operator's Config folder and wrote `config.toml` wherever the sidecar can
reach — and the local mirror "succeeding" before the deploy later fails on
a bad name also broke the local-first ordering the feature promises.

write_local_agent_config now refuses anything that isn't a single normal
path component (rejects `..`, `.`, embedded separators — `\` explicitly,
since it's only a separator on Windows — and absolute paths) before any
filesystem write, and is `pub` so the containment contract is exercised
directly by an integration test.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants