You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Provider-OAuth connection documents must not trade same-object publication authority for pathname convenience. POSIX renameat() constrains namespace resolution with directory descriptors but still consumes a source pathname; that is not proof that final mutation consumed the exact opened/reviewed source object. DiskSage therefore keeps existing-record replacement unavailable rather than presenting repeated pathname checks as exact-source-object mutation.
provider-OAuth security: reject unknown OAuth connection authority fields #339 exact f32eba19df3f8e087cc1390d074d3d844f22ba01 is ordinary/non-force on exact security: restore object-bound private evidence publication #344. Its predecessor 450772c9... reproduced the Ubuntu full-Rust-suite RED four times; attempt-4 job 102334279549 identified a rustfmt-sensitive source-contract assertion although production already obtained metadata and bounded bytes from the same opened File handle. f32eba19... fixes only the test; production authority is unchanged. Exact Test 34314249490 is terminal SUCCESS;
canonical Test owner fix(ci): repair contract-doc path filtering #338 is exact 8b0e2b529bff0640cef87e2aa7b6c15f40c28655, ordinarily restacked onto exact fix: verify Windows release artifact namespace #264. Test-first 13aa167... requires Windows provider_oauth_cli_process whenever its owner source exists; exact 8b0e2b... adds the canonical conditional execution. Test 34318110278 is non-terminal: macOS 102358542894, Windows 102358543010, and real llama.cpp CPU/FFI 102358542989 are GREEN while Ubuntu 102358543004 remains in progress. The Windows log explicitly says SKIP provider_oauth_cli_process: owner test source absent; no runtime regression executed, so this owner head has workflow-admission evidence only;
POSIX.1-2024 rename()/renameat() are pathname operations; directory descriptors constrain resolution but do not turn a source pathname into an opened-file-handle precondition. Linux O_TMPFILE/linkat(..., AT_EMPTY_PATH) are platform-specific and do not by themselves provide a portable existing-destination replacement contract.
Microsoft exposes handle-oriented rename metadata through FILE_RENAME_INFO.RootDirectory and SetFileInformationByHandle(FileRenameInfo), but DiskSage still needs a complete design binding temporary creation, final replacement, reparse handling, cleanup, ACL/privacy policy, and durability to accepted native handles.
Production fail-closes existing-record replacement when exact-source-object mutation cannot be proved. Create-new publication remains separate and retains exact private-mode admission, descriptor-relative no-follow authority, absolute destination/policy boundaries, exact opened/final identity and byte verification, bounded final reads/serialization, exact-private parent requirements, and descriptor-bound cleanup. Missing-parent pathname provisioning and delete-and-create replacement are not authorized shortcuts.
First-create behavior stays distinct from replacement. Failure cleanup must never pathname-unlink an unrelated replacement object.
Unix durable connection-document load admission remains exact 0600; error classification must not turn pathname metadata into read/mutation authority.
Any future Unix/macOS enabled replacement must prove at the final identity-check→mutation boundary that the object mutated is the exact reviewed source. Another pathname recheck is insufficient.
Windows must pin directory/file namespace authority with native handles through temporary creation and final replacement, reject reparse drift, enforce private ACL policy, define data/namespace flush behavior, and fail closed when unavailable.
macOS evidence must name the persistence primitive actually exercised and not claim stronger power-loss durability than demonstrated.
No source copy into fix: make cloud operational help a successful terminal action #212 or sibling services; DiskSage retains filesystem invariants through owner contracts. Exact-head applicable Test/Release/Security/SAST/CodeQL/coverage/review evidence must be terminal success before integration.
Close only after #212 inherits the exact current owner contracts with its own source-present GREEN evidence, Windows parity is addressed for every exposed update path, and any future enabled replacement has adversarial real-filesystem exact-source and durability evidence.
Buyer/security gap
Provider-OAuth connection documents must not trade same-object publication authority for pathname convenience. POSIX
renameat()constrains namespace resolution with directory descriptors but still consumes a source pathname; that is not proof that final mutation consumed the exact opened/reviewed source object. DiskSage therefore keeps existing-record replacement unavailable rather than presenting repeated pathname checks as exact-source-object mutation.Current exact owner evidence — 2026-09-09 KST
main:0e90f9cebadbd7f59606baaec4ca1d2f178c899a;90ca44841891d98615b11117de0f35adf917cc31; Release/Test/SAST/Security are terminal GREEN. Required CodeQL/OpenCode/Noema/Strix and one-human-approval governance remain non-passing;e72f75d273f01a63a04b24ac421de9ed99734c44, open/Draft and exact-head GREEN. Test34163872423, SAST/Security/Secret Scan/Docs are terminal success;f32eba19df3f8e087cc1390d074d3d844f22ba01is ordinary/non-force on exact security: restore object-bound private evidence publication #344. Its predecessor450772c9...reproduced the Ubuntu full-Rust-suite RED four times; attempt-4 job102334279549identified a rustfmt-sensitive source-contract assertion although production already obtained metadata and bounded bytes from the same openedFilehandle.f32eba19...fixes only the test; production authority is unchanged. Exact Test34314249490is terminal SUCCESS;8b1edb0e079a72fa6fa9a803fb46075266f987b8, ordinary two-parent non-force on exact security: reject unknown OAuth connection authority fields #339, with its 13-file CLI delta retained. Test34317460873is non-terminal: Windows home-resolution102356579751and real llama.cpp CPU/FFI102356579596are GREEN; Ubuntu full Test102356579555remains in progress;.github/workflows/provider-oauth-windows.ymlhas produced no Actions run on the inspected predecessor/current fix: make cloud operational help a successful terminal action #212 heads. That cannot be counted as Windows provider-process evidence and is also a shared-Test single-writer violation;8b0e2b529bff0640cef87e2aa7b6c15f40c28655, ordinarily restacked onto exact fix: verify Windows release artifact namespace #264. Test-first13aa167...requires Windowsprovider_oauth_cli_processwhenever its owner source exists; exact8b0e2b...adds the canonical conditional execution. Test34318110278is non-terminal: macOS102358542894, Windows102358543010, and real llama.cpp CPU/FFI102358542989are GREEN while Ubuntu102358543004remains in progress. The Windows log explicitly saysSKIP provider_oauth_cli_process: owner test source absent; no runtime regression executed, so this owner head has workflow-admission evidence only;8eff6c663af94a1cce140a277af920e0f8ba02ccand now records the current security: reject unknown OAuth connection authority fields #339/fix: make cloud operational help a successful terminal action #212/fix(ci): repair contract-doc path filtering #338 topology indocs/product-technical-gap-baseline.md. Predecessor99eee633...Test34314459845is GREEN; fresh successor Test34318708189is queued and predecessor evidence does not transfer.Authoritative platform contract
POSIX.1-2024
rename()/renameat()are pathname operations; directory descriptors constrain resolution but do not turn a source pathname into an opened-file-handle precondition. LinuxO_TMPFILE/linkat(..., AT_EMPTY_PATH)are platform-specific and do not by themselves provide a portable existing-destination replacement contract.rename()/renameat(): https://pubs.opengroup.org/onlinepubs/9799919799/functions/rename.htmlopen(): https://pubs.opengroup.org/onlinepubs/9799919799/functions/open.htmlrenameat(2): https://man7.org/linux/man-pages/man2/rename.2.htmlopen(2)/O_TMPFILE: https://man7.org/linux/man-pages/man2/open.2.htmllinkat(2)/AT_EMPTY_PATH: https://man7.org/linux/man-pages/man2/link.2.htmlMicrosoft exposes handle-oriented rename metadata through
FILE_RENAME_INFO.RootDirectoryandSetFileInformationByHandle(FileRenameInfo), but DiskSage still needs a complete design binding temporary creation, final replacement, reparse handling, cleanup, ACL/privacy policy, and durability to accepted native handles.FILE_RENAME_INFO: https://learn.microsoft.com/en-us/windows/win32/api/winbase/ns-winbase-file_rename_infoSetFileInformationByHandle: https://learn.microsoft.com/en-us/windows/win32/api/fileapi/nf-fileapi-setfileinformationbyhandleOn macOS, namespace atomicity,
fsync, and stronger device-flush semantics remain distinct; claims must match the primitive actually exercised.fsync(2): https://developer.apple.com/library/archive/documentation/System/Conceptual/ManPages_iPhoneOS/man2/fsync.2.htmlfcntl(2)/F_FULLFSYNC: https://developer.apple.com/library/archive/documentation/System/Conceptual/ManPages_iPhoneOS/man2/fcntl.2.htmlCurrent #344 contract
Production fail-closes existing-record replacement when exact-source-object mutation cannot be proved. Create-new publication remains separate and retains exact private-mode admission, descriptor-relative no-follow authority, absolute destination/policy boundaries, exact opened/final identity and byte verification, bounded final reads/serialization, exact-private parent requirements, and descriptor-bound cleanup. Missing-parent pathname provisioning and delete-and-create replacement are not authorized shortcuts.
Remaining RED/GREEN acceptance
8b0e2b...must first earn terminal current-head GREEN. Source-absent Windows success is not provider runtime evidence.provider-oauth-windows.yml, and its resulting exact Test must executeprovider_oauth_cli_processfrom source on Windows and finish GREEN. Predecessor Windows evidence does not transfer.0600; error classification must not turn pathname metadata into read/mutation authority.Close only after #212 inherits the exact current owner contracts with its own source-present GREEN evidence, Windows parity is addressed for every exposed update path, and any future enabled replacement has adversarial real-filesystem exact-source and durability evidence.