Skip to content

fix(persistence): atomic updates, durable writes and protected credentials - #418

Merged
Cylae merged 1 commit into
mainfrom
gate/03-persistence-2026-09-13
Sep 13, 2026
Merged

fix(persistence): atomic updates, durable writes and protected credentials#418
Cylae merged 1 commit into
mainfrom
gate/03-persistence-2026-09-13

Conversation

@Cylae

@Cylae Cylae commented Sep 13, 2026

Copy link
Copy Markdown
Owner

Gate & Scope

G3 persistence, findings A02/A07/A11. File writes acquire advisory locks, use owned temporary files, set permissions before fsync and sync the parent directory. Configuration transactions reload from disk under a lock and reject malformed YAML. Remove the redundant global cache; serialize disabled services deterministically. Repair existing secret permissions without rotating credentials. Compose files now use 0600 because they contain credentials.

Covered Requirements

REQ-SEC-003, REQ-SEC-004, REQ-OPS-001, REQ-TST-003.

Evidence

Six regression tests cover concurrent updates, corruption preservation and redaction, same-content timestamps, lock symlinks, secret permission repair, and independent config paths. git diff --check passed. Local build/test/clippy attempts are ongoing; GitHub CI must pass before merge. No local green result is asserted.

Risks / Visible Behavior

Compose becomes owner-readable only. Corrupt config is rejected instead of silently overwritten. Lockfiles remain alongside managed outputs. Parent directories must be trusted; this does not claim arbitrary symlink confinement.

Rollback

Revert this PR squash commit; permissions need not be loosened to revert code.

Out of Scope

Host deployment, web session lifecycle, operational error handling; handled separately.

@Cylae
Cylae merged commit 21c1ed2 into main Sep 13, 2026
2 checks passed
@Cylae
Cylae deleted the gate/03-persistence-2026-09-13 branch September 13, 2026 19:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant