docs: scrub self-ref cookies across 5 files (#719 batch 2)
All five files scrubbed to 0 issue-ref cookies. Most refs were '(closes #NNN)' style attribution after closed work landed. - docs/turn-loop.md: 6 → 0 (#598 unified binary, #419 auth-fail, #542 mtime resumption, #519 role markers, #442 spawn path, #474/#478 partial edit) - docs/approvals.md: 5 → 0 (#317 flake validation, #250 withdraw, #441 rebuild-queue dispatch, #753 manager port hash, #425 crash-watch grace) - docs/terminal-rendering.md: 2 → 0 (#666 ask-operator inline) - docs/conventions.md: 3 → 0 (#753 port hash, #692 parent sentinel, #486 reparenting) - docs/security.md: 4 → 0 (#240 + #658 ×2 + #673/#678 attribution) Combined with PR #810 (docs/web-ui.md 14→0), this PR closes the small / medium files. Remaining: agent-hierarchy.md (13), gotchas.md (13), persistence.md (13). gateway.md is atlas's lane.
This commit is contained in:
parent
a8d8159038
commit
5ca96b8c85
5 changed files with 27 additions and 29 deletions
|
|
@ -1,6 +1,6 @@
|
|||
# Security model
|
||||
|
||||
## Nix builds and credential isolation (issue #240)
|
||||
## Nix builds and credential isolation
|
||||
|
||||
### Background
|
||||
|
||||
|
|
@ -19,12 +19,11 @@ any file in the container that the nixbld user can read.
|
|||
**What is NOT exposed**:
|
||||
|
||||
- `/home/<name>/.claude/` — mode `0700`, owned by the per-agent
|
||||
user `<name>` (post-#658 — was `/root/.claude` owned by root
|
||||
pre-#658). nixbld users cannot read it.
|
||||
user `<name>`. nixbld users cannot read it.
|
||||
- `$HYPERHIVE_STATE_DIR/forge-token` (= `/agents/<name>/state/forge-token`)
|
||||
— written at mode `0600` by `hive-c0re/src/forge.rs` and chowned to the
|
||||
per-agent uid:gid by `lifecycle::chown_to_agent` (post-#673/#678).
|
||||
nixbld users cannot read it.
|
||||
per-agent uid:gid by `lifecycle::chown_to_agent`. nixbld users
|
||||
cannot read it.
|
||||
|
||||
**Policy**: all credential files written to agent state directories MUST be mode
|
||||
`0600` or stricter. Do not create world-readable secret files in agent state dirs.
|
||||
|
|
|
|||
Loading…
Reference in a new issue