Skip to content

RFC: writable global sources (content-only) #19

Description

@ivklgn

Problem

Global sources are read-only everywhere outside the MCP read tools. Relaxing this to allow content writes (relations would stay forbidden) is a substantial change with open questions — write-addressing scheme, provenance marker, path hardening, atomic writes — and it touches several accepted rules/decisions.

Expected result

An RFC that resolves the open questions and includes a security review, ending in a recorded decision to either amend the read-only rule or reaffirm it.

Impact

Ensures a risky change to the globals trust model is made deliberately, with the path-traversal and provenance implications reviewed up front.

Scope

  • Resolve the open design questions.
  • Security-review the write-addressing and path-traversal surface.
  • Record the decision (or rejection); update the idea's status.

Files: a new RFC/decision doc under .archcore/

Acceptance: the design is settled and the read-only rule is either amended or reaffirmed.

Status: design/RFC + security review only.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    globalsGlobal sourcesneeds-designRequires an RFC/design decision first

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions