Skip to content

~/.guild/ directory permissions inconsistent: 0755 in install path, 0700 elsewhere #79

Description

@travisbreaks

Noticed internal/install/init.go:425 creates ~/.guild/ with 0o755 while internal/session/state.go:48 and internal/release/cache.go:69 use 0o700 for the same directory. On a multi-user host (shared dev VM, jumpbox, home directory mounted on a shared file server), 0755 lets peers ls ~/.guild and read whatever umask leaves on lore.db and quest.db. The lore corpus is a project's decisions, research notes, and file paths, not a "world-readable by default" shape.

The inconsistency suggests this is an oversight rather than a deliberate posture, since the codebase already standardizes on 0o700 in two other call sites. Worth aligning on 0o700 for the directory and 0o600 for the SQLite files (modernc/sqlite respects O_CREAT perms but doesn't tighten existing files, so a one-time os.Chmod after open closes the gap on installs that pre-existed the fix).

One follow-on the original missed: with journal_mode=WAL on both DBs, SQLite creates <db>-wal and <db>-shm siblings at runtime (and <db>-journal in rollback mode). They land at default 0644 & ~umask, and the WAL holds uncommitted writes until checkpoint, so chmod'ing only the main DB leaves the corpus readable through the sidecar. The startup chmod should sweep the four extensions.

Happy to send a small PR if you'd take it: standardize on a single helper for ~/.guild/ creation, plus a startup os.Chmod over ["", "-wal", "-shm", "-journal"] for each opened DB. I have a working tree ready; would land as one commit.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: installguild init / mcp install / releasebugSomething isn't workingpriority: P2Normal prioritysecuritySecurity-sensitive

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions