Noticed internal/install/init.go:425 creates ~/.guild/ with 0o755 while internal/session/state.go:48 and internal/release/cache.go:69 use 0o700 for the same directory. On a multi-user host (shared dev VM, jumpbox, home directory mounted on a shared file server), 0755 lets peers ls ~/.guild and read whatever umask leaves on lore.db and quest.db. The lore corpus is a project's decisions, research notes, and file paths, not a "world-readable by default" shape.
The inconsistency suggests this is an oversight rather than a deliberate posture, since the codebase already standardizes on 0o700 in two other call sites. Worth aligning on 0o700 for the directory and 0o600 for the SQLite files (modernc/sqlite respects O_CREAT perms but doesn't tighten existing files, so a one-time os.Chmod after open closes the gap on installs that pre-existed the fix).
One follow-on the original missed: with journal_mode=WAL on both DBs, SQLite creates <db>-wal and <db>-shm siblings at runtime (and <db>-journal in rollback mode). They land at default 0644 & ~umask, and the WAL holds uncommitted writes until checkpoint, so chmod'ing only the main DB leaves the corpus readable through the sidecar. The startup chmod should sweep the four extensions.
Happy to send a small PR if you'd take it: standardize on a single helper for ~/.guild/ creation, plus a startup os.Chmod over ["", "-wal", "-shm", "-journal"] for each opened DB. I have a working tree ready; would land as one commit.
Noticed
internal/install/init.go:425creates~/.guild/with0o755whileinternal/session/state.go:48andinternal/release/cache.go:69use0o700for the same directory. On a multi-user host (shared dev VM, jumpbox, home directory mounted on a shared file server),0755lets peersls ~/.guildand read whatever umask leaves onlore.dbandquest.db. The lore corpus is a project's decisions, research notes, and file paths, not a "world-readable by default" shape.The inconsistency suggests this is an oversight rather than a deliberate posture, since the codebase already standardizes on
0o700in two other call sites. Worth aligning on0o700for the directory and0o600for the SQLite files (modernc/sqlite respectsO_CREATperms but doesn't tighten existing files, so a one-timeos.Chmodafter open closes the gap on installs that pre-existed the fix).One follow-on the original missed: with
journal_mode=WALon both DBs, SQLite creates<db>-waland<db>-shmsiblings at runtime (and<db>-journalin rollback mode). They land at default0644 & ~umask, and the WAL holds uncommitted writes until checkpoint, so chmod'ing only the main DB leaves the corpus readable through the sidecar. The startup chmod should sweep the four extensions.Happy to send a small PR if you'd take it: standardize on a single helper for
~/.guild/creation, plus a startupos.Chmodover["", "-wal", "-shm", "-journal"]for each opened DB. I have a working tree ready; would land as one commit.