Refuse unknown [permissions].allow names and correct the Log / --profile critical docs - #3252
Merged
Merged
Conversation
O6lvl4
enabled auto-merge
October 3, 2026 12:51
…a did-you-mean, through one shared matcher Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ile critical in cli.md Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
O6lvl4
added a commit
that referenced
this pull request
Oct 4, 2026
…rn rule, porta's manifest, and the proc resource list Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #3247
Closes #3249
Both fixes hold under any outcome of the effect-category redesign (#3243 / #3244). Nothing from those drafts is implemented here. ADR-0027 item 3 also says "unknown names are errors", which matches this change.
#3247: unknown
[permissions].allownames are refusedEffect::ALLandEffect::from_name(crates/almide-ir/src/effect.rs) now define the vocabulary.project::allowed_effectsis the only matcher, and both former copies (src/cli/mod.rs,src/cli/check.rs) now call it. It returns an error for an unknown name and never drops one.mainmanifest gate for A duplicate dependency key in almide.toml is accepted, then written into almide.lock twice, and the next run refuses the lock #2583 wasrefuse_duplicate_manifest_keys. It is nowrefuse_invalid_manifest, and it also runsproject::check_manifest_permissions. That function reads the lines exactly asparse_tomldoes. The gate is needed because most manifest readers useparse_toml(..).ok(), so an error raised only inside the parser would quietly turn into "no permissions":project::unknown_capability_messagenow also produces the--profile critical --allowrefusal. That refusal gains the did-you-mean, which Unknown names in [permissions].allow are dropped silently, while --profile critical --allow rejects them #3247 asked for on both paths. A case-only miss (io) is suggested ahead of an edit-distance match. The two vocabularies stay as they are (Fanin the manifest,Processin--allow). Each message lists its own vocabulary.--allowrefusal. This one follows them and printspath:line:with a hint.codes.toml,explainand the code-coverage floor are unchanged.Tests:
tests/diagnostics/permissions-unknown-capability/is a broken/fixed pair. The harness gainsbroken.toml/fixed.toml: a case whose defect is in the manifest is staged in a scratch project with that file asalmide.toml.tests/manifest_permissions_test.rschecks four things:check,check --effects,buildandrunall refuse an unknown name on its line.Logis refused.--allowpath gives the suggestion.#3249: docs say what the code does
docs/specs/effect-system.md§8:Logrow is gone. The table lists six categories and matchesmodule_to_effect.Timemaps todatetime(timeis not a module).Randnow reads "no module infers it". Measured:random.intunderallow = ["IO"]checks and builds.ioandrandominfer nothing.Log.logmodule (none exists).docs/specs/cli.mdgains#### --profile critical. It is written fromalmide check --helpand a probe, and covers:--allowtable fromCAPABILITY_GRANTSFanis absent--jsonbehaviourdocs/diagnostics/E085.mdnow links that section instead of a section that did not exist.docs/roadmap/PRODUCTION_READY.md:Logremoved from the category list.docs/wasm/capability-system.md: a note that its dotted names (FS.read, …) are a design, and the compiler refuses them.CHEATSHEET.md/llms.txthave noLogreferences.docs/adr/0022(D1) anddocs/roadmap/done/still mentionlog. They are records and were not edited.Gates run locally
diagnostic_harness_test,manifest_permissions_test,critical_profile_test,manifest_duplicate_key_test,diagnostic_coverage_test,explain_list_test,explain_docs_test,diagnostic_silent_test: all green.check-contracts.sh,check-env-switches.sh,check-llm-surface.sh,check-diagnostic-code-coverage.sh: all green.almide-ir: A 93, unchangedalmide-codegen: A 90, unchangedsrc: B 86, unchangedRebased onto #3235
#3235 added
[permissions] proc. Both features are kept:check_proc_allowlistandenforce_proc_allowlistsit next toallowed_permissions_or_reportinsrc/cli/mod.rs.allow. Aproclist holds commands, not capabilities, so the gate does not check it.tests/manifest_permissions_test.rspins this.docs/wasm/capability-system.md, Serve process on wasm through the private almide:process/spawn capability (ADR-0025) #3235's section "What the checker enforces today" is unchanged. The dotted-names note now points to it as the one implemented addition.Not done here
A multi-line
allow = [array is still read as empty, which means "everything allowed". The line-based reader only handles a one-line array. This is outside #3247, so it is left for a follow-up.