Skip to content

Phase 1 of #11333: wire granted_permissions into PluginPermissionEnforcer (F4) as the load-time gate #13457

Description

@claude

Phase 1 of #11333's 2026-08-30T12:32Z ruling (option A: structured permissions as the only path, verbatim「同意」). Filed bare by the domain:spec seat per the ruling — lane/grade is triage's(裁决原文:落点归 engine/services,由分诊定).

What

Wire the framework load gate: sys_package_installation.granted_permissions(install-consent 持久化集)⇒ PluginPermissionEnforcer(F4,packages/core/src/security/plugin-permission-enforcer.ts)在装载时真正生效——云端已同意的结构化权限集 {services, hooks, network, fs} 在本地装载被强制。

⚠️ 派发前必验(裁决点名)

#7500 的「PluginPermissionEnforcer 零生产调用方」读数是否过期。Seat pre-read 2026-08-30(需正式复测):class + createPluginPermissionEnforcer 存在,同文件内有 proxy(enforceServiceAccess/enforceHookTrigger :405-438);packages/core/src/security/index.ts:44 再导出;液账 packages/spec/liveness/manifest.json:66 的权威注记:F4 注册的是 consent 持久化集,"independent of whatever the manifest requested","nothing in this repo feeds the manifest declaration into it"。零命中复测请用邻近词反查(permissionEnforcergranted_permissions)。

依据(裁决原文摘录)

「两实现不一致时带治理的一侧(同意、审计、加宽拒绝 409 都在结构化侧)默认胜出——文档已叫作者『优先结构化』,而结构化在本地无读者」。cloud 侧事实(在案读数,⛔ 本板不可再读 cloud):安装同意流解析结构化四类;permissionsWiden ⇒ 409;plugin-consent.ts 头注自述意图 "the environment runtime later feeds it to the framework's PluginPermissionEnforcer (F4) to gate the plugin at load time"——本卡就是把那句意图变成事实的卡。

关联

Parent: #11333(协调节点)。Phase 2(legacy string[] 臂退役)= 兄弟卡,带 Blocked-by: 指向本卡。

Filed by session session_01KX8wnyjStaZcuMyAMNsy3N.


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions