Skip to content

Enforce capability-exact file handle permission states #394

Description

@wieslawsoltes

Parent: #248
Native authority: SceneTech/AppScene#123

Reproduction

At WebScene 2ffb0dc, FileSystemHandle.queryPermission({mode:"readwrite"}) and requestPermission({mode:"readwrite"}) return granted whenever any write-like grant bit is present. A write/create-only opaque save grant therefore reports readwrite even though getFile correctly rejects read access. Directory grants can similarly overclaim a combined permission from only a subset of read/enumerate/write/create/delete authority.

Focused scope

  • Derive read and readwrite permission states from the exact opaque grant capability set; readwrite requires both readable and writable authority for the handle kind.
  • Preserve browser dictionary/default/invalid-mode and illegal-receiver behavior.
  • Treat AppScene grants as terminal granted/denied capability decisions. Do not invent a prompt/elevation operation, replay picker activation, or mutate native authority in JavaScript.
  • Preserve permission state through transient structured clone and durable IndexedDB restore, including origin/profile retirement behavior.
  • Add Chromium/spec oracle coverage, native real-V8 security/lifecycle coverage, capability adapter assertions, and bounded 100/10,000-cycle heap/RSS/FD/latency gates.

Boundaries

This child does not add create/delete/remove/move authority, raw paths, permission prompts, AppScene changes, CSS, History #392, resource #388, consolidation #76, or vscode-demo changes. Missing native entry mutation remains a separate authority dependency.

Refs #248

Activity

  1. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Native authority audit found one prerequisite outside this slice: AppScene save-picker completions currently provide WRITE | CREATE without READ. Browser readwrite permission is constrained by read permission, so WebScene #394 will truthfully report denied for that capability set rather than invent read authority. SceneTech/AppScene#160 now tracks adding read authority at the native picker boundary and is attached under AppScene #123. This slice remains limited to exact grant interpretation, descriptor behavior, clone/durable parity, and bounded lifecycle/performance coverage.

  2. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Merged in PR #395 at 7438a60 (reviewed head 6301d6c). File and directory permission state now derives from exact opaque grant capabilities; readwrite requires the kind-specific read authority plus WRITE, descriptor conversion reads mode once, and structured-clone/IndexedDB restore preserve the result. Direct exact-head gates passed: Linux, macOS, portable V8, NativeAOT 11/12, and native document contracts. Local evidence: Chrome 153 2/2; 10,000 native queries / 100 cycles in 0.00408 s, heap delta 0, RSS +2.16 MiB, FD 4 -> 4, queues 0; durable IndexedDB and ABI/C11 gates passed. AppScene #160 tracks adding READ to save-picker grants.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    vscode-oss/plannedPlanned for the AppScene/WebScene VS Code OSS integration

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions