Skip to content

Fix shared-roost egg policy and MCP browser consent - #7

Merged
ehrlich-b merged 4 commits into
mainfrom
fix/shared-roost-egg-filesystem-policy
Sep 14, 2026
Merged

ehrlich-b merged 4 commits into
mainfrom
fix/shared-roost-egg-filesystem-policy

Conversation

@ehrlich-b

Copy link
Copy Markdown
Owner

What changed

  • treat administrator egg.yaml as the shared-host filesystem policy instead of replacing it with generated mounts
  • require deny:/ and reject any root mount while preserving arbitrary non-root mounts, explicit denies, environment, network, and agent settings
  • stop prompt/caller paths from widening shared-host mounts
  • accept Chromium's Origin: null only for the MCP consent POST while retaining Sec-Fetch-Site enforcement and binding the single-use consent request to the authenticated user
  • replace the self-contained fixtures with production-shaped external repo symlinks and add a full org-mode browser MCP OAuth/token/tool-call regression

Production evidence

  • v0.146.0 prod config contains ro:/opt/wingthing/repos, but the running egg argv omitted it and every explicit deny
  • v0.146.0 prod MCP: consent GET 200, same-page consent POST 403 (hosted mode rejects cross-origin browser mutations)
  • Bryan canary on this exact source: 25/25 deployed checks, including repos visible/read-only, sibling role denied, PKCE exchange 200, MCP initialize/list 200, and wing_list call 200; zero console/page/request errors
  • service active, NRestarts=0, preexisting session process survived; temporary sessions and canary OAuth registration removed

Gates

  • make check
  • make test-web (org 33/33; legacy org and hosted direct green)
  • make test-linux
  • make test-linux-ubuntu
  • make test-integ
  • make test-compat
  • make test-claude-policy
  • make test-vuln
  • go vet ./...
  • go test -race ./...
  • make release-contract
  • git diff --check

@ehrlich-b
ehrlich-b merged commit 26f2400 into main Sep 14, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant