Skip to content

[Seatbelt] Explicitly denied path no longer leaks metadata - #1439

Open
Elliot (theelliotm) wants to merge 1 commit into
mainfrom
user/emichlin/fix-seatbelt-metadata-2
Open

Elliot (theelliotm) wants to merge 1 commit into
mainfrom
user/emichlin/fix-seatbelt-metadata-2

Conversation

@theelliotm

@theelliotm Elliot (theelliotm) commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

📖 Description

Seatbelt's baseline includes file-read-metadata access for all files, but when a path is explicitly denied, the deny file-read* rule is considered "less-specific", so it doesn't override the allow-all metadata grant. This PR now explicitly denies metadata access for files in deniedPaths and documents this.

🔗 References

Resolves #1430

🔍 Validation

Tested in CI, all MacOS tests green (using tests in #1431): https://github.com/microsoft/mxc/actions/runs/37581840096

✅ Checklist

📋 Issue Type

  • Bug fix
  • Feature
  • Task
Microsoft Reviewers: Open in CodeFlow

@theelliotm
Elliot (theelliotm) requested a review from a team as a code owner October 7, 2026 07:10
Copilot AI balanced review requested due to automatic review settings October 7, 2026 07:10
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The macOS behavioral regression test must be landed in-tree with this security fix.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Fixes Seatbelt metadata leakage for explicitly denied paths.

Changes:

  • Explicitly denies file-read-metadata.
  • Updates unit coverage and backend documentation.
File Description
profile_builder.rs Strengthens denied-path profile generation.
seatbelt-backend.md Documents metadata-rule precedence.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/mxc-sdk/src/backends/seatbelt/common/profile_builder.rs
@theelliotm Elliot (theelliotm) self-assigned this Oct 7, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Seatbelt: stat() succeeds on a deniedPaths entry, leaking size and timestamps

3 participants