Repository navigation
Dialog-minted filesystem scopes: generation-bound session grants in the FsBroker retained set (sibling pattern for draw.io .bkp) — approve the permission-model shape #403
Description
Activity
- addedwayfinder:grillingWayfinder human decisionWayfinder human decisionelectron-compatElectron compatibility program areaElectron compatibility program area
on Oct 6, 2026 Generated by an AI agent (Claude Code, Fable 5.1) on behalf of @0monish, 2026-10-06, under the map's execution doctrine. Statements are labelled FACT / INFERENCE / UNKNOWN by their author; nothing here authorizes implementation.
Decision packet
Decision: Under the strict profile, which owner turns a user-chosen path (dialog, file association, argv, drag-drop) into filesystem authority for the Bun main role, with what sibling rule and what lifetime, without a second policy owner or a widened manifest?
Classification:
needs-human· Milestone (YAGNI test against the first proof):parked· Reversible: Yes. A adds nothing; B is additive and generation-bound. C is not cheaply reversible once users hold persisted grants. · Owner: keld-guard crate under KEL-102 (Linear, fetched 2026-10-06: In Progress, unassigned; T3 landed 2026-10-05). KEL-130 (Done) is the closed FsBroker owner and cannot carry the amendment. No Linear issue owns a dialog broker (search 2026-10-06); the orchestrator must route that gap, not this subagent.Facts
- FACT (Linear availability, fetched live 2026-10-06 in this session, read-only, zero failures): team KELD is reachable. KEL-102 In Progress, unassigned; KEL-130 Done (completed 2026-09-21, assignee Amisha Ramani); KEL-140 Backlog, unassigned; KEL-127 Todo, unassigned; KEL-78 In Progress. The mempalace MCP server failed to connect (executable not found) and was not used.
- FACT (Linear KEL-102 comments cde25f5e and 264b4e6c, 2026-10-05, fetched 2026-10-06): KEL-102/T3 is PASSED and LANDED at main 66ccbbc (PR feat(core): route guarded filesystem requests #357, CI run 37313738834); the KEL-140 predecessor gate is satisfied and KEL-140 is unclaimed. The published F06 blocker 'KEL-102 T3 admission so FsBroker is reachable from the host' is therefore stale. A 2026-10-06 comment on KEL-102 records that kel102/kel130/kel139 specs and arch 03/05 still say 'not landed' (known doc drift, docs-only PR pending).
- FACT (crates/keld-guard/src/lib.rs:153-166, 707-736, re-read at HEAD b4b907c): only the guard mints a ScopePermit, and evaluate() resolves it from a manifest grant array index. A path absent from the manifest is denied before the broker runs, so 'register into the FsBroker retained set' cannot by itself produce an Allow.
- FACT (docs/specs/kel102-host-guard-enforcement.md:79, :88, :92): permission model approved as immutable-host-session-snapshot; D5 makes dispatch_privileged the sole production caller of evaluate; D9 authorizes no manifest-schema change without its own review gate.
- FACT (docs/specs/kel130-retained-filesystem.md:69): 'dialog grant' is an explicit non-goal of the retained-filesystem spec.
- FACT (corpus drawio-desktop@2edf9fb src/main/electron.js:3433-3438, re-read): draft/backup siblings are prefix-named: DRAFT_PREFEX '.$', OLD '~$', DRAFT_EXT '.dtmp', BKP_PREFEX '.$', BKP_EXT '.bkp'. The published sibling pattern '.*' matches none of them.
- FACT (scratchpad prototypes/f06-guard-probe run against the live keld-guard crate, 2026-10-06): a grant '/Users/u/Documents/a.drawio.' denies both 'a.drawio.bkp' and '.$a.drawio.bkp' (KELD-GUARD002). A lone '' is a literal in the live matcher, so the proposed sibling glob is not expressible today at all.
- FACT (drawio electron.js:217-222, 251-253): the blessed-path set is persisted across sessions (cap 500) so Open Recent works after restart.
- FACT (docs/specs/kel78-strict-profile-sandbox.md:172-177): the legacy profile is 'authenticated + guarded, unsandboxed'. The Bun role keeps ambient filesystem access, so no mint is needed for the first proof.
- FACT (Linear search 'dialog', team KELD, 14 results, complete page, 2026-10-06): no issue owns a dialog/menu/tray/shell broker.
Inferences
- INFERENCE: the mint must be a keld-guard-owned, host-minted session-grant set evaluated inside dispatch_privileged and distinguishable from manifest grants in the permit and deny text. The alternative (keld-native deciding) is a second policy owner forbidden by KEL-102-D5.
- INFERENCE: sibling authority must be an app-declared rule (prefix/suffix around the granted basename), not a host-hardcoded glob, because the only corpus oracle uses prefix names that a generic suffix rule cannot express.
- INFERENCE: 'never persisted' makes draw.io Open Recent a declared divergence under strict; 'dialog only' misses file-association, argv and second-instance mints that draw.io also blesses (refuter receipts at electron.js 1754/1803/2151, not re-opened by me).
Unknowns
- UNKNOWN: what fraction of draw.io's fs rows during install + activation + the 4-step workflow are scopable to a user-intent mint at all (panel experiment E1/S2 has not reported).
- UNKNOWN: Linux portal choosers may return document-portal paths; macOS security-scoped bookmarks have no Keld packaging target.
- UNKNOWN: whether a durable user-granted-roots store can be bound to KEL-135 authenticated identity without a new trust root (no spec text exists).
Alternatives
Option Cost New invariant created Existing invariant at risk A. No mint: strict-profile dialog-to-fs flows stay unsupported with a typed diagnostic; dialogs return paths and the app uses ambient fs only under the explicit legacy profile. Zero mechanism now; strict draw.io/Zettlr cannot open user files at all. None. Program-level honesty risk already recorded by the panel: legacy becomes the de-facto profile for every document app. B. Guard-owned session grants: host mints on a user-intent event, keld-guard evaluates them in dispatch_privileged, generation-bound, never persisted; open and save both grant read+write on the chosen node; openDirectory grants a subtree; derivative siblings via an app-declared rule. Approved spec amending KEL-102-D5/D9 and the KEL-130 non-goal; permission-model and public-API gates; Open Recent across restart becomes a declared divergence. Authority can exist in a session without being in the verified manifest snapshot, but only when minted by the host from a user-intent event and bound to one generation. KEL-102 'immutable-host-session-snapshot' model; one-evaluator rule if the set is evaluated anywhere but the guard. C. B plus persisted user-granted roots (host-owned, identity-bound, capped store). Durable authority store, tamper resistance, revocation surface, per-OS bookmark analogues. Authority outlives the session and is not in the reviewed manifest. Default-deny reviewability ('the manifest is the authority lockfile'); KEL-135 identity binding becomes security-critical for fs. D. Static manifest directory grants only (e.g. documents subtree). No new mechanism; grants far wider than the user's choice; cannot express 'any file the user picked'. None. Default-deny intent (wide standing grants). Recommendation
Park. For the first proof take A (legacy profile, no mint) and remove F06-D1 (#403) and the stale 'KEL-102 T3 admission' edge from the first-proof slice of F06-T2 (#478) (#478). When strict draw.io is scheduled, propose B as a spec amendment under KEL-102, written only after the E1 authority trace reports; do not adopt C without the owner's answer. The published mechanism (FsBroker registration, '.*' sibling glob, dialog-only, never persisted) is refuted by code and corpus and must not be carried forward. The one remaining owner question: may host-minted user-intent filesystem authority persist across app launches (required for Open Recent under strict), or must every launch re-mint from a fresh user action?
Falsifier: The E1 trace shows the 4-step workflow under legacy needs a host-mediated fs call (A is insufficient for the first proof), or it shows most draw.io fs rows are unscopable by any user-intent mint (B does not deliver strict draw.io and a different model is needed).
Missing evidence: E1/S2 authority trace classification of draw.io fs rows; an approved spec text for a guard-owned session-grant set; the owner's answer on persistence.
Next action: Orchestrator (single writer) edits F06-D1 (#403) (#403) and F06-T2 (#478) (#478): replace the proposed mechanism with options A-D, drop the T3 blocker citing the KEL-102 terminal artifact, and split T2 into a legacy dialog broker (first proof) and strict session grants (blocked by this decision). First completion check: #478 no longer lists F06-D1 (#403) or 'KEL-102/T3 admission' as blockers for its first-proof slice.
- addedmilestone:parkedParked by the YAGNI test until a current requirement proves itParked by the YAGNI test until a current requirement proves it
on Oct 6, 2026 Generated by an AI agent (Claude Code, Fable 5.1) on behalf of @0monish, 2026-10-06, under the map's execution doctrine. Statements are labelled FACT / INFERENCE / UNKNOWN by their author; nothing here authorizes implementation.
Owner decision (delegated)
Decided by the agent under @0monish's standing delegation of product and architecture decisions (2026-10-06). Any spec amendment this implies still needs its own exact-content approval; that approval is a separate step and is not claimed here.
Park. First proof takes option A (legacy profile, dialogs return paths, no scope minting). The published FsBroker-registration mechanism, the .* sibling glob and the dialog-only/never-persisted lifetime are refuted and withdrawn. Reopen when strict-profile draw.io is scheduled: propose guard-owned session grants as a KEL-102 spec amendment after the boot/authority trace; persistence across launches stays an owner question.
Alternatives considered: A. No mint: strict-profile dialog-to-fs flows stay unsupported with a typed diagnostic; dialogs return paths and the app uses ambient fs onl; B. Guard-owned session grants: host mints on a user-intent event, keld-guard evaluates them in dispatch_privileged, generation-bound, never ; C. B plus persisted user-granted roots (host-owned, identity-bound, capped store).; D. Static manifest directory grants only (e.g. documents subtree).
Falsifier / reopen predicate: The E1 trace shows the 4-step workflow under legacy needs a host-mediated fs call (A is insufficient for the first proof), or it shows most draw.io fs rows are unscopable by any user-intent mint (B does not deliver strict draw.io and a different model is needed).
Parent map: #391 · Unit: F06 (native-desktop) · Wayfinder type:
grilling· Status: open (not resolvable from current evidence)Question
Proposed (unrefuted): the host dialog returns paths and registers each as a generation-bound fs scope into KEL-130's retained set (open → read leaf, save → write leaf + declared sibling pattern), revoked on generation death, never persisted. Needs an independent refutation (batch 2) and a permission-model review; the user-granted-roots-survive-restart question is a separate KEL-79/KEL-130 spec gap.
What is known / why it is still open
No evidence-backed resolution yet; see the unit research note for the proposed answer and refuter verdicts.
Context
Epic #476 · research note
wayfinder/electron-compat/notes/F06.mdon the research branch.