gabriel / muse public
BREAKING task/muse-dir-snapshot-integrity #1 / 1
gabriel · 167 days ago · Apr 14, 2026 · Diff

security: defend all paths against .muse/ leaking into snapshots

Defense-in-depth: .muse/ VCS internals must never appear in working-tree snapshots. Four layers of protection now in place:

1. _collect_paths explicit-path branch (code_stage.py): _is_inside_muse_dir guard silently skips any path under .muse/ before staging.

2. _collect_paths -u/-A/no-path branches (code_stage.py): head_manifest iteration now skips keys starting with .muse/ so pre-fix corruption in a committed snapshot cannot be perpetuated by a restage.

3. run_add current_stage carry-forward (code_stage.py): updated_stage is initialized by filtering .muse/ entries from current_stage. Guards against the case where a commit was a no-op (snapshot matched HEAD after stripping) and therefore did not clear the stage.

4. CodePlugin.snapshot() (plugin.py): both the committed manifest and the stage entries are filtered at snapshot-build time, providing a last-resort guard regardless of how entries entered the stage.

Tests I7-I12 in TestSecurityI cover all four layers.

sha256:b013815083fdd10f9d31261ba8e8df38340e8e0ab2811f0a165ffa2608578677 sha
+3 ~5 symbols
sha256:6b8139eb1694322d5d36770199f12bf4b8076fab73e804b7aac888d02a2cb1a2 snapshot
+3
symbols added
~5
symbols modified
0
dead code introduced
Semantic Changes 8 symbols
~ muse/plugins/code/plugin.py .py 2 symbols modified
~ tests/test_cmd_code_add.py .py 3 symbols added, 1 symbol modified
+ test_I10_muse_dir_not_staged_by_update_flag method method test_I10_muse_dir_not_staged_by_update_flag L217–249
+ test_I11_muse_dir_not_staged_by_all_flag method method test_I11_muse_dir_not_staged_by_all_flag L251–270
+ test_I12_snapshot_strips_muse_dir_entries_at_commit method method test_I12_snapshot_strips_muse_dir_entries_at_commit L272–313
← Older Oldest on task/muse-dir-snapshot-integrity
All commits
Newer → Latest on task/muse-dir-snapshot-integrity

0 comments

No comments yet. Be the first to start the discussion.

To add a comment, use the Muse CLI: muse hub commit comment sha256:b013815083fdd10f9d31261ba8e8df38340e8e0ab2811f0a165ffa2608578677 --body "your comment"