Skip to content

fix(desktop): require folder permission for native file tools - #8345

Merged
waleedlatif1 merged 8 commits into
stagingfrom
codex/desktop-local-file-consent
Oct 9, 2026
Merged

waleedlatif1 merged 8 commits into
stagingfrom
codex/desktop-local-file-consent

Conversation

@waleedlatif1

@waleedlatif1 waleedlatif1 commented Sep 26, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Ask before native reads or imports from an unapproved folder, remember approval across chats and restarts, and support revocation through File → Folder Access.
  • Add an off-by-default Full file access toggle in Desktop settings and remove the sleep setting helper text. Full file access bypasses folder prompts while retaining account, origin, cancellation, and filesystem identity checks; sign-out and server changes clear access.
  • Revalidate background calls before saving approval, share concurrent consent decisions without coupling cancellation, and show standalone consent without reopening a closed main window.
  • Verify native descriptors with lossless filesystem identities, reject replaced directories, and clear remembered grants even when persisting the Full file access reset fails.

Type of Change

  • Bug fix and feature

Testing

  • Full CI passed on the final rebased head: lint, all audits and workspace type checks, build, application and script suites, all integration shards, and HTTP E2E suites.
  • Real Electron E2E: 95 passed, 15 environment-specific skips; real Sim + Electron E2E: 12 passed; universal packaged-app smoke passed. CI retains reports, traces, and failure screenshots.
  • Native regression negative controls failed on pre-fix behavior for offline approval, closed-window reopening, grant cleanup after storage failure, hidden-browser throttling, and filesystem identity handling.
  • Repeated pinned-runtime consent checks passed without retries. An advisory canary round exposed one sign-out timing failure; the subsequent unchanged diagnostic repeat passed 10/10 without retries.
  • Manual packaged-app QA verified real sign-in, consent, cross-chat reuse, denial, revocation, restart persistence, native import with matching preview contents, and sign-out grant cleanup. Browser alert/confirm and unsaved-draft Stay, Escape, and Leave paths also passed.

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 9, 2026 2:33am UTC

Request Review

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 8 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread apps/desktop/src/main/local-file-permissions.ts Outdated
@greptile-apps

greptile-apps Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[High impact] The PR appears safe to merge based on the reviewed changes and resolved previous findings.

Summary

This PR adds folder consent and remembered grants for desktop native file tools, an opt-in Full file access setting, and descriptor-based checks for file access. It also adds cancellation, revocation, and Electron end-to-end coverage.

Diagram

%%{init: {'theme': 'neutral'}}%%
flowchart LR
  Call[Authorized file-tool call] --> Access{Full access or folder grant?}
  Access -->|Yes| Verify[Revalidate call and folder identity]
  Access -->|No| Consent[Ask for folder consent]
  Consent --> Verify
  Verify --> Native[Open verified native descriptor]
  Native --> Result[Return bounded result]
Loading

Reviews (11) · Last reviewed commit: "fix(desktop): revalidate folder consent ..." · Reviewed by Greptile

Comment thread apps/desktop/src/main/local-file-permissions.ts Outdated
Comment thread apps/desktop/src/main/local-file-permissions.ts Outdated
Comment thread apps/desktop/e2e/local-files.spec.ts Outdated
@waleedlatif1
waleedlatif1 force-pushed the codex/desktop-local-file-consent branch from d43d45a to 6ca8a97 Compare September 26, 2026 22:07
@waleedlatif1 waleedlatif1 changed the title fix(desktop): ask before accessing local files fix(desktop): require folder permission for native file tools Sep 26, 2026
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 26, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 13 files

Tip: instead of fixing issues one by one fix them all with cubic

Re-trigger cubic

Comment thread apps/desktop/src/main/local-filesystem-grant-store.ts
Comment thread apps/desktop/src/main/local-filesystem.ts
Comment thread apps/desktop/src/main/local-file-permissions.ts Outdated
Comment thread apps/desktop/src/main/local-files.ts Outdated
Comment thread apps/desktop/src/main/ipc.ts Outdated
Comment thread apps/desktop/src/main/local-files.ts
@waleedlatif1
waleedlatif1 force-pushed the codex/desktop-local-file-consent branch from 6ca8a97 to b5ae75a Compare September 26, 2026 22:31
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 26, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 15 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

Comment thread apps/desktop/src/main/local-files.ts Outdated
Comment thread apps/desktop/src/main/ipc.ts
@waleedlatif1
waleedlatif1 requested a review from a team as a code owner September 26, 2026 22:51
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 26, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

Comment thread apps/desktop/native/directory.cc
Comment thread apps/desktop/src/main/local-files.ts

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 20 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread apps/desktop/src/main/local-files.ts
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 26, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

Comment thread apps/desktop/src/main/desktop-settings.ts
Comment thread apps/desktop/src/main/index.ts Outdated

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 29 files

You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/desktop/src/main/index.ts Outdated
Comment thread apps/desktop/src/main/index.ts
Comment thread apps/desktop/src/main/local-filesystem-grant-store.ts Outdated
@waleedlatif1
waleedlatif1 force-pushed the codex/desktop-local-file-consent branch from cdb786e to 4cf15ef Compare October 9, 2026 02:18
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1 issue found across 34 files

Confidence score: 3/5

  • In directory.cc, a stale or repeated closeFile call can close an unrelated resource if the descriptor has been reused. Track descriptors opened by openApproved and validate them before closing.
Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. When an issue isn't valid or won't be fixed in this PR, reply in its thread with the reason and then resolve the thread. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name="apps/desktop/native/directory.cc">

<violation number="1" location="apps/desktop/native/directory.cc:305">
P2: `closeFile` closes whatever integer it receives, so a stale or doubled close can hit a reused descriptor. Track descriptors opened by `openApproved` (for example, a set checked before close) or wrap them in a handle that can be closed only once.</violation>
</file>

You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/desktop/native/directory.cc
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile Please review the current PR diff against staging. This branch was rebased onto 900afc3. Workflow tests and their run reporting came from staging PR #8773; they are not changed by this PR, as confirmed by the current Files changed list. Please reassess the confidence score for this PR’s 34 changed files at 4cf15ef, excluding changes already in its staging base.

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 34 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

@waleedlatif1
waleedlatif1 force-pushed the codex/desktop-local-file-consent branch from 4cf15ef to 5282735 Compare October 9, 2026 02:33
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile Please review the current 34-file PR diff against staging at 5282735. This is a clean rebase onto 1ed08d8 with no changes to desktop source or tests since the prior 5/5 review.

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 34 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

@waleedlatif1
waleedlatif1 merged commit dc39947 into staging Oct 9, 2026
51 checks passed
@waleedlatif1
waleedlatif1 deleted the codex/desktop-local-file-consent branch October 9, 2026 04:08

This branch was previously deployed

1 inactive deployment
Preview — 52827358 Deployed Oct 9, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant