0e579a02ddec7e29027a5326091a0d7b2fd2e55f
Closes the read-privacy gap flagged in plan R1/R5. Rather than fork the FUSE uid/gid Acl model (whose identity is POSIX uid, incompatible with the daemon's name-based HELLO identity), read-gating is done owner/grant-native: - commands.rs: new admit_read(coord) mirroring admit_mutate (owner -> read-grant -> deny; unowned records world-readable). Wired into (read+execute) and (metadata read), gated by enforce_owner exactly like writes. - Tests: read_gate_blocks_non_owner_and_allows_read_grant (bob denied, allowed after alice grants read), read_gate_requires_identity_under_enforce (anonymous stat rejected under --require-identity). - Full ./check quick green: 39 cubesys lib tests, clippy -D warnings clean. Note in plan: Acl lift (R1) is NOT a literal fork; the daemon reuses the owner/grant enforcement concept, not the POSIX Acl struct.
Description
No description provided
536 KiB
Languages
Rust
94.5%
Python
2.8%
Shell
2.7%