Isolate upload staging and active upload state per User #450

Open
opened 2026-09-29 13:03:28 +00:00 by kayg · 0 comments
Owner

Follow-up from #435 and docs/audits/cross-user-inventory.md. DESIGN §48 requires physical separation of User Derived data; DESIGN §5 permits the Instance Blob store only without a cross-User oracle.

Current state: plugins/files/src/uploads.rs and files_uploads/files_upload_chunks hold incomplete content and offsets. Use handle-relative per-User staging and per-User Index rows. Preserve resumable upload recovery and quota reservation; test cross-User IDs, size and timing.

Acceptance: document the exact current boundary, migrate affected durable User state restartably where required, verify cross-User isolation with a negative control and extend tests/adversarial/xuser_matrix.py. Keep the server as the only writer and use calternal-fs for all filesystem access.

Follow-up from #435 and docs/audits/cross-user-inventory.md. DESIGN §48 requires physical separation of User Derived data; DESIGN §5 permits the Instance Blob store only without a cross-User oracle. Current state: plugins/files/src/uploads.rs and files_uploads/files_upload_chunks hold incomplete content and offsets. Use handle-relative per-User staging and per-User Index rows. Preserve resumable upload recovery and quota reservation; test cross-User IDs, size and timing. Acceptance: document the exact current boundary, migrate affected durable User state restartably where required, verify cross-User isolation with a negative control and extend tests/adversarial/xuser_matrix.py. Keep the server as the only writer and use calternal-fs for all filesystem access.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#450
No description provided.