Isolate Files change and Event feeds per User #452

Open
opened 2026-09-29 13:03:31 +00:00 by kayg · 0 comments
Owner

Follow-up from #435 and docs/audits/cross-user-inventory.md. DESIGN §48 requires physical separation of User Derived data; DESIGN §5 permits the Instance Blob store only without a cross-User oracle.

Current state: plugins/files files_change_feed*, files_events*, files_share_search_invalidations hold paths, counters and invalidations. Move feeds per User without changing Share delivery semantics. Test no cross-User cursor, size or timing oracle.

Acceptance: document the exact current boundary, migrate affected durable User state restartably where required, verify cross-User isolation with a negative control and extend tests/adversarial/xuser_matrix.py. Keep the server as the only writer and use calternal-fs for all filesystem access.

Follow-up from #435 and docs/audits/cross-user-inventory.md. DESIGN §48 requires physical separation of User Derived data; DESIGN §5 permits the Instance Blob store only without a cross-User oracle. Current state: plugins/files files_change_feed*, files_events*, files_share_search_invalidations hold paths, counters and invalidations. Move feeds per User without changing Share delivery semantics. Test no cross-User cursor, size or timing oracle. Acceptance: document the exact current boundary, migrate affected durable User state restartably where required, verify cross-User isolation with a negative control and extend tests/adversarial/xuser_matrix.py. Keep the server as the only writer and use calternal-fs for all filesystem access.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#452
No description provided.