Skip to content

HUE-010 — Implement trusted Space resource roots and filesystem boundary validation

Canonical source: docs/roadmap/issues.json · HUE-010

Specification status: TBI · Readiness: agent:blocked

Enforce resource-root policy for Projects and Areas outside model prompts.

  • Register primary/additional roots and repositories
  • Canonicalize and check symlink/path traversal
  • Separate read/write grants and health
  • Escapes and unauthorized roots are denied
  • Moved/missing roots enter degraded state
  • Effective access is inspectable
  • Adversarial path tests pass
  • HUE-005
  • HUE-009
  • None beyond the documented scope.
  • Follow the milestone and repository product contract.
  • Preserve the documented security, project, memory and event boundaries.
  • Add or update automated tests for every observable acceptance criterion.
  • Provide real verification output; do not rely on a worker/agent self-report.
  • Update only the exact documentation sections whose status changed.
  • Include screenshots or a recording for user-interface changes.
  • Include migration, rollback and recovery notes for data/state changes.
  • Link the pull request to this issue with Closes #<issue-number>.