Skip to content

Reviewed host configuration installation

Keep host installation explicit, adapter-bound, release-exact, and separate from read-only inspection. Require host plan or host apply, one caller-selected path, one exact adapter, and the same selected strict policy and launcher that produced the adapter. Never search for a host, create a parent directory, resolve a connector credential, contact Discord or another network endpoint, start a process, create activity state, or change connector policy. Do not add a generic config importer, opaque host-database writer, TOML writer, comment-preserving guess, or host auto-detection path.

Require the parent to be an existing canonical directory owned by the process user and not writable by group or world where portable metadata exists. Permit an absent target, but require every existing target to pass the inspection boundary for canonical path, regular type, single link, bounded stable duplicate-free JSON, trusted owner, and private mode. Bound JSON structure and reject non-finite, unsafe-integer, or negative-zero values that native rewriting cannot preserve. Reject incompatible shared-document roots, non-object existing server collections, non-array existing extension inputs, and duplicate generated input IDs rather than deleting or coercing ambiguous state. Preserve every unrelated top-level value, server entry, and extension input semantically. Treat a generated dedicated extension manifest as one complete-document projection, never as a shared merge.

Emit only fixed change categories and safe counts from planning. Never return the selected path, observed value, raw host JSON, unrelated entry, credential material, or a stable digest of private host bytes. Bind the plan digest to the exact activation and adapter identities, generated server name, normalized target internally, fixed change summary, and stable target and parent identity metadata. State that metadata freshness detects ordinary changes but is not a cryptographic content commitment against a privileged filesystem adversary. Require the exact generated server name as confirmation and the exact recomputed fresh plan digest before apply.

Serialize changed output as bounded canonical UTF-8 JSON. Apply only under an exclusive owner-mode sibling lock, through an exclusive synced temporary file, after an exact source byte and metadata recheck. Retain an exact owner-mode sibling backup before replacing an existing target, use no-clobber creation for an absent target, sync directory metadata where supported, reread exact published bytes, and require ordinary adapter inspection to match. On failed verification, restore and reread the original or remove and verify absence for a newly created target only while the published binding and bytes remain exact. Preserve a destination changed during verification and return uncertainty rather than overwriting it. Never claim the sibling lock excludes an external writer that ignores it. Never declare an interrupted operation's sibling lock stale automatically.

Return a backup path only when recovery requires locating the retained original and disclose that it may contain any credential already present in the host file. Never return destination content or include host content in activity, logs, telemetry, diagnostics, or another persistent record. Clear temporary byte buffers where practical and disclose that parsed JavaScript strings cannot be reliably erased. Treat successful publication as one static-file fact only; require host reload, static inspection, smoke, and a read-only host request for progressively stronger evidence.

Canonical source: SECURITY.md

Documentation generated for guildcontrol@0.0.0. Canonical source and edit history remain in the public repository. GuildControl is an independent project and is not affiliated with or endorsed by Discord Inc. Discord is used only to identify the platform that GuildControl connects to.