What happens
If the database file is read-only (for example chmod 444 on a snapshot), the first memesh process that opens it changes its mode to 600. That process still cannot write (SQLite had already opened it read-only), but every later hook, CLI or MCP process opens it normally and writes into it.
Steps
chmod 444 ~/.memesh/knowledge-graph.db (on a copy).
- Run any memesh command. The file mode is now
600.
- Run
memesh remember "x". The write succeeds.
Expected
memesh never loosens the permissions of a file the user protected; it only tightens permissions that are more open than 600.
What happens
If the database file is read-only (for example
chmod 444on a snapshot), the first memesh process that opens it changes its mode to600. That process still cannot write (SQLite had already opened it read-only), but every later hook, CLI or MCP process opens it normally and writes into it.Steps
chmod 444 ~/.memesh/knowledge-graph.db(on a copy).600.memesh remember "x". The write succeeds.Expected
memesh never loosens the permissions of a file the user protected; it only tightens permissions that are more open than
600.