diff --git a/04-ISSUES/079-every-machine-is-named-twice-over/01-diagnosis.md b/04-ISSUES/079-every-machine-is-named-twice-over/01-diagnosis.md index 6942653..c60b1ae 100644 --- a/04-ISSUES/079-every-machine-is-named-twice-over/01-diagnosis.md +++ b/04-ISSUES/079-every-machine-is-named-twice-over/01-diagnosis.md @@ -15,3 +15,10 @@ tests, once its controller image is rebuilt from the fix. produced the defect: two places composing one name. The control plane now hands the suffix it composed the names with down to the facts, so an operator who chose another gets that one and nothing appended. What remains unproven by a bed is a mesh with a suffix other than the default. + +*Later.* With the suffix right, the large bed's name test asked the second half of its question: +a machine that leaves the private network must not be answered for. The names were every placed +machine with an address, while the resolver's "on the private network" is a machine that also +runs the module that puts it there. The names follow the resolver's rule now — one predicate, +used by both — held by a controller test that unassigns one machine's networking and reads the +names back. diff --git a/04-ISSUES/080-a-cache-grant-lets-the-consumer-flush-the-server/00-report.md b/04-ISSUES/080-a-cache-grant-lets-the-consumer-flush-the-server/00-report.md new file mode 100644 index 0000000..5eae272 --- /dev/null +++ b/04-ISSUES/080-a-cache-grant-lets-the-consumer-flush-the-server/00-report.md @@ -0,0 +1,29 @@ +--- +status: resolved +opened: 2026-09-22 +located-in: [mesh-catalog modules/redis (the provisioner's ACL)] +fixed-by: mesh-catalog multiple-fixes (the consumer's ACL user loses the dangerous command category); proven by the grant end-to-end bed, which now asserts a write outside the consumer's keys and FLUSHALL are refused +--- + +# 080 — A cache grant lets the consumer flush the server + +## Symptom + +The cache provider's provisioner creates each consumer an ACL user confined to keys under its own +login and allowed every command. A key pattern confines only commands that name keys. `FLUSHALL`, +`FLUSHDB`, `CONFIG`, `SHUTDOWN` and the rest of the dangerous category name none, so a consumer +granted "its own keys" could wipe every other consumer's, or stop the server. + +Found by carrying the large mesh bed's retired tenancy assertions into the grant end-to-end bed: +`FLUSHALL` as the consumer answered `OK`. + +## Why it matters beyond the instance + +A grant is the mesh's promise that a consumer gets what it asked for and nothing else. The +promise was checked on the key pattern and never on the command set, and the one bed that had +asked was retired before it was run against the catalogue's module. + +## What would close it + +The ACL user is allowed the ordinary command set minus the dangerous category, and the grant bed +asserts a write outside the consumer's keys and a `FLUSHALL` are both refused. diff --git a/04-ISSUES/080-a-cache-grant-lets-the-consumer-flush-the-server/01-diagnosis.md b/04-ISSUES/080-a-cache-grant-lets-the-consumer-flush-the-server/01-diagnosis.md new file mode 100644 index 0000000..0795dff --- /dev/null +++ b/04-ISSUES/080-a-cache-grant-lets-the-consumer-flush-the-server/01-diagnosis.md @@ -0,0 +1,9 @@ +# Diagnosis — 2026-09-22 + +1. The provisioner's `ACL SETUSER` gave `~:*` and `+@all`. Redis applies a key pattern to + commands that take keys; a command taking none is governed by the command categories alone, + and `@all` includes `@dangerous`. +2. Fixed with `-@dangerous` after `+@all`. `KEYS` goes with the category; `SCAN` stays, and is + what a consumer scoped to a prefix should use. + +**Located in:** the redis module's client. Not a decision. Proven by the grant end-to-end bed.