Issue 080: a cache grant let the consumer flush the server; 079: the names follow the resolver's rule for the private network
This commit is contained in:
@@ -15,3 +15,10 @@ tests, once its controller image is rebuilt from the fix.
|
|||||||
produced the defect: two places composing one name. The control plane now hands the suffix it
|
produced the defect: two places composing one name. The control plane now hands the suffix it
|
||||||
composed the names with down to the facts, so an operator who chose another gets that one and
|
composed the names with down to the facts, so an operator who chose another gets that one and
|
||||||
nothing appended. What remains unproven by a bed is a mesh with a suffix other than the default.
|
nothing appended. What remains unproven by a bed is a mesh with a suffix other than the default.
|
||||||
|
|
||||||
|
*Later.* With the suffix right, the large bed's name test asked the second half of its question:
|
||||||
|
a machine that leaves the private network must not be answered for. The names were every placed
|
||||||
|
machine with an address, while the resolver's "on the private network" is a machine that also
|
||||||
|
runs the module that puts it there. The names follow the resolver's rule now — one predicate,
|
||||||
|
used by both — held by a controller test that unassigns one machine's networking and reads the
|
||||||
|
names back.
|
||||||
|
|||||||
@@ -0,0 +1,29 @@
|
|||||||
|
---
|
||||||
|
status: resolved
|
||||||
|
opened: 2026-09-22
|
||||||
|
located-in: [mesh-catalog modules/redis (the provisioner's ACL)]
|
||||||
|
fixed-by: mesh-catalog multiple-fixes (the consumer's ACL user loses the dangerous command category); proven by the grant end-to-end bed, which now asserts a write outside the consumer's keys and FLUSHALL are refused
|
||||||
|
---
|
||||||
|
|
||||||
|
# 080 — A cache grant lets the consumer flush the server
|
||||||
|
|
||||||
|
## Symptom
|
||||||
|
|
||||||
|
The cache provider's provisioner creates each consumer an ACL user confined to keys under its own
|
||||||
|
login and allowed every command. A key pattern confines only commands that name keys. `FLUSHALL`,
|
||||||
|
`FLUSHDB`, `CONFIG`, `SHUTDOWN` and the rest of the dangerous category name none, so a consumer
|
||||||
|
granted "its own keys" could wipe every other consumer's, or stop the server.
|
||||||
|
|
||||||
|
Found by carrying the large mesh bed's retired tenancy assertions into the grant end-to-end bed:
|
||||||
|
`FLUSHALL` as the consumer answered `OK`.
|
||||||
|
|
||||||
|
## Why it matters beyond the instance
|
||||||
|
|
||||||
|
A grant is the mesh's promise that a consumer gets what it asked for and nothing else. The
|
||||||
|
promise was checked on the key pattern and never on the command set, and the one bed that had
|
||||||
|
asked was retired before it was run against the catalogue's module.
|
||||||
|
|
||||||
|
## What would close it
|
||||||
|
|
||||||
|
The ACL user is allowed the ordinary command set minus the dangerous category, and the grant bed
|
||||||
|
asserts a write outside the consumer's keys and a `FLUSHALL` are both refused.
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
# Diagnosis — 2026-09-22
|
||||||
|
|
||||||
|
1. The provisioner's `ACL SETUSER` gave `~<login>:*` and `+@all`. Redis applies a key pattern to
|
||||||
|
commands that take keys; a command taking none is governed by the command categories alone,
|
||||||
|
and `@all` includes `@dangerous`.
|
||||||
|
2. Fixed with `-@dangerous` after `+@all`. `KEYS` goes with the category; `SCAN` stays, and is
|
||||||
|
what a consumer scoped to a prefix should use.
|
||||||
|
|
||||||
|
**Located in:** the redis module's client. Not a decision. Proven by the grant end-to-end bed.
|
||||||
Reference in New Issue
Block a user