Issue 080: a cache grant let the consumer flush the server; 079: the names follow the resolver's rule for the private network

This commit is contained in:
2026-09-22 01:39:29 +02:00
parent e31e077fc8
commit f760bf632c
3 changed files with 45 additions and 0 deletions
@@ -15,3 +15,10 @@ tests, once its controller image is rebuilt from the fix.
produced the defect: two places composing one name. The control plane now hands the suffix it produced the defect: two places composing one name. The control plane now hands the suffix it
composed the names with down to the facts, so an operator who chose another gets that one and composed the names with down to the facts, so an operator who chose another gets that one and
nothing appended. What remains unproven by a bed is a mesh with a suffix other than the default. nothing appended. What remains unproven by a bed is a mesh with a suffix other than the default.
*Later.* With the suffix right, the large bed's name test asked the second half of its question:
a machine that leaves the private network must not be answered for. The names were every placed
machine with an address, while the resolver's "on the private network" is a machine that also
runs the module that puts it there. The names follow the resolver's rule now — one predicate,
used by both — held by a controller test that unassigns one machine's networking and reads the
names back.
@@ -0,0 +1,29 @@
---
status: resolved
opened: 2026-09-22
located-in: [mesh-catalog modules/redis (the provisioner's ACL)]
fixed-by: mesh-catalog multiple-fixes (the consumer's ACL user loses the dangerous command category); proven by the grant end-to-end bed, which now asserts a write outside the consumer's keys and FLUSHALL are refused
---
# 080 — A cache grant lets the consumer flush the server
## Symptom
The cache provider's provisioner creates each consumer an ACL user confined to keys under its own
login and allowed every command. A key pattern confines only commands that name keys. `FLUSHALL`,
`FLUSHDB`, `CONFIG`, `SHUTDOWN` and the rest of the dangerous category name none, so a consumer
granted "its own keys" could wipe every other consumer's, or stop the server.
Found by carrying the large mesh bed's retired tenancy assertions into the grant end-to-end bed:
`FLUSHALL` as the consumer answered `OK`.
## Why it matters beyond the instance
A grant is the mesh's promise that a consumer gets what it asked for and nothing else. The
promise was checked on the key pattern and never on the command set, and the one bed that had
asked was retired before it was run against the catalogue's module.
## What would close it
The ACL user is allowed the ordinary command set minus the dangerous category, and the grant bed
asserts a write outside the consumer's keys and a `FLUSHALL` are both refused.
@@ -0,0 +1,9 @@
# Diagnosis — 2026-09-22
1. The provisioner's `ACL SETUSER` gave `~<login>:*` and `+@all`. Redis applies a key pattern to
commands that take keys; a command taking none is governed by the command categories alone,
and `@all` includes `@dangerous`.
2. Fixed with `-@dangerous` after `+@all`. `KEYS` goes with the category; `SCAN` stays, and is
what a consumer scoped to a prefix should use.
**Located in:** the redis module's client. Not a decision. Proven by the grant end-to-end bed.