30 lines
1.4 KiB
Markdown
30 lines
1.4 KiB
Markdown
---
|
|
status: resolved
|
|
opened: 2026-09-22
|
|
located-in: [mesh-catalog modules/redis (the provisioner's ACL)]
|
|
fixed-by: mesh-catalog multiple-fixes (the consumer's ACL user loses the dangerous command category); proven by the grant end-to-end bed, which now asserts a write outside the consumer's keys and FLUSHALL are refused
|
|
---
|
|
|
|
# 080 — A cache grant lets the consumer flush the server
|
|
|
|
## Symptom
|
|
|
|
The cache provider's provisioner creates each consumer an ACL user confined to keys under its own
|
|
login and allowed every command. A key pattern confines only commands that name keys. `FLUSHALL`,
|
|
`FLUSHDB`, `CONFIG`, `SHUTDOWN` and the rest of the dangerous category name none, so a consumer
|
|
granted "its own keys" could wipe every other consumer's, or stop the server.
|
|
|
|
Found by carrying the large mesh bed's retired tenancy assertions into the grant end-to-end bed:
|
|
`FLUSHALL` as the consumer answered `OK`.
|
|
|
|
## Why it matters beyond the instance
|
|
|
|
A grant is the mesh's promise that a consumer gets what it asked for and nothing else. The
|
|
promise was checked on the key pattern and never on the command set, and the one bed that had
|
|
asked was retired before it was run against the catalogue's module.
|
|
|
|
## What would close it
|
|
|
|
The ACL user is allowed the ordinary command set minus the dangerous category, and the grant bed
|
|
asserts a write outside the consumer's keys and a `FLUSHALL` are both refused.
|