Count a file that says nothing as trusted, and drop the refusal date
The fourth review (hq issue 339): the safe reading of a file that asks for a setting and does not say is that root or a consumer trusts it, so its settings are the terminal's; `"trusted": false` is the opt-out. With that, nothing unsafe is left to refuse: `module check` lists and counts the unmarked files and never refuses them.
This commit is contained in:
@@ -3,7 +3,6 @@ package catalogue
|
||||
import (
|
||||
"fmt"
|
||||
"sort"
|
||||
"time"
|
||||
)
|
||||
|
||||
// Which settings are the controller's terminal's alone (novox/hq issue 339).
|
||||
@@ -19,25 +18,22 @@ import (
|
||||
// database's port, an object store's scheme, a registry's port, an identity provider's issuer and token
|
||||
// path. Through a verb, any caller could point every consumer at a listener of its own and collect the
|
||||
// credentials they present.
|
||||
// 3. **Every setting a file marked `trusted` asks for**: a file root or a consumer trusts — a logind drop-in,
|
||||
// an env file that says which uid a container runs as, a script run as root. The manifest says so on the
|
||||
// file (TrustedField), and `module check` names a file that asks for a setting without saying.
|
||||
// 3. **Every setting a file asks for, unless the file says `"trusted": false`.** A file root or a consumer trusts —
|
||||
// a logind drop-in, an env file that says which uid a container runs as, a script run as root — must not
|
||||
// change through a verb, and the safe reading of a file that says nothing is that it is one of them (fail
|
||||
// closed). `"trusted": false` is the opt-out, for a file nothing trusts: a person's own notifier settings.
|
||||
// `module check` lists the files that say nothing, so an author can opt one out where that is true.
|
||||
//
|
||||
// Derived from the manifest, never listed by hand, so a provider or a trusted file added tomorrow is covered.
|
||||
|
||||
// TrustedField is the key a file resource carries to say whether the settings it asks for are trusted: true
|
||||
// makes each a terminal key; false says, out loud, that none changes what root or a consumer trusts. Said in the
|
||||
// TrustedField is the key a file resource carries to say whether the settings it asks for are trusted: true, or
|
||||
// absent, makes each a terminal key; false says, out loud, that none changes what root or a consumer trusts. Said in the
|
||||
// catalogue, never on the machine: the composer takes it out before the node-engine, which parses strictly.
|
||||
const TrustedField = "trusted"
|
||||
|
||||
// TrustRequiredFrom is when `module check` refuses a file that asks for a setting and does not say whether it is
|
||||
// trusted. Until then it is warned and counted: the catalogue's files get the field in their own change, which
|
||||
// can only land once a controller that takes the field out of the declaration runs.
|
||||
var TrustRequiredFrom = time.Date(2026, 10, 10, 0, 0, 0, 0, time.UTC)
|
||||
|
||||
// TerminalKeys are the settings keys of a module that are set at the controller's terminal alone: places and
|
||||
// accesses, every key its provisions serve and every setting a served value asks for, and every setting a file
|
||||
// marked trusted asks for. Places and accesses first, then the rest sorted.
|
||||
// asks for unless it says `"trusted": false`. Places and accesses first, then the rest sorted.
|
||||
func TerminalKeys(m Manifest) []string {
|
||||
keys := map[string]bool{}
|
||||
for _, served := range m.Serves {
|
||||
@@ -51,7 +47,10 @@ func TerminalKeys(m Manifest) []string {
|
||||
}
|
||||
}
|
||||
for _, r := range m.Resources {
|
||||
if trusted, _ := r[TrustedField].(bool); !trusted || fmt.Sprint(r["type"]) != "file" {
|
||||
if fmt.Sprint(r["type"]) != "file" {
|
||||
continue
|
||||
}
|
||||
if trusted, said := r[TrustedField].(bool); said && !trusted {
|
||||
continue
|
||||
}
|
||||
if content, ok := r["content"].(string); ok {
|
||||
@@ -70,7 +69,8 @@ func TerminalKeys(m Manifest) []string {
|
||||
return append([]string{PlacesSetting, AccessesSetting}, rest...)
|
||||
}
|
||||
|
||||
// UnsaidTrust is every file of a module that asks for a setting and does not say whether it is trusted, by id.
|
||||
// UnsaidTrust is every file of a module that asks for a setting and does not say whether it is trusted, by id:
|
||||
// each counts as trusted, and is listed so an author can opt out a file nothing trusts.
|
||||
func UnsaidTrust(m Manifest) []string {
|
||||
var out []string
|
||||
for _, r := range m.Resources {
|
||||
|
||||
@@ -138,14 +138,16 @@ func TestTerminalKeysAreDerived(t *testing.T) {
|
||||
power := Manifest{Module: "power", Resources: []map[string]any{
|
||||
{"id": "logind", "type": "file", "path": "/etc/systemd/logind.conf.d/power.conf", "trusted": true,
|
||||
"content": "HandleLidSwitch=${setting:handle-lid-switch}\n"},
|
||||
{"id": "note", "type": "file", "path": "/var/lib/power/note", "trusted": false, "content": "${setting:greeting}\n"}}}
|
||||
{"id": "note", "type": "file", "path": "/var/lib/power/note", "trusted": false, "content": "${setting:greeting}\n"},
|
||||
// Unmarked counts as trusted (fail closed): only `"trusted": false` lets a verb change what a file asks for.
|
||||
{"id": "unmarked", "type": "file", "path": "/etc/power/unmarked", "content": "${setting:unmarked}\n"}}}
|
||||
for _, c := range []struct {
|
||||
m Manifest
|
||||
want string
|
||||
}{
|
||||
{postgres, "places,accesses,port"},
|
||||
{keycloak, "places,accesses,issuer,token-path"},
|
||||
{power, "places,accesses,handle-lid-switch"},
|
||||
{power, "places,accesses,handle-lid-switch,unmarked"},
|
||||
{Manifest{Module: "plain"}, "places,accesses"},
|
||||
} {
|
||||
if got := strings.Join(TerminalKeys(c.m), ","); got != c.want {
|
||||
|
||||
Reference in New Issue
Block a user