Keep places and accesses at the terminal, and refuse a line break in any setting
mesh/merge-gate pass: builds build-agent, mesh-controller, route-proxy → ace, g14, novox, shanks; no bus step; every machine composes with the change as it…
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery superseded: a newer head of the same pull request

Through the settings verb a caller could place a module's directory at /etc
with an owner of its own and have root hand it over at the next send, or mount
any of the machine's paths into a container (hq ADR 0266). Both keys are now
the terminal's and never at the machine's own trees; a plans line that acts is
refused wherever its subcommand stands; and a line break in a setting, which a
file it is written into reads as a directive, is refused where it is kept and
where it is composed.
This commit is contained in:
jochen
2026-10-08 21:54:30 +02:00
parent e003f0e37b
commit 1d5a523a53
9 changed files with 302 additions and 10 deletions
+44
View File
@@ -1,6 +1,7 @@
package catalogue
import (
"strings"
"testing"
)
@@ -111,3 +112,46 @@ func TestTheRuntimeIsToldTheAgentAccount(t *testing.T) {
t.Error("a bundle may tell the runtime whom agents run as")
}
}
// No placement and no access at the machine's own system or the mesh's state, however it is spelled (novox/hq
// ADR 0266); a module's own place elsewhere is taken.
func TestAPlacementOrAnAccessAtTheMachinesOwnIsRefused(t *testing.T) {
m := Manifest{Module: "notes", Resources: []map[string]any{{"id": "data", "type": "directory"}},
Accesses: []Access{{ID: "media"}}}
for _, path := range []string{"/", "/etc", "/etc/sudoers.d", "/usr/bin", "/root", "/var/lib", "/home",
"/var/lib/mesh/x", "/var/lib/mesh-host", "/srv/../etc", "/proc/1", "/dev"} {
layers := []Layer{{From: "laptop", Values: map[string]any{PlacesSetting: map[string]any{"data": path}}}}
if _, err := Places(m, layers); err == nil {
t.Errorf("a place at %s was taken", path)
}
layers = []Layer{{From: "laptop", Values: map[string]any{AccessesSetting: map[string]any{"media": path}}}}
if _, err := AccessPlaces(m, layers); err == nil {
t.Errorf("an access at %s was taken", path)
}
}
for _, path := range []string{"/srv/notes", "/mnt/plex/data", "/storage/media", "/home/restic", "/var/lib/notes/data"} {
layers := []Layer{{From: "laptop", Values: map[string]any{PlacesSetting: map[string]any{"data": path}}}}
if got, err := Places(m, layers); err != nil || got["data"].Path != path {
t.Errorf("a place at %s: %v %v", path, got, err)
}
}
}
// A line break or a NUL in any string of any setting is refused, at any depth; PEM blocks alone may hold lines.
func TestASettingHoldsOneLine(t *testing.T) {
m := Manifest{Module: "mailu"}
for _, v := range []any{"a\nDEBUG=1", "a\rb", "a\x00b", map[string]any{"k": []any{"ok", "x\ny"}},
map[string]any{"k\nx": "v"}} {
if err := JudgeSettings(m, []Layer{{From: "home", Values: map[string]any{"v": v}}}, false); err == nil ||
!strings.Contains(err.Error(), "line break") {
t.Errorf("%q: %v", v, err)
}
}
pem := "-----BEGIN CERTIFICATE-----\nMIIBeDCCAR2gAwIBAgIQ\n-----END CERTIFICATE-----\n"
if err := JudgeSettings(m, []Layer{{From: "home", Values: map[string]any{"root": pem}}}, false); err != nil {
t.Errorf("a PEM block: %v", err)
}
if err := JudgeSettings(m, []Layer{{From: "home", Values: map[string]any{"root": pem + "PATH=/tmp evil\n"}}}, false); err == nil {
t.Error("a PEM block with a line of something else after it was taken")
}
}
+39 -2
View File
@@ -2,6 +2,7 @@ package catalogue
import (
"fmt"
"path/filepath"
"regexp"
"sort"
"strings"
@@ -44,6 +45,33 @@ type Placement struct {
var ownerShape = regexp.MustCompile(`^[0-9]+:[0-9]+$`)
// systemTrees are where no placement and no access may be: the machine's own system, and the node-engine's
// and the tool runner's state (novox/hq ADR 0266). A placed directory is created and chowned by the
// node-engine as root, and an access is mounted into a container: a place at /etc, owned by an account a
// caller names, hands that account the machine. Refused at or below each of these.
var systemTrees = []string{"/etc", "/usr", "/boot", "/root", "/proc", "/sys", "/dev", "/run", "/bin", "/sbin",
"/lib", "/lib64", "/var/lib/mesh", "/var/lib/mesh-host", "/var/lib/mesh-bus-conf"}
// systemRoots are directories a placement may be below but never be: each holds the whole machine's, or
// every module's or every person's, directories.
var systemRoots = []string{"/", "/var", "/var/lib", "/home", "/mnt", "/srv", "/opt", "/storage", "/data", "/tmp", "/var/tmp"}
// systemPath says why a path is the machine's own and no placement's, or "".
func systemPath(path string) string {
clean := filepath.Clean(path)
for _, root := range systemRoots {
if clean == root {
return clean + " is a whole tree of the machine's"
}
}
for _, tree := range systemTrees {
if clean == tree || strings.HasPrefix(clean, tree+"/") {
return clean + " is in " + tree + ", the machine's own or the mesh's state"
}
}
return ""
}
// accessRef is how a module names one of its accesses: ${access:<id>}.
var accessRef = regexp.MustCompile(`\$\{access:([a-z0-9][a-z0-9-]*)\}`)
@@ -103,7 +131,11 @@ func Places(m Manifest, layers []Layer) (map[string]Placement, error) {
if !strings.HasPrefix(p.Path, "/") {
return nil, fmt.Errorf("%s places %q at %q, which is not an absolute path", m.Module, id, p.Path)
}
p.Path = strings.TrimRight(p.Path, "/")
p.Path = filepath.Clean(p.Path)
if why := systemPath(p.Path); why != "" {
return nil, fmt.Errorf("%s places %q at %s: %s, and the node-engine would create and own it as "+
"root (novox/hq ADR 0266)", m.Module, id, p.Path, why)
}
out[id] = p
}
}
@@ -147,7 +179,12 @@ func AccessPlaces(m Manifest, layers []Layer) (map[string]string, error) {
return nil, fmt.Errorf("%s places the access %q at %v, which is not an absolute path",
m.Module, id, body)
}
out[id] = strings.TrimRight(path, "/")
path = filepath.Clean(path)
if why := systemPath(path); why != "" {
return nil, fmt.Errorf("%s places the access %q at %s: %s, and an access is mounted into the "+
"module's container (novox/hq ADR 0266)", m.Module, id, path, why)
}
out[id] = path
}
}
if len(out) == 0 {
+65
View File
@@ -209,6 +209,68 @@ func deepCopy(in map[string]any) map[string]any {
return out
}
// settingsHoldOneLine refuses a line break or a NUL in any string of any setting, for every module, at any
// depth: a key or a value, in an object or a list (novox/hq ADR 0266). A value is substituted into env and
// configuration files the node-engine writes as root (an app's .env, a logind drop-in), and a line break
// there is a directive of the caller's own; a NUL ends a string early wherever C reads it. Judged where a
// setting is kept and again where it is composed, so a stored value with one costs its module its place
// and says which key. One shape is let through: PEM blocks alone (a certificate authority's root handed to a
// provider), whose lines are base64 between BEGIN and END. Anything else that must hold lines is the
// module's own file, not a setting.
func settingsHoldOneLine(module string, layers []Layer) error {
for _, layer := range layers {
for _, key := range sortedKeysAny(layer.Values) {
if at := lineBreakIn(layer.Values[key], key); at != "" {
return fmt.Errorf("%s: the setting %s in %q holds a line break or a NUL, which a file it is written "+
"into would read as a directive of its own (novox/hq ADR 0266); a setting is one line",
module, at, layer.From)
}
}
}
return nil
}
// pemShape is the one value with lines a setting may hold: PEM blocks and nothing else — a certificate
// authority's root the operator hands a provider is one. Its lines are base64 between BEGIN and END: no
// space, quote, dot or underscore, so no path, option or command — at most a padded line an env file would
// read as an empty assignment, which names no program.
var pemShape = regexp.MustCompile(`^(-----BEGIN [A-Z0-9 ]+-----\n([A-Za-z0-9+/]{1,76}={0,2}\n)+-----END [A-Z0-9 ]+-----\n?)+$`)
// lineBreakIn is the path of the first string under v holding \n, \r or NUL, or "".
func lineBreakIn(v any, at string) string {
switch t := v.(type) {
case string:
if strings.ContainsAny(t, "\n\r\x00") && !pemShape.MatchString(t) {
return at
}
case map[string]any:
for _, k := range sortedKeysAny(t) {
if strings.ContainsAny(k, "\n\r\x00") {
return at + "." + strings.ToValidUTF8(strings.NewReplacer("\n", "\\n", "\r", "\\r", "\x00", "\\0").Replace(k), "?")
}
if found := lineBreakIn(t[k], at+"."+k); found != "" {
return found
}
}
case []any:
for i, e := range t {
if found := lineBreakIn(e, fmt.Sprintf("%s[%d]", at, i)); found != "" {
return found
}
}
}
return ""
}
func sortedKeysAny(m map[string]any) []string {
out := make([]string, 0, len(m))
for k := range m {
out = append(out, k)
}
sort.Strings(out)
return out
}
// UnusedSettings names settings that reach nothing.
//
// Somebody who sets a key on a module with nothing mergeable, or misspells one, has changed
@@ -405,6 +467,9 @@ var networkName = regexp.MustCompile(`^[A-Za-z0-9][A-Za-z0-9_.-]*$`)
// refused where it is stored (SetSettings, with UnusedSettings) and said where a plan is read,
// and never costs a module its place.
func JudgeSettings(m Manifest, layers []Layer, adopted bool) error {
if err := settingsHoldOneLine(m.Module, layers); err != nil {
return err
}
// With no layers too: a definition may ask for a setting nobody made — an access placed by
// nobody, a file's ${setting:…} nothing sets — and that is the same statement, missing.
if _, err := GivenPorts(m, layers); err != nil {