mirror of
https://github.com/bitechdev/ResolveSpec.git
synced 2026-10-01 04:21:58 +00:00
fix(modelregistry): address audit findings
Replace try-lock/sleep scheme with blocking locks, add ErrModelNotFound/ ErrModelExists/ErrInvalidModel sentinels, make RegisterModelWithRules atomic, snapshot in IterateModels, guard defaultRegistry access, cap the pointer-unwrap depth, and recover panics in callbacks and reflection. Security hooks now allow-by-default only on ErrModelNotFound. Add tests.
This commit is contained in:
@@ -23,7 +23,7 @@ per-package audits reference this file rather than restating them.
|
||||
| X5 | **Medium** | locking | Unsynchronized package-level mutable globals are the dominant concurrency pattern |
|
||||
| X6 | **Medium** | security | Insecure-by-default transport across the board: `sslmode: disable`, `WithInsecure()`, no TLS in cache configs |
|
||||
| X7 | **Medium** | panic handling | Panic handling is inconsistent and, where it exists, tends to fail open |
|
||||
| X8 | **Medium** | security | `logger.Warn`/`Error` forward every message to Sentry unscrubbed, and error strings routinely embed attacker data |
|
||||
| X8 | **Medium** | security | `logger.Warn`/`Error` forward every message to Sentry unscrubbed, and error strings routinely embed attacker data *(partly fixed 2026-09-30: redaction and rate limiting added in `pkg/logger`; call sites still embed attacker data)* |
|
||||
| X9 | **Low** | testing | Test coverage is extremely uneven: 5 packages have no test file at all |
|
||||
|
||||
The table is ordered by severity; the sections below are in ID order, since other
|
||||
@@ -67,7 +67,7 @@ every one of them on the first run:
|
||||
| `pkg/cache` | `defaultCache` read/written by concurrent request handlers | `cache.audit.md` finding 3 |
|
||||
| `pkg/config` | `*viper.Viper` has no internal lock; `configInstance` singleton | `config.audit.md` findings 1, 2 |
|
||||
| `pkg/logger` | `Logger`, `errorTracker` globals | `logger.audit.md` finding 1 |
|
||||
| `pkg/modelregistry` | `defaultRegistry` read by 6 functions without the lock | `modelregistry.audit.md` findings 2, 8 |
|
||||
| `pkg/modelregistry` | `defaultRegistry` read by 6 functions without the lock | `modelregistry.audit.md` findings 2, 8 *(fixed 2026-09-30)* |
|
||||
| `pkg/tracing` | `tracer` global | `tracing.audit.md` finding 5 |
|
||||
| `pkg/errortracking` | `sentry.Init` mutates process globals | `errortracking.audit.md` finding 2 |
|
||||
|
||||
@@ -160,7 +160,7 @@ The test bodies that exist but are never executed by CI:
|
||||
| `metrics` | 1 | 64 | no |
|
||||
| `resolvemcp` | 1 | 34 | no |
|
||||
| `logger` | 0 | 0 | — |
|
||||
| `modelregistry` | 0 | 0 | — |
|
||||
| `modelregistry` | 1 | ~150 | yes (`-race`) *(added 2026-09-30)* |
|
||||
| `testmodels` | 0 | 0 | — |
|
||||
| `tracing` | 0 | 0 | — |
|
||||
|
||||
@@ -308,7 +308,7 @@ package-level variables, and most guard it with nothing:
|
||||
| `pkg/cache` | `defaultCache *Cache` (`cache.go:10`) | **no** |
|
||||
| `pkg/config` | `configInstance *Manager` (`manager.go:15`) | **no** |
|
||||
| `pkg/tracing` | `tracer` (`tracing.go:19`) | **no** |
|
||||
| `pkg/modelregistry` | `defaultRegistry` | partially — `TryLock` with a retry/`time.Sleep` loop, and 6 functions read it unlocked |
|
||||
| `pkg/modelregistry` | `defaultRegistry` | **yes** *(fixed 2026-09-30)* — guarded by `registriesMutex`; all access via `GetDefaultRegistry()` |
|
||||
| `pkg/metrics` | `globalProvider` (`interfaces.go:50-51`) | **yes** — `globalProviderMu sync.RWMutex` |
|
||||
|
||||
`pkg/metrics` is the model the others should follow:
|
||||
@@ -524,7 +524,7 @@ codebase invites it by logging the header contents as the diagnostic.
|
||||
only **Critical** authorization finding: `GetModel` returns a "registry locked"
|
||||
error under write-lock contention, which `security/hooks.go:274-294` converts
|
||||
into `return nil // model not registered, allow by default`
|
||||
(`modelregistry.audit.md` finding 1). A twenty-line test that registers a model
|
||||
(`modelregistry.audit.md` finding 1; *fixed 2026-09-30, regression tests added*). A twenty-line test that registers a model
|
||||
from one goroutine while reading it from another would demonstrate the fail-open
|
||||
immediately. The package guards a security boundary and has never been tested.
|
||||
|
||||
|
||||
@@ -32,6 +32,22 @@ There are **zero tests** in this package.
|
||||
| 11 | Low | Slowness | `os.Getpid()` called on every log line |
|
||||
| 12 | Low | Observability | `UpdateLogger` build failure degrades silently to stdlib `log` |
|
||||
|
||||
## Resolution status (2026-09-30)
|
||||
|
||||
- **#1** — Fixed (earlier race work): `stateMu` RWMutex with `getLogger`/`swapLogger`/`getErrorTracker`; the exported `Logger` var is kept for compatibility
|
||||
- **#2** — Fixed: messages are scrubbed before `CaptureMessage` (URL credentials, `password=`/`token=`/`secret=`/`api_key=` values, `Bearer`/`Basic` tokens). Local logs are unchanged. Sentry `BeforeSend` and structured-field allowlisting are not done
|
||||
- **#3** — Partly fixed: global token bucket (burst 50, 20/s) plus per-severity/template dedup (1s, 1024 keys). Panics are not limited. The `error_tracking.sample_rate` default (Sentry maps 0 to 1.0) is still unset in `config/manager.go`
|
||||
- **#4** — Partly fixed: `CatchPanicRethrow` added. `pkg/security/provider.go:302` and `:443` still use the swallowing `CatchPanic`; left for the security audit pass
|
||||
- **#5** — Fixed: stack captured with `runtime.Stack` into a 16 KiB buffer. Per-fingerprint panic rate limiting not done
|
||||
- **#6** — Fixed: `Info`/`Debug` format first and fall back with `log.Printf("%s", ...)`. `gosec` was enabled separately
|
||||
- **#7** — Fixed: CR/LF and other control characters are escaped on the stdlib fallback path
|
||||
- **#8** — Fixed: `Info`/`Debug` strip `context.Context` args
|
||||
- **#9** — Fixed: the replaced logger is synced on `UpdateLogger`
|
||||
- **#10** — Fixed: `logger.Sync()` added. Not yet called from the server shutdown path
|
||||
- **#11** — Fixed: PID cached in a package var
|
||||
- **#12** — Partly fixed: `UpdateLoggerE` returns the build error and a failed build keeps the previous logger. `Init` still returns nothing
|
||||
- Tests: `pkg/logger/logger_test.go` (run with `-race`).
|
||||
|
||||
---
|
||||
|
||||
## Findings
|
||||
|
||||
@@ -38,6 +38,34 @@ There are **no tests** in this package and no `-race` coverage of it anywhere.
|
||||
| 12 | Low | Panic | Package has no `recover` anywhere, and calls a caller-supplied callback under a lock (see 6) |
|
||||
| 13 | Low | Security | `DefaultModelRules()` grants `CanRead/Update/Create/Delete: true` — registration without explicit rules is fully mutable |
|
||||
|
||||
## Resolution (2026-09-30)
|
||||
|
||||
Fixed in `pkg/modelregistry/model_registry.go`, `pkg/security/hooks.go`, and new
|
||||
`pkg/modelregistry/model_registry_test.go` (passes under `-race`).
|
||||
|
||||
| # | Status | What changed |
|
||||
|---|--------|--------------|
|
||||
| 1 | **Fixed** | Added sentinels `ErrModelNotFound`, `ErrModelExists`, `ErrInvalidModel` (wrapped, `errors.Is`-friendly). `checkModelUpdateAllowed`/`checkModelDeleteAllowed` now allow-by-default **only** on `ErrModelNotFound`; any other error denies. Lookups can no longer return a "locked" error at all. |
|
||||
| 2 | **Fixed** | `GetDefaultRegistry` uses a plain `RLock`; no unsynchronised fallback. |
|
||||
| 3 | **Fixed** | `SetDefaultRegistry` uses a blocking `Lock` (cannot silently no-op); a nil registry is ignored. |
|
||||
| 4 | **Fixed** | `RegisterModelWithRules` and `RegisterModel` share `registerLocked`, which writes model + rules under one lock acquisition. |
|
||||
| 5 | **Fixed** | `GetAllModels`/`GetModels` use blocking locks and can no longer return empty/partial results due to contention. Signatures unchanged (`GetAllModels` is used through interfaces by resolvespec/restheadspec/openapi). |
|
||||
| 6 | **Fixed** | `IterateModels` iterates a snapshot; the callback runs with no lock held (regression test re-enters the registry). |
|
||||
| 7 | **Fixed** | Try-lock/sleep helpers and `lockRetry*` constants removed. |
|
||||
| 8 | **Fixed** | All package-level functions go through `GetDefaultRegistry()` / `registriesSnapshot()`; `defaultRegistry` is only touched under `registriesMutex`. |
|
||||
| 9 | **Fixed** | One discipline: blocking locks, snapshot-and-release, documented lock order (`registriesMutex` before a registry's mutex). |
|
||||
| 10 | **Fixed** | Reflection/validation (`validateModel`) runs before the write lock is taken. |
|
||||
| 11 | **Fixed** | Unwrap loop capped at 16 levels; `type T *T` now returns `ErrInvalidModel` (tested). |
|
||||
| 12 | **Fixed** | Sentinel errors added. `IterateModels` recovers a callback panic per model, logs it via `logger.HandlePanic` with the model name, and continues; `validateModel` recovers reflection panics and returns `ErrInvalidModel` so registration fails closed. No lock is held during either, so the registry cannot be wedged. |
|
||||
| 13 | **Accepted (decision)** | Allow-by-default retained deliberately: `DefaultModelRules()` still grants read/update/create/delete. Callers wanting restrictions must use `RegisterModelWithRules`/`SetModelRules`. |
|
||||
|
||||
Tests added: sentinel errors, recursive pointer type, pointer normalisation, atomic
|
||||
`RegisterModelWithRules` (concurrent reader never sees permissive rules), re-entrant `IterateModels`,
|
||||
cross-registry `GetModelRulesByName`, and a concurrent `-race` stress test.
|
||||
|
||||
Not changed: the `pkg/security` middleware-wiring question (context fast-path) remains tracked in
|
||||
`audit/pkg/security.audit.md`.
|
||||
|
||||
---
|
||||
|
||||
## Findings
|
||||
|
||||
@@ -1787,7 +1787,7 @@ func checkModelUpdateAllowed(secCtx SecurityContext) error {
|
||||
`checkModelDeleteAllowed` is identical (`:298-318`, fail-open at `:311`). A model
|
||||
served by the spec handler but absent from the registry — or present under a name
|
||||
the two lookups do not produce — is fully writable. This is the consuming side of
|
||||
`modelregistry.audit.md` finding 1: the registry's lookup failure and this
|
||||
`modelregistry.audit.md` finding 1 (*registry side fixed 2026-09-30: `checkModelUpdateAllowed`/`checkModelDeleteAllowed` now allow only on `ErrModelNotFound`*): the registry's lookup failure and this
|
||||
`return nil` combine into "unknown model ⇒ permitted".
|
||||
|
||||
**Any authenticated user may perform any operation.** `CheckModelAuthAllowed` is
|
||||
|
||||
Reference in New Issue
Block a user