fix(modelregistry): address audit findings

Replace try-lock/sleep scheme with blocking locks, add ErrModelNotFound/
ErrModelExists/ErrInvalidModel sentinels, make RegisterModelWithRules
atomic, snapshot in IterateModels, guard defaultRegistry access, cap the
pointer-unwrap depth, and recover panics in callbacks and reflection.
Security hooks now allow-by-default only on ErrModelNotFound. Add tests.
This commit is contained in:
Hein
2026-09-30 13:26:55 +02:00
parent a4e1abc1df
commit 97fe88b3a6
7 changed files with 335 additions and 155 deletions
+1 -1
View File
@@ -1787,7 +1787,7 @@ func checkModelUpdateAllowed(secCtx SecurityContext) error {
`checkModelDeleteAllowed` is identical (`:298-318`, fail-open at `:311`). A model
served by the spec handler but absent from the registry — or present under a name
the two lookups do not produce — is fully writable. This is the consuming side of
`modelregistry.audit.md` finding 1: the registry's lookup failure and this
`modelregistry.audit.md` finding 1 (*registry side fixed 2026-09-30: `checkModelUpdateAllowed`/`checkModelDeleteAllowed` now allow only on `ErrModelNotFound`*): the registry's lookup failure and this
`return nil` combine into "unknown model ⇒ permitted".
**Any authenticated user may perform any operation.** `CheckModelAuthAllowed` is