fix(modelregistry): address audit findings

Replace try-lock/sleep scheme with blocking locks, add ErrModelNotFound/
ErrModelExists/ErrInvalidModel sentinels, make RegisterModelWithRules
atomic, snapshot in IterateModels, guard defaultRegistry access, cap the
pointer-unwrap depth, and recover panics in callbacks and reflection.
Security hooks now allow-by-default only on ErrModelNotFound. Add tests.
This commit is contained in:
Hein
2026-09-30 13:26:55 +02:00
parent a4e1abc1df
commit 97fe88b3a6
7 changed files with 335 additions and 155 deletions
+9 -2
View File
@@ -2,6 +2,7 @@ package security
import (
"context"
"errors"
"fmt"
"reflect"
@@ -284,7 +285,10 @@ func checkModelUpdateAllowed(secCtx SecurityContext) error {
rules, err = modelregistry.GetModelRulesByName(entity)
}
if err != nil {
return nil // model not registered, allow by default
if errors.Is(err, modelregistry.ErrModelNotFound) {
return nil // model not registered, allow by default
}
return err
}
}
if !rules.CanUpdate {
@@ -308,7 +312,10 @@ func checkModelDeleteAllowed(secCtx SecurityContext) error {
rules, err = modelregistry.GetModelRulesByName(entity)
}
if err != nil {
return nil // model not registered, allow by default
if errors.Is(err, modelregistry.ErrModelNotFound) {
return nil // model not registered, allow by default
}
return err
}
}
if !rules.CanDelete {