Optional ingest-time gating for untrusted document sources
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 5/5
- Geschätzter Aufwand
- Über eine Woche
- Anfängerfreundlichkeit
- 30/100
Rechercherichtung
No implementation is selected yet. Read _ingest_location, _resolve_local, _locations_from_files_table, and add_docs to understand the current trust behavior, then review the DID-matlab companion issue and bridge sync requirements. Done would require an agreed optional gating design, matching Python and MATLAB changes, and tests for trusted and attacker-authored sources.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
Context
Follow-up to #58 and #60. After #60 (PR #62), _ingest_location refuses only unsafe uid values via _is_safe_uid — the ingest source location is trusted verbatim (_resolve_local, no containment check), on the reasoning that the caller who says "add this file to my DB" chose the source. This unblocks legitimate ingest workflows (NDI-python stages sources under /tmp/ndi-vhsb-*/ and adds them to a DB whose .ndi lives elsewhere) and keeps the destination fully constrained under <FileDir>/<uid>.
The read-side _is_safe_local_location filter (_locations_from_files_table) still defends orig_location, so a crafted stored location cannot steer open_doc to read outside db_dir through the orig_location branch.
The gap
There is one code path that ingestion isn't gated against, and it only matters when the document JSON is attacker-controlled (a cloud pull, not a locally authored document):
- A document with
location='../../etc/passwd'(or any traversal / absolute-outside path pointing at a readable file) now ingests successfully on POSIX.shutil.copyfileresolves the traversal, reads the target file, and writes its contents into<FileDir>/<uid>. - On a later
open_doc, the read-side filter refusesorig_location, but by then the cache candidate at<FileDir>/<uid>— built from the safe uid — already exists and wins the earlier loop; the smuggled contents are served back.
There is no such issue when the source of the document is trusted (the local NDI-python call, say). It is specifically the cloud-pull path where the JSON is not the caller's.
What we're not doing
For now, no change. The trade-off from #60 stands: reintroducing a source-side containment check breaks the legitimate workflow, and this residual surface only matters for the "attacker-authored document" case — one downstream packages can also mitigate by not blindly ingesting cloud-pulled documents.
What an optional gate might look like
If we do decide to close this later:
- Narrow the guard to relative locations with a traversal segment (a relative path whose
_resolve_localresult escapesdb_dir) — this refuses the../../etc/passwdshape without refusing an absolute path that legitimately lives outsidedb_dir. It's stricter than "no traversal", weaker than "must be inside db_dir". - Or make the guard opt-in via
add_docs(..., trust_sources=True|False), defaulting toTrue(today's behavior) and set toFalseby callers who pull documents from a cloud store. Downstream (NDI cloud pull) then setstrust_sources=Falseand gets the strict containment check.
Either would need matching changes on the MATLAB side and a bridge sync note. See the DID-matlab companion issue for the parity version.
- Vorherrschende Sprache
- Python
- Sterne
- 0
- Forks
- 1
- Ø Merge
- 2 Std. 15 Min.
- Gemergte PRs (30 T.)
- 40
Beitragsleitfaden
Für dieses Repository ist kein Beitragsleitfaden indexiert
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Ähnliche Issues
-
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 90/100
-
bug
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 86/100
zostera/django-bootstrap4#894 ·
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
use-agent-os/agent-os#3276 ·
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 88/100
zephyrproject-rtos/zephyr#119726 ·
-
area/auth bug comp/agent P3 platform/discord type/security
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 88/100
NousResearch/hermes-agent#117848 ·