oxidecomputer / oxidecomputer/omicron
Silo groups could be leaked after silo delete
Nobody has claimed this yet.
- Dominant language
- Rust
- Stars
- 572
- Forks
- 97
- Avg merge
- 2d 12h
- Merged PRs (30d)
- 96
Description
If a caller is racing a request to create a silo group (which currently could happen during a SAML+JIT login, or when a silo is created) and a request to delete a silo, depending on the ordering of DB queries, Nexus could create a silo group after the silo had been deleted, and return it, instead of returning a 404. There's nothing in the silo group ensure query that checks if the parent silo is undeleted.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start at the silo group ensure query described in the issue, then trace the SAML+JIT login and silo-creation paths that can race with silo deletion. Verify the ordering that creates a group after its parent is deleted, and confirm that the completed behavior returns 404 without creating or returning a silo group.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust
- Domain
- api, backend
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100