Vouch request: Atharva-Kanherkar #3943
Atharva-Kanherkar
started this conversation in
Vouch Request
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
What do you want to work on?
I want to fix #3942 an update names only binary A and sets allow_uninspected_credentials, OpenShell accepts it and the shared endpoint now carries the flag for every binary in the rule, including binary B, which the update never named. The same update shape with websocket_credential_rewrite, or with a new allowed-ip, is rejected with "also declare /usr/local/bin/tool-b". So the existing "declare every binary you affect" check works for those settings but not for this one.
Why this change?
If you use one rule for multiple binaries, every binary listed there gets permission to send this kind of traffic without the supervisor being able to inspect it.
Binary B could already make the connection before. The difference is that after this change, it can also send binary data through that connection without the supervisor seeing what is inside it.
A real, production workflow impact I can not vouch for, but this is just not the behaviour the software promises, so it should be fixed. Reference : Atharva-Kanherkar/kairo#56 I run an open dataset of errors/bugs around LLM Infra and Routers, so this bug emerged out of the research not a production workflow. Clearing that out here.
Checklist
All reactions