fix(bus): bind the zenohd router to loopback, as its commit title already claimed
The council's C11 live re-probe injected a forged, invalid-signature event
into the bus FROM A LAN ADDRESS and a real WebSocket client received it as
authentic. The router was reachable because the "loopback-only" profile
published it with a bare "${ZENOH_HOST_PORT:-7447}:7447", which Docker
binds to 0.0.0.0.
The NonLocalEndpoint refusal that this campaign treated as the boundary
confines the relay's DIAL address. It cannot confine the router's LISTEN
address, and nothing else did. So the guard's stated threat model --
"keep the endpoint on loopback", in its own error string -- was not
achieved by the shipped profile, and the commit title said loopback while
the port said every interface.
Fixed in both places, because either alone is useless: docker-compose.yml
publishes on 127.0.0.1, and run.sh's generated override does too. The
generator matters more -- its block is `!override`, so it REPLACES the
base ports list, and a bare mapping there would have silently undone the
base fix on every machine run.sh touches.
Found by live probe, not by review or by any test. The 21 zenoh_bus tests
pass against the vulnerable configuration, because none of them stands up
a router on a routable interface.
Signed-off-by: Joshua Belke <joshua@innovationhub-act.org>
This commit is contained in:
parent
6893ecfbd5
commit
6606e618dd
3 changed files with 24 additions and 6 deletions
|
|
@ -49,8 +49,11 @@ services:
|
|||
# in-network `tcp/zenohd:7447` endpoint keeps working for other containers.
|
||||
# Mirror this in .env.local as ZENOH_HOST_PORT + MERIDIAN_ZENOH_ENDPOINTS.
|
||||
# There is no REST port to relocate — the plugin is refused.
|
||||
# Keep the 127.0.0.1 prefix. Publishing this router on 0.0.0.0 lets any host
|
||||
# that can reach the port inject forged events that clients receive as
|
||||
# authentic — confirmed by live probe, not theory.
|
||||
# zenohd:
|
||||
# ports: !override
|
||||
# - "7448:7447"
|
||||
# - "127.0.0.1:7448:7447"
|
||||
|
||||
{}
|
||||
|
|
|
|||
|
|
@ -495,10 +495,19 @@ services:
|
|||
volumes:
|
||||
- ./deploy/compose/zenoh/zenohd.json5:/etc/zenoh/zenohd.json5:ro
|
||||
ports:
|
||||
# Host port is overridable like every other one here; 7447 is Zenoh's
|
||||
# well-known port and collides with any other Zenoh stack on the host.
|
||||
# Relocating it means moving MERIDIAN_ZENOH_ENDPOINTS with it.
|
||||
- "${ZENOH_HOST_PORT:-7447}:7447"
|
||||
# BOUND TO 127.0.0.1 DELIBERATELY. A bare "${PORT}:7447" publishes on
|
||||
# 0.0.0.0, and a live probe (council C11) confirmed the consequence: from
|
||||
# another host on the LAN, an unauthenticated process published a forged
|
||||
# event through this router and a real WebSocket client received it as
|
||||
# authentic. The relay's NonLocalEndpoint refusal confines the relay's
|
||||
# DIAL address; it cannot confine the router's LISTEN address, which is
|
||||
# this line. Removing the 127.0.0.1 prefix reopens an event-injection
|
||||
# primitive on every interface the host has.
|
||||
#
|
||||
# Host port is still overridable; 7447 is Zenoh's well-known port and
|
||||
# collides with any other Zenoh stack on the host. Relocating it means
|
||||
# moving MERIDIAN_ZENOH_ENDPOINTS with it.
|
||||
- "127.0.0.1:${ZENOH_HOST_PORT:-7447}:7447"
|
||||
networks:
|
||||
- meridian-net
|
||||
healthcheck:
|
||||
|
|
|
|||
8
run.sh
8
run.sh
|
|
@ -712,7 +712,13 @@ services:
|
|||
# until COMPOSE_PROFILES includes \`bus\`.
|
||||
zenohd:
|
||||
ports: !override
|
||||
- "${PORT_ZENOH}:7447"
|
||||
# 127.0.0.1 is load-bearing. This block is \`!override\`, so it REPLACES the
|
||||
# base file's ports list — a bare "PORT:7447" here silently undoes the
|
||||
# loopback bind in docker-compose.yml and republishes the router on every
|
||||
# interface. A live probe (council C11) injected a forged event from a LAN
|
||||
# address through an 0.0.0.0-published router and a real client received it
|
||||
# as authentic.
|
||||
- "127.0.0.1:${PORT_ZENOH}:7447"
|
||||
EOF
|
||||
dbg "wrote docker-compose.override.yml"
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue