|
Some checks failed
helm chart / lint + unittest + render matrix (push) Has been cancelled
helm chart / install on kind (gated) (push) Has been cancelled
helm chart / publish chart to GHCR (push) Has been cancelled
Meridian Harness / Build (aarch64-unknown-linux-musl) (push) Has been cancelled
Meridian Harness / Build (x86_64-unknown-linux-musl) (push) Has been cancelled
Meridian Harness / Publish rolling release (push) Has been cancelled
Meridian Harness / Publish tagged release (push) Has been cancelled
CI / Detect Changed Paths (push) Has been cancelled
CI / Dead Token Reference Guard (push) Has been cancelled
control plane / chart (push) Has been cancelled
control plane / test (push) Has been cancelled
control plane / browser-e2e (push) Has been cancelled
control plane / Build control plane image (linux/amd64) (push) Has been cancelled
control plane / Build control plane image (linux/arm64) (push) Has been cancelled
Docker image / Build (linux/amd64) (push) Has been cancelled
Docker image / Build (linux/arm64) (push) Has been cancelled
Docker image / Build public push gateway (linux/amd64) (push) Has been cancelled
Docker image / Build public push gateway (linux/arm64) (push) Has been cancelled
CI / Rust Lint (push) Has been cancelled
CI / Unit Tests (push) Has been cancelled
CI / Isolated DB Gate (push) Has been cancelled
CI / Desktop Core (push) Has been cancelled
CI / Desktop Smoke E2E (1) (push) Has been cancelled
CI / Desktop Smoke E2E (2) (push) Has been cancelled
CI / Desktop Smoke E2E (3) (push) Has been cancelled
CI / Desktop Smoke E2E (4) (push) Has been cancelled
CI / Desktop (push) Has been cancelled
CI / Desktop E2E Relay (push) Has been cancelled
CI / Desktop E2E Integration (1/2) (push) Has been cancelled
CI / Desktop E2E Integration (2/2) (push) Has been cancelled
CI / Desktop E2E Integration (push) Has been cancelled
CI / Backend Integration (relay e2e) (push) Has been cancelled
CI / Relay E2E (push) Has been cancelled
CI / Web (push) Has been cancelled
CI / Admin Web (push) Has been cancelled
CI / Mobile (push) Has been cancelled
CI / Security (push) Has been cancelled
CI / Server Cross-Compile (push) Has been cancelled
CI / Server Cross-Compile-1 (push) Has been cancelled
CI / Windows Rust (x86_64-pc-windows-msvc) (push) Has been cancelled
CI / Desktop Build (macOS) (push) Has been cancelled
control plane / Publish signed control plane image (push) Has been cancelled
Docker image / Merge release multi-arch manifest (push) Has been cancelled
Docker image / Merge debug multi-arch manifest (push) Has been cancelled
Docker image / Publish public push gateway image (push) Has been cancelled
`meridian-f43l` closed a cross-tenant injection path by making a below-floor bus event's tenancy come from its row in the system of record rather than from the publisher-chosen key expression. Every refusal on that path was covered without infrastructure; `CommunityBinding::Bound` was covered by code inspection only, because the row it asks for cannot exist without Postgres. That is the wrong way round for a security control: a binding that refused everything would have passed the entire existing suite. Three tests, in the crate's `--lib` module because `fan_out_pubsub_event_with` — the only entry point that reaches the `Reverify` arm without a Zenoh session — is `pub(crate)`, and gated `#[ignore = "requires Postgres"]` so `just test-relay-db-run` (CI's "Relay DB/Redis gate") runs them and the infra-free suite stays infra-free: - `reverify_delivers_the_community_whose_row_binds_the_event_and_no_other`. One event, one signature, one channel UUID, two real communities. Under A, where the event's row exists carrying the routed channel scope, it is re-verified and delivered. Under B — a real community holding a real *open* channel with the same UUID and a subscriber on it, which is the shape an attacker gets for free from caller-chosen channel ids and a `(community_id, id)` primary key — the identical bytes on the identical topic are refused. Without the delivered half, "refused" would be equally consistent with a binding that refuses everything. - `a_relay_derived_channel_kind_is_bound_by_its_row_scope_and_nothing_else`. `bind_scope` answers `Silent` for reactions, deletions, gift wraps, 9007 and 44100/44101, so for those kinds the routed channel is checked in exactly one place: `stored.channel_id == routed_channel`. The stream-message pair cannot reach that arm — its refusal is decided before any lookup and its acceptance has tag and row agreeing — so this test is the one that fails when the comparison is deleted. Verified: with it deleted the pair still passes and this test fails. - `unknown_tenancy_refuses_and_withdraws_the_replay_id_that_unbound_spends`. A database error refuses rather than accepts, and is told apart from a decided `Unbound` by the replay set: `Unbound` spends the id, `Unknown` withdraws it so one Postgres blip is not a ten-minute hole. Needs no live database — `Unbound` is reached by an ephemeral kind and `Unknown` by a pool pinned at an address nothing listens on, so it runs in the default suite. The seen-set assertion is also what proves the refusal came from the tenancy check rather than from the visibility gate failing closed one step later. Mutation-verified in both directions: forcing `Bound` fails the paired refusal and the `Unknown` test; forcing `Unbound` fails the acceptance. The `--lib` pool is untouched. `test_state` still resolves through `test_config` and connects lazily; `postgres_state` is a sibling builder that resolves `meridian_test_db::disposable_url()` and connects eagerly, failing loudly rather than skipping, the same repair `api::operator` got in meridian-wxqw. Redis stays unconnectable for all three — the cross-node *receive* path publishes nothing, and a live one would pull these into meridian-h0tg's non-exiting test binary. The seeded rows are removed on the way out, because that gate's database is shared and nothing resets it. Refs: meridian-f43l Signed-off-by: Joshua Belke <joshua@innovationhub-act.org> |
||
|---|---|---|
| .. | ||
| git-credential-nostr | ||
| git-sign-nostr | ||
| meridian-acp | ||
| meridian-admin | ||
| meridian-agent | ||
| meridian-audit | ||
| meridian-auth | ||
| meridian-cli | ||
| meridian-conformance | ||
| meridian-control-plane | ||
| meridian-core | ||
| meridian-db | ||
| meridian-dev-mcp | ||
| meridian-harness | ||
| meridian-media | ||
| meridian-openapi | ||
| meridian-pair-relay | ||
| meridian-pairing-cli | ||
| meridian-persona | ||
| meridian-pubsub | ||
| meridian-push-gateway | ||
| meridian-relay | ||
| meridian-relay-mesh | ||
| meridian-sdk | ||
| meridian-search | ||
| meridian-test-client | ||
| meridian-test-db | ||
| meridian-workflow | ||
| meridian-ws-client | ||
| AGENTS.md | ||