The council's C11 live re-probe injected a forged, invalid-signature event
into the bus FROM A LAN ADDRESS and a real WebSocket client received it as
authentic. The router was reachable because the "loopback-only" profile
published it with a bare "${ZENOH_HOST_PORT:-7447}:7447", which Docker
binds to 0.0.0.0.
The NonLocalEndpoint refusal that this campaign treated as the boundary
confines the relay's DIAL address. It cannot confine the router's LISTEN
address, and nothing else did. So the guard's stated threat model --
"keep the endpoint on loopback", in its own error string -- was not
achieved by the shipped profile, and the commit title said loopback while
the port said every interface.
Fixed in both places, because either alone is useless: docker-compose.yml
publishes on 127.0.0.1, and run.sh's generated override does too. The
generator matters more -- its block is `!override`, so it REPLACES the
base ports list, and a bare mapping there would have silently undone the
base fix on every machine run.sh touches.
Found by live probe, not by review or by any test. The 21 zenoh_bus tests
pass against the vulnerable configuration, because none of them stands up
a router on a routable interface.
Signed-off-by: Joshua Belke <joshua@innovationhub-act.org>
59 lines
2.9 KiB
Text
59 lines
2.9 KiB
Text
# =============================================================================
|
|
# docker-compose.override.yml.example — template for local Compose overrides
|
|
# =============================================================================
|
|
# Copy to docker-compose.override.yml (gitignored) and edit:
|
|
# cp docker-compose.override.yml.example docker-compose.override.yml
|
|
#
|
|
# Compose auto-loads docker-compose.override.yml alongside docker-compose.yml
|
|
# with no flags and no environment wiring. That makes it the only local-override
|
|
# mechanism that survives a bare `docker compose up -d` — .env.local does not,
|
|
# because Compose reads that file only when COMPOSE_ENV_FILES is set in the
|
|
# shell (setting it inside .env is silently ignored).
|
|
#
|
|
# Use this file for:
|
|
# * pinning relocated host ports so plain `docker compose` is correct
|
|
# * anything env-var substitution cannot express — extra mounts, a sidecar,
|
|
# different resource limits, an alternate image tag
|
|
#
|
|
# Keep any ports here in sync with .env.local; `just compose-check` fails on
|
|
# drift. To disable temporarily: mv docker-compose.override.yml{,.disabled}
|
|
#
|
|
# -----------------------------------------------------------------------------
|
|
# `!override` is required for lists
|
|
# -----------------------------------------------------------------------------
|
|
# Compose MERGES sequences by appending. A plain `ports:` block here publishes
|
|
# BOTH the default and your relocated port — recreating the collision you were
|
|
# trying to escape. `!override` replaces the list. Same applies to `command`,
|
|
# `volumes`, and any other sequence.
|
|
# =============================================================================
|
|
|
|
services:
|
|
# --- Relocate Dragonfly's host port -----------------------------------------
|
|
# Only the host side moves; the container still listens on 6379, so the
|
|
# `redis` network alias keeps resolving for in-network clients.
|
|
# Mirror this in .env.local as REDIS_HOST_PORT + REDIS_URL.
|
|
# dragonfly:
|
|
# ports: !override
|
|
# - "6390:6379"
|
|
|
|
# --- Give Dragonfly more headroom for load testing --------------------------
|
|
# maxmemory must be >= 256MiB per thread or the container exits 1 at startup.
|
|
# dragonfly:
|
|
# command: !override
|
|
# - "--maxmemory=2gb"
|
|
# - "--proactor_threads=8"
|
|
# - "--dbfilename="
|
|
|
|
# --- Relocate zenohd's host port (COMPOSE_PROFILES=bus) ---------------------
|
|
# Only the host side moves; the container still listens on 7447, so the
|
|
# in-network `tcp/zenohd:7447` endpoint keeps working for other containers.
|
|
# Mirror this in .env.local as ZENOH_HOST_PORT + MERIDIAN_ZENOH_ENDPOINTS.
|
|
# There is no REST port to relocate — the plugin is refused.
|
|
# Keep the 127.0.0.1 prefix. Publishing this router on 0.0.0.0 lets any host
|
|
# that can reach the port inject forged events that clients receive as
|
|
# authentic — confirmed by live probe, not theory.
|
|
# zenohd:
|
|
# ports: !override
|
|
# - "127.0.0.1:7448:7447"
|
|
|
|
{}
|