Add ADR-029/030, implementation tasks, and spec updates for admin socket removal
Security review #005 identified critical vulnerabilities in the Unix domain socket admin API (C1 symlink race, C2 no auth, C3 info leak, W1-W7, S1-S6). ADR-028 (already accepted) replaces the socket with an authenticated HTTP admin API on the health check port. This commit adds the remaining spec work: - ADR-029: Config file TOCTOU mitigation (mtime check on reload) - ADR-030: Store cli_allow_wildcard_bind in ConfigReloadHandle for consistent reload validation - Implementation tasks for the admin HTTP migration (fix/admin-http-api), TOCTOU fix (fix/config-reload-toctou), and wildcard flag fix (fix/wildcard-flag-reload) - Updated review #005 status to resolved with per-finding disposition - Resolved OQ-16: POST for state-changing admin endpoints, GET for read-only - Updated all architecture docs to reference new ADRs, use admin_key_path instead of admin_socket_path, and reflect POST method for /admin/reload
This commit is contained in:
71
tasks/fix/review-005-status-update.md
Normal file
71
tasks/fix/review-005-status-update.md
Normal file
@@ -0,0 +1,71 @@
|
||||
---
|
||||
id: fix/review-005-status-update
|
||||
name: Update security review #005 status to reflect ADR-028 decision
|
||||
status: open
|
||||
depends_on: []
|
||||
scope: narrow
|
||||
risk: low
|
||||
impact: docs
|
||||
level: documentation
|
||||
review_findings: [C1, C2, C3, W1, W3, W4, S1, S2, S3, S4, S5, S6]
|
||||
adr: [028]
|
||||
---
|
||||
|
||||
## Description
|
||||
|
||||
Security review #005 (`docs/reviews/005-admin-socket-security-review.md`) is
|
||||
currently marked as `status: draft`. The review's architectural recommendation
|
||||
to replace the Unix domain socket with an authenticated HTTP admin endpoint has
|
||||
been accepted as ADR-028. The review findings should be annotated with their
|
||||
resolution status.
|
||||
|
||||
### Changes Required
|
||||
|
||||
**`docs/reviews/005-admin-socket-security-review.md`**:
|
||||
- Update frontmatter `status` from `draft` to the appropriate post-decision
|
||||
status (e.g., `accepted` or `resolved`)
|
||||
- Add a resolution section at the top of the document noting:
|
||||
- C1, C2, C3, W1, W3, W4, S1–S6: **Resolved by ADR-028** (replacing Unix
|
||||
domain socket with authenticated HTTP admin API)
|
||||
- W2 (config file TOCTOU): **Tracked separately** — ADR-029, task
|
||||
`fix/config-reload-toctou`
|
||||
- W5 (wildcard flag inconsistency): **Tracked separately** — ADR-030, task
|
||||
`fix/wildcard-flag-reload`
|
||||
- W6 (changed_fields in reload response): **Tracked** — will be implemented
|
||||
as part of `fix/admin-http-api` (the new `/admin/reload` endpoint will
|
||||
include changed_fields in its response per operations.md)
|
||||
- W7 (health check port recon): **Accepted risk** — health check is
|
||||
localhost-only, returns minimal information. The admin HTTP endpoint adds
|
||||
authentication for `/admin/*` routes.
|
||||
|
||||
**`docs/reviews/006-attack-surface-review.md`**:
|
||||
- Update Category 5 (Admin Socket) references from `src/admin/socket.rs` to
|
||||
`src/admin/auth.rs` and `src/admin/handler.rs` (after admin-http-api task
|
||||
is complete)
|
||||
- Update entry 4.3 (admin reload config file) to reference the shared
|
||||
`read_and_validate_config()` function with mtime check
|
||||
- Remove or update entries that are eliminated by the socket removal (e.g.,
|
||||
Category 4: Unix Domain Socket entries)
|
||||
|
||||
## Acceptance Criteria
|
||||
|
||||
- [ ] Review #005 frontmatter status updated
|
||||
- [ ] Review #005 has a resolution section annotating each finding with its
|
||||
disposition (resolved by ADR-028, tracked separately, accepted risk)
|
||||
- [ ] Review #006 admin socket references updated (after admin-http-api task)
|
||||
- [ ] No inline content removed — findings are annotated, not deleted
|
||||
|
||||
## References
|
||||
|
||||
- docs/reviews/005-admin-socket-security-review.md
|
||||
- docs/reviews/006-attack-surface-review.md
|
||||
- docs/architecture/decisions/028-admin-http-api.md
|
||||
|
||||
## Notes
|
||||
|
||||
> This task should be done after the `fix/admin-http-api` task is complete,
|
||||
> since review #006 references need to point to the new file structure.
|
||||
|
||||
## Summary
|
||||
|
||||
> To be filled on completion
|
||||
Reference in New Issue
Block a user