Add ADR-029/030, implementation tasks, and spec updates for admin socket removal

Security review #005 identified critical vulnerabilities in the Unix domain
socket admin API (C1 symlink race, C2 no auth, C3 info leak, W1-W7, S1-S6).
ADR-028 (already accepted) replaces the socket with an authenticated HTTP
admin API on the health check port. This commit adds the remaining spec work:

- ADR-029: Config file TOCTOU mitigation (mtime check on reload)
- ADR-030: Store cli_allow_wildcard_bind in ConfigReloadHandle for consistent
  reload validation
- Implementation tasks for the admin HTTP migration (fix/admin-http-api),
  TOCTOU fix (fix/config-reload-toctou), and wildcard flag fix
  (fix/wildcard-flag-reload)
- Updated review #005 status to resolved with per-finding disposition
- Resolved OQ-16: POST for state-changing admin endpoints, GET for read-only
- Updated all architecture docs to reference new ADRs, use admin_key_path
  instead of admin_socket_path, and reflect POST method for /admin/reload
This commit is contained in:
2026-06-15 05:19:42 +00:00
parent 9096ec5873
commit 161049a17d
21 changed files with 1210 additions and 119 deletions

View File

@@ -0,0 +1,71 @@
---
id: fix/review-005-status-update
name: Update security review #005 status to reflect ADR-028 decision
status: open
depends_on: []
scope: narrow
risk: low
impact: docs
level: documentation
review_findings: [C1, C2, C3, W1, W3, W4, S1, S2, S3, S4, S5, S6]
adr: [028]
---
## Description
Security review #005 (`docs/reviews/005-admin-socket-security-review.md`) is
currently marked as `status: draft`. The review's architectural recommendation
to replace the Unix domain socket with an authenticated HTTP admin endpoint has
been accepted as ADR-028. The review findings should be annotated with their
resolution status.
### Changes Required
**`docs/reviews/005-admin-socket-security-review.md`**:
- Update frontmatter `status` from `draft` to the appropriate post-decision
status (e.g., `accepted` or `resolved`)
- Add a resolution section at the top of the document noting:
- C1, C2, C3, W1, W3, W4, S1S6: **Resolved by ADR-028** (replacing Unix
domain socket with authenticated HTTP admin API)
- W2 (config file TOCTOU): **Tracked separately** — ADR-029, task
`fix/config-reload-toctou`
- W5 (wildcard flag inconsistency): **Tracked separately** — ADR-030, task
`fix/wildcard-flag-reload`
- W6 (changed_fields in reload response): **Tracked** — will be implemented
as part of `fix/admin-http-api` (the new `/admin/reload` endpoint will
include changed_fields in its response per operations.md)
- W7 (health check port recon): **Accepted risk** — health check is
localhost-only, returns minimal information. The admin HTTP endpoint adds
authentication for `/admin/*` routes.
**`docs/reviews/006-attack-surface-review.md`**:
- Update Category 5 (Admin Socket) references from `src/admin/socket.rs` to
`src/admin/auth.rs` and `src/admin/handler.rs` (after admin-http-api task
is complete)
- Update entry 4.3 (admin reload config file) to reference the shared
`read_and_validate_config()` function with mtime check
- Remove or update entries that are eliminated by the socket removal (e.g.,
Category 4: Unix Domain Socket entries)
## Acceptance Criteria
- [ ] Review #005 frontmatter status updated
- [ ] Review #005 has a resolution section annotating each finding with its
disposition (resolved by ADR-028, tracked separately, accepted risk)
- [ ] Review #006 admin socket references updated (after admin-http-api task)
- [ ] No inline content removed — findings are annotated, not deleted
## References
- docs/reviews/005-admin-socket-security-review.md
- docs/reviews/006-attack-surface-review.md
- docs/architecture/decisions/028-admin-http-api.md
## Notes
> This task should be done after the `fix/admin-http-api` task is complete,
> since review #006 references need to point to the new file structure.
## Summary
> To be filled on completion