Files
reverse-proxy/tasks/fix/review-005-status-update.md
glm-5.1 161049a17d Add ADR-029/030, implementation tasks, and spec updates for admin socket removal
Security review #005 identified critical vulnerabilities in the Unix domain
socket admin API (C1 symlink race, C2 no auth, C3 info leak, W1-W7, S1-S6).
ADR-028 (already accepted) replaces the socket with an authenticated HTTP
admin API on the health check port. This commit adds the remaining spec work:

- ADR-029: Config file TOCTOU mitigation (mtime check on reload)
- ADR-030: Store cli_allow_wildcard_bind in ConfigReloadHandle for consistent
  reload validation
- Implementation tasks for the admin HTTP migration (fix/admin-http-api),
  TOCTOU fix (fix/config-reload-toctou), and wildcard flag fix
  (fix/wildcard-flag-reload)
- Updated review #005 status to resolved with per-finding disposition
- Resolved OQ-16: POST for state-changing admin endpoints, GET for read-only
- Updated all architecture docs to reference new ADRs, use admin_key_path
  instead of admin_socket_path, and reflect POST method for /admin/reload
2026-06-15 05:19:42 +00:00

71 lines
2.8 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
id: fix/review-005-status-update
name: Update security review #005 status to reflect ADR-028 decision
status: open
depends_on: []
scope: narrow
risk: low
impact: docs
level: documentation
review_findings: [C1, C2, C3, W1, W3, W4, S1, S2, S3, S4, S5, S6]
adr: [028]
---
## Description
Security review #005 (`docs/reviews/005-admin-socket-security-review.md`) is
currently marked as `status: draft`. The review's architectural recommendation
to replace the Unix domain socket with an authenticated HTTP admin endpoint has
been accepted as ADR-028. The review findings should be annotated with their
resolution status.
### Changes Required
**`docs/reviews/005-admin-socket-security-review.md`**:
- Update frontmatter `status` from `draft` to the appropriate post-decision
status (e.g., `accepted` or `resolved`)
- Add a resolution section at the top of the document noting:
- C1, C2, C3, W1, W3, W4, S1S6: **Resolved by ADR-028** (replacing Unix
domain socket with authenticated HTTP admin API)
- W2 (config file TOCTOU): **Tracked separately** — ADR-029, task
`fix/config-reload-toctou`
- W5 (wildcard flag inconsistency): **Tracked separately** — ADR-030, task
`fix/wildcard-flag-reload`
- W6 (changed_fields in reload response): **Tracked** — will be implemented
as part of `fix/admin-http-api` (the new `/admin/reload` endpoint will
include changed_fields in its response per operations.md)
- W7 (health check port recon): **Accepted risk** — health check is
localhost-only, returns minimal information. The admin HTTP endpoint adds
authentication for `/admin/*` routes.
**`docs/reviews/006-attack-surface-review.md`**:
- Update Category 5 (Admin Socket) references from `src/admin/socket.rs` to
`src/admin/auth.rs` and `src/admin/handler.rs` (after admin-http-api task
is complete)
- Update entry 4.3 (admin reload config file) to reference the shared
`read_and_validate_config()` function with mtime check
- Remove or update entries that are eliminated by the socket removal (e.g.,
Category 4: Unix Domain Socket entries)
## Acceptance Criteria
- [ ] Review #005 frontmatter status updated
- [ ] Review #005 has a resolution section annotating each finding with its
disposition (resolved by ADR-028, tracked separately, accepted risk)
- [ ] Review #006 admin socket references updated (after admin-http-api task)
- [ ] No inline content removed — findings are annotated, not deleted
## References
- docs/reviews/005-admin-socket-security-review.md
- docs/reviews/006-attack-surface-review.md
- docs/architecture/decisions/028-admin-http-api.md
## Notes
> This task should be done after the `fix/admin-http-api` task is complete,
> since review #006 references need to point to the new file structure.
## Summary
> To be filled on completion