fix(security): reject imported architecture ids that claim the gate-exempt index.md page - #842
Merged
Merged
Conversation
…hored page
The active-content scan in validate-architectures.mjs skips
REPO_AUTHORED_PAGES (index.md), because the hand-authored catalog landing
page legitimately renders layout elements and imports a component. Nothing
enforced the precondition that exemption relies on: that no imported page
can land on an exempt path.
Both importers write docs/architectures/<id>.md with an id derived from
text the repository does not control - a submission issue's 'Organization
or Team Name' answer, or an upstream cncf/architecture directory name.
slugify('Index') is 'index', so a submission overwrites index.md with its
own body, and the gate skips exactly that file.
Derive RESERVED_PAGE_IDS from REPO_AUTHORED_PAGES so the two cannot drift,
and reject a catalog record claiming one. Gating at the validator covers
every importer without editing either.
Signed-off-by: hivecommons-hive[bot] <hivecommons-hive@hive.kubestellar.io>
Contributor
Author
|
Important Held for human review by the hive's ACMM level gate. This PR was opened by the "sec-check" agent while Hive policy required a human checkpoint for that agent. Non-outreach agents are held at ACMM L3–L5; the Hive will automatically remove the |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Security Fix
scripts/validate-architectures.mjsscans every page underdocs/architectures/for active content and fails the build when it finds any, but it skips
REPO_AUTHORED_PAGES(index.md) — the hand-authored catalog landing page,which legitimately renders layout elements and imports a component.
Nothing enforced the precondition that exemption relies on: that no imported
page can land on an exempt path. Both importers write
docs/architectures/<id>.mdwith an id derived from text the repository doesnot control — a submission issue's "Organization or Team Name" answer
(
scripts/import-architecture-issue.mjs), or an upstreamcncf/architecturedirectory name (
scripts/import-architectures.mjs).slugify('Index')isindex, so a submission overwritesindex.mdwith its own body and the gateskips exactly that file.
Verified on
main@7772dcf: a submission whose organization name isIndexand whose body carries
<iframe src="https://evil.example/beacon">overwritesdocs/architectures/index.md, and bothvalidate:architecturesandvalidate:architecture-assetsexit 0. The same body in any non-exempt page iscorrectly rejected.
What this changes
scripts/lib/architecture-pages.mjs: addsRESERVED_PAGE_IDS, derived fromREPO_AUTHORED_PAGESso the two cannot drift, plusisReservedPageId().scripts/validate-architectures.mjs: rejects a catalog record whose id isreserved, beside the existing duplicate-id check, and notes at the exemption
why the
continueis now safe.Gating at the validator covers every importer, including the two that write the
page, without editing either.
.github/workflows/architecture-submission.ymlalready runs
npm run validate:architecturesafter its import step, so thisfails the run — issue comment,
architecture-readylabel removed — rather thanopening a pull request.
Previously the exploit was backstopped only incidentally, by
tests/architecture-catalog-contract.test.mjsfiltering its page list with ahard-coded
name !== 'index.md'. That is a data-shape contract test that doesnot mention the exemption; the security gate itself failed open.
Verification
[error] index: id is reserved for a repo-authored page ..., exit 1.node --test tests/architecture-pages.test.mjs tests/validate-architectures.test.mjs: 40 pass, 0 fail.--check 97 --check-source 99 --check-regions 93 --check-source-regions 97) exit 0; all four changed files at 100.00% lines / 100.00% regions.prettier --checkclean on all four files.Claimed ground
scripts/lib/architecture-pages.mjs,scripts/validate-architectures.mjs,tests/architecture-pages.test.mjs,tests/validate-architectures.test.mjs;functions
RESERVED_PAGE_IDS/isReservedPageIdand the catalog-record loop invalidate-architectures.mjs.Deliberately disjoint from the open hold-gated PRs on neighbouring files: #812
(
scripts/import-architecture-issue.mjs,scripts/lib/mdx-escape.mjs), #827(
scripts/validate-architecture-assets.mjs), #836(
scripts/lib/svg-active-content.mjs), #810 and #820 (their respective testfiles), #825 (
tests/import-architectures.test.mjsand siblings). No file orfunction here is touched by any of them.
Closes #841
Filed by sec-check agent (ACMM L4/L5 — hold-gated mode). Hold-gated: human review required.
— hive: agent=sec-check backend=copilot model=claude-opus-5 copilot=1.0.88