Hybrid helper socket: authenticate the peer / generate the profile ID in-helper (defense in depth, split from #993 R3)
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 55/100
Research direction
Start in brainbar_hybrid_helper.py:181-201, where the Unix socket accepts connections, and review the existing peer and profile-ID handling. Add the requested protection so a direct socket client cannot cause a chosen value to be logged, then add and run a test covering that direct-client case.
Written by the indexing model from the issue text.
Description
Split out of PR #993 (BL-0.2) at review round 3, the final round (Codex Sol). The lead ruled a split under canon 9.
Finding: brainbar_hybrid_helper.py:181-201 binds its Unix socket (mode 0600) and accepts any same-user connection without peer checks. A direct client can pass _profile_query_id, and with BRAINLAYER_SEARCH_PROFILE=1 that value is written to the profile record. The reviewer proved it in a scratch harness with a synthetic value.
Why it isn't a #993 blocker: the socket is owner-only, so the only possible caller already runs as the same user. That user can already read the DB and owns the log that receives the value. Profiling is off by default. No trust boundary is crossed. BrainBar's own path (the Swift router) now always generates the ID and drops the client's (#993).
Hardening: have the helper generate its own profile ID, or accept one only from an authenticated BrainBar peer (getpeereid + a per-launch token). Add a test that a direct socket client can't get a chosen value logged.
— brainlayerClaude-90982d09 (Claude Opus 5.5)
- Dominant language
- Python
- Stars
- 9
- Forks
- 7
- Avg merge
- 2h 7m
- Merged PRs (30d)
- 237
Getting set up
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from EtanHey/brainlayer
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
EtanHey/brainlayer#1040 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
EtanHey/brainlayer#1034 · 1 comment ·
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
EtanHey/brainlayer#1032 ·
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
EtanHey/brainlayer#999 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
EtanHey/brainlayer#986 ·
Maintainers usually reply within 1 day
All issues in EtanHey/brainlayer
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
kornia/kornia#5263 · 1 comment ·
Maintainers usually reply within 1 day
-
approved correction metadata
Difficulty 1/5 Under an hour Newbie friendliness 88/100
acl-org/acl-anthology#10133 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
BasedHardware/omi#20084 ·
Maintainers usually reply within 1 day
-
bug needs-acceptance wg/evaluation-quality
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
vllm-project/semantic-router#4424 ·
Maintainers usually reply within 1 day