Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

ruvector-context: macOS extended ACLs bypass the private-root check (doc or detection)

Aperta Adatta ai principianti
#909 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
2/5
Tempo stimato
1-3 ore
Idoneità per principianti
74/100
Tipo di issue
Documentazione
Chiarezza
Abbastanza chiara
Stato di attività
Attiva
Stack tecnologico
rust

Direzione di ricerca

Iniziare dalla documentazione del crate e da ADR-334 invariant 10, che descrivono la garanzia di una root privata e il controllo basato sulle modalità. Documentare che le ACL estese non vengono rilevate su macOS e non devono essere concesse sulla root dell’indice. Il lavoro è completato quando la garanzia dichiarata viene ristretta in modo coerente senza modificare l’implementazione del rilevamento delle ACL.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Follow-up from the PR #902 security review (LOW, non-blocking — #902 merged at 682e1c75).

Reproduced

On macOS, granting an NFSv4-style extended ACL on an otherwise-private root:

chmod +a "everyone allow read,write,execute,search,add_file,add_subdirectory,delete_child" <root>

gives every user on the box add_file and delete_child — i.e. full name-substitution power inside the index root — while symlink_metadata().mode() still reads 0700 and ScopedContextIndex::open() accepts it.

That is precisely the root-write capability the design states must be impossible. With it, the name-substitution attacks that rounds 1–4 of the review closed become reachable again.

Platform scope

macOS / NFSv4-ACL specific. On Linux, POSIX ACLs fold into the mode's group bits through the mask, so the existing mode & 0o077 != 0 check catches them.

Severity: LOW, and why

An attacker cannot set that ACL themselves — only the owner or root can. So this is a misconfiguration the check fails to detect, not an attacker-reachable escalation. It belongs in the same category as the operator error that the crate's retained defence-in-depth (staging directory, inode identity check, lone-regular-file requirement, reserved-name sweep) is documented to cover.

Fix — narrow the claim, or read the ACL

The crate currently says it "refuses a root other users can reach." On macOS what it actually refuses is a root whose mode bits say so. Either:

  • Cheap and honest: add a sentence to the crate docs and ADR-334 invariant 10 stating that mode-based detection does not see extended ACLs on macOS, so operators must not grant them on the index root; or
  • Complete: read the ACL (e.g. acl_get_file) on macOS and refuse a root carrying entries that grant non-owner access.

The documentation fix is probably the right first move given the misconfiguration-only reach — it keeps the stated guarantee true, which is the property that matters.

Lingua principale
Rust
Stelle
4.5k
Fork
603
Merge medio
2g 9h
PR unite (30g)
34

Preparare l'ambiente

Non abbiamo ancora controllato i file di configurazione di questo progetto. Parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di ruvnet/RuVector

Tutte le issue di ruvnet/RuVector

Issue simili

Altre issue su Rust

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.