Actuator validate_params enum screen: consider a safe-char allowlist (parity with invoke-tool composition) #7

Closed
opened 2026-09-10 12:38:08 +00:00 by jmz · 1 comment
Owner

From the M4 T1 re-review (out-of-scope observation).

mesh/manifest.py _UNSAFE_RE = [\s\x00-\x1f\x7f] (used by validate_params, the actuator-side runtime param check) is a whitespace/control-only DENYLIST — it still lets shell metacharacters through in an enum/regex param value. This is a DIFFERENT threat model than M4 T1 (the actuator runs argv with shell=False, so no shell interpolation there), so it is not a live RCE like the composition path was — but: (1) the new remediate.py comment claims the allowlist "mirrors validate_params", which is INACCURATE (different charset + strategy) — fix the comment; (2) evaluate whether the actuator param screen should also become a positive allowlist for defense-in-depth. Files: src/warden/mesh/manifest.py:164, src/warden/remediate.py:229.

From the M4 T1 re-review (out-of-scope observation). `mesh/manifest.py` `_UNSAFE_RE = [\s\x00-\x1f\x7f]` (used by `validate_params`, the actuator-side runtime param check) is a whitespace/control-only DENYLIST — it still lets shell metacharacters through in an enum/regex param value. This is a DIFFERENT threat model than M4 T1 (the actuator runs argv with shell=False, so no shell interpolation there), so it is not a live RCE like the composition path was — but: (1) the new `remediate.py` comment claims the allowlist "mirrors validate_params", which is INACCURATE (different charset + strategy) — fix the comment; (2) evaluate whether the actuator param screen should also become a positive allowlist for defense-in-depth. Files: src/warden/mesh/manifest.py:164, src/warden/remediate.py:229.
Author
Owner

Fixed in v0.18.0 (commits 54a0cd9 + e8d5348). manifest.validate_params now applies the positive safe-char allowlist [A-Za-z0-9._@:=+/-] to ENUM values (parity with the composition path); regex/int params unchanged. The inaccurate remediate.py comment is corrected.

Fixed in v0.18.0 (commits 54a0cd9 + e8d5348). `manifest.validate_params` now applies the positive safe-char allowlist [A-Za-z0-9._@:=+/-] to ENUM values (parity with the composition path); regex/int params unchanged. The inaccurate remediate.py comment is corrected.
jmz closed this issue 2026-09-10 16:17:44 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
public/warden#7
No description provided.