Skip to content

gate cmd_tlm overlay writes at every writer - #3731

Open
jmthomas wants to merge 3 commits into
mainfrom
security-cmd-tlm-overlay-writers
Open

gate cmd_tlm overlay writes at every writer#3731
jmthomas wants to merge 3 commits into
mainfrom
security-cmd-tlm-overlay-writers

Conversation

@jmthomas

@jmthomas jmthomas commented Aug 19, 2026

Copy link
Copy Markdown
Member

Prevent a non-admin from writing the cmd_tlm directory when creating scripts.

Extract the canonical-path and cmd_tlm rules into OpenC3::ConfigOverlay and call it from all three writers: storage_controller, tables_controller, and scripts#create/destroy.

🤖 Generated with Claude Code

scripts#create wrote an arbitrary targets_modified path at the script_edit
tier, so a non-admin could place a cmd_tlm definition that PacketConfig
evaluates as code (GENERIC_*_CONVERSION) in the decom microservices. The
existing gates only covered the presigned upload and the Table writers.

Extract the canonical-path and cmd_tlm rules into OpenC3::ConfigOverlay and
call it from all three writers: storage_controller, tables_controller, and
scripts#create/destroy.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@jmthomas
jmthomas requested review from ryanmelt and a lite review from Copilot and removed request for Copilot August 19, 2026 18:17
@codecov

codecov Bot commented Aug 19, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 79.99%. Comparing base (2123636) to head (4d6da09).

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #3731      +/-   ##
==========================================
- Coverage   80.02%   79.99%   -0.03%     
==========================================
  Files         885      886       +1     
  Lines       65382    65401      +19     
  Branches     2543     2543              
==========================================
- Hits        52322    52319       -3     
- Misses      12396    12417      +21     
- Partials      664      665       +1     
Flag Coverage Δ
frontend 65.93% <ø> (-0.09%) ⬇️
python 81.88% <ø> (+<0.01%) ⬆️
ruby-api 82.17% <100.00%> (-0.29%) ⬇️
ruby-backend 84.44% <100.00%> (+0.01%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

This comment was marked as resolved.

@jmthomas jmthomas changed the title fix(security): gate cmd_tlm overlay writes at every writer gate cmd_tlm overlay writes at every writer Aug 19, 2026
@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants