You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Edge-sync spoke IDs can still collide through case folding and Unicode normalization #740
Unicode normalization.café in NFC and NFD are distinct byte strings, both accepted, and the same volumes treat them as one name.
Arc ships a darwin-arm64 binary through the Homebrew tap (release-build.yml:353), so macOS is a supported platform to run and develop on. CI is ubuntu-latest only (ci.yml:29), so nothing catches it.
The precondition is the same as #737: an administrator has to register the colliding ID, since registration is admin-only and there is no self-registration. No advisory.
TestSpokeNamespacesAreInjective in internal/edgesync/receive_test.go deliberately excludes ROCKET_01 from its candidate list with a comment pointing here, because including it would pass on Linux CI and fail on a macOS dev machine.
Rejecting non-lowercase or non-NFC IDs would refuse identifiers that are legitimate today, so it breaks existing deployments in a way the .. fix does not: .. in a spoke ID is always pathological, mixed case is not. That needs a deprecation path rather than a validator line.
Normalize on the way in and store the canonical form, which changes what registry.List() returns and therefore what receivedNamespaces in cmd/arc/main.go matches against on disk. Needs care.
Make the invariant structural at the storage boundary so the namespace encoding is injective regardless of identifier spelling. See the related sanitizePath issue.
Follow-up from #737, found while writing its regression test.
#737 closed the
..fold. The same class remains open for two other many-to-one mappings the filesystem applies rather than Arc:rocket_01andROCKET_01both passvalidateSpokeID. On a case-insensitive volume (macOS APFS by default, Windows) they are one directory, so either spoke can write into the other's namespace. Exactly Edge-sync spoke IDs containing an embedded..collide with another spoke's local namespace #737 with a different fold.caféin NFC and NFD are distinct byte strings, both accepted, and the same volumes treat them as one name.Arc ships a
darwin-arm64binary through the Homebrew tap (release-build.yml:353), so macOS is a supported platform to run and develop on. CI isubuntu-latestonly (ci.yml:29), so nothing catches it.The precondition is the same as #737: an administrator has to register the colliding ID, since registration is admin-only and there is no self-registration. No advisory.
TestSpokeNamespacesAreInjectiveininternal/edgesync/receive_test.godeliberately excludesROCKET_01from its candidate list with a comment pointing here, because including it would pass on Linux CI and fail on a macOS dev machine.Why it was not folded into #737
Rejecting non-lowercase or non-NFC IDs would refuse identifiers that are legitimate today, so it breaks existing deployments in a way the
..fix does not:..in a spoke ID is always pathological, mixed case is not. That needs a deprecation path rather than a validator line.Options
Registry.InvalidStoredIDsadded in Edge-sync spoke IDs containing an embedded..collide with another spoke's local namespace #737 is the hook).registry.List()returns and therefore whatreceivedNamespacesincmd/arc/main.gomatches against on disk. Needs care.sanitizePathissue.