Commit 367c72b
committed
fix(security): validate haproxy.acl.path + haproxy.acl.header at parse time
The audit's P2-10 framing was "drop the dead ACLPath/ACLHeader fields,"
but those labels are documented in
ubuntu-ha-proxy-install/docs/architecture.md and
ubuntu-ha-proxy-install/docs/example-docker-compose.yml as supported
forward-looking features ("Path-based routing", "Custom ACL conditions").
Deleting the BackendConfig fields would break that documented API.
Instead, validate them now so the latent injection class (same shape as
P0-1 BackendName and P0-2 ACLIP) is closed before any future PR wires
them into a generated directive like:
acl req_path path_beg <path>
acl req_hdr_cnt(<header>) gt 0
Two new validators in parser.go:
- validACLPath: leading slash + URL-path-safe charset
(`^/[a-zA-Z0-9/_.\-~%]*$`). Rejects embedded newlines, semicolons,
whitespace, query strings, fragments.
- validACLHeader: RFC 7230 HTTP header token characters
(`^[a-zA-Z0-9!#$%&'*+\-.^_`+"`"+`|~]+$`). Rejects newlines, colons,
slashes, spaces.
extractBackendConfig now rejects the whole backend if either field has
a non-empty malformed value. Empty values (the overwhelmingly common
case) skip validation as today.
Tests cover the legitimate-shape pass list, the injection class
(newline + HAProxy directive payload), and the common-injection-
character reject list.
P2-10 from the 2026-05 security audit.1 parent 509bf6a commit 367c72b
2 files changed
Lines changed: 140 additions & 2 deletions
Lines changed: 39 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
43 | 43 | | |
44 | 44 | | |
45 | 45 | | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
46 | 58 | | |
47 | 59 | | |
48 | 60 | | |
| |||
312 | 324 | | |
313 | 325 | | |
314 | 326 | | |
| 327 | + | |
| 328 | + | |
| 329 | + | |
| 330 | + | |
| 331 | + | |
| 332 | + | |
| 333 | + | |
| 334 | + | |
| 335 | + | |
| 336 | + | |
| 337 | + | |
| 338 | + | |
| 339 | + | |
| 340 | + | |
| 341 | + | |
| 342 | + | |
| 343 | + | |
| 344 | + | |
| 345 | + | |
| 346 | + | |
| 347 | + | |
| 348 | + | |
| 349 | + | |
| 350 | + | |
| 351 | + | |
315 | 352 | | |
316 | 353 | | |
317 | 354 | | |
| |||
334 | 371 | | |
335 | 372 | | |
336 | 373 | | |
337 | | - | |
338 | | - | |
| 374 | + | |
| 375 | + | |
339 | 376 | | |
340 | 377 | | |
341 | 378 | | |
| |||
Lines changed: 101 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
757 | 757 | | |
758 | 758 | | |
759 | 759 | | |
| 760 | + | |
| 761 | + | |
| 762 | + | |
| 763 | + | |
| 764 | + | |
| 765 | + | |
| 766 | + | |
| 767 | + | |
| 768 | + | |
| 769 | + | |
| 770 | + | |
| 771 | + | |
| 772 | + | |
| 773 | + | |
| 774 | + | |
| 775 | + | |
| 776 | + | |
| 777 | + | |
| 778 | + | |
| 779 | + | |
| 780 | + | |
| 781 | + | |
| 782 | + | |
| 783 | + | |
| 784 | + | |
| 785 | + | |
| 786 | + | |
| 787 | + | |
| 788 | + | |
| 789 | + | |
| 790 | + | |
| 791 | + | |
| 792 | + | |
| 793 | + | |
| 794 | + | |
| 795 | + | |
| 796 | + | |
| 797 | + | |
| 798 | + | |
| 799 | + | |
| 800 | + | |
| 801 | + | |
| 802 | + | |
| 803 | + | |
| 804 | + | |
| 805 | + | |
| 806 | + | |
| 807 | + | |
| 808 | + | |
| 809 | + | |
| 810 | + | |
| 811 | + | |
| 812 | + | |
| 813 | + | |
| 814 | + | |
| 815 | + | |
| 816 | + | |
| 817 | + | |
| 818 | + | |
| 819 | + | |
| 820 | + | |
| 821 | + | |
| 822 | + | |
| 823 | + | |
| 824 | + | |
| 825 | + | |
| 826 | + | |
| 827 | + | |
| 828 | + | |
| 829 | + | |
| 830 | + | |
| 831 | + | |
| 832 | + | |
| 833 | + | |
| 834 | + | |
| 835 | + | |
| 836 | + | |
| 837 | + | |
| 838 | + | |
| 839 | + | |
| 840 | + | |
| 841 | + | |
| 842 | + | |
| 843 | + | |
| 844 | + | |
| 845 | + | |
| 846 | + | |
| 847 | + | |
| 848 | + | |
| 849 | + | |
| 850 | + | |
| 851 | + | |
| 852 | + | |
| 853 | + | |
| 854 | + | |
| 855 | + | |
| 856 | + | |
| 857 | + | |
| 858 | + | |
| 859 | + | |
| 860 | + | |
0 commit comments