Skip to content

ucan: no depth, proof-count, or size budget on verify_chain allows oversized pre-handler verification work #467

Description

@euxaristia

Summary

Ucan::verify_chain (crates/gitlawb-core/src/ucan.rs:252-292) recurses through prf with no depth, proof-count, or per-chain size budget. Every linkage it checks is satisfiable by self-minted chains: proof.aud == self.iss holds by construction, and */* attenuates under */* (ucan.rs:52-60). require_ucan_chain runs before handlers on every write route group (crates/gitlawb-node/src/server.rs:49-56), and only creation_routes carries rate limiting (server.rs:92-112) - the remaining write groups are unlimited.

Impact

A crafted X-Ucan header within hyper's default header cap drives verified CPU cost into the tens of milliseconds per request ahead of any handler (measured offline against gitlawb-core; harness available on request), and headers are replayable (#253). On the write groups without rate limits this is a pre-handler CPU sink with no configuration bound. Nested chains cannot reach crash depth - each nesting level JSON-escapes the one below, so growth is self-limiting within the cap; the issue is unbounded per-request verification work, not memory or stack exhaustion.

Remediation

  1. Cap chain depth, proof count, and per-token size before walking prf; reject oversized X-Ucan headers early.
  2. Carry the same budgets into feat(node)!: anchor the UCAN proof chain and honour delegated git/push #331's anchored verification.
  3. Optionally cache (signer, token-hash) validations so replayed headers do not re-verify.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    crate:coregitlawb-core — identity, certs, encrypt, DID/UCANcrate:nodegitlawb-node — the serving node and REST APIkind:securityVulnerability fix or hardeningsev:mediumDegraded but workaround existssubsystem:identityDID/UCAN, http-sig auth, push authorization

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions