Files
OwnCord/Server/plugin/host_events.go
T
J3vb 605f97051a docs(audit): correct CRITICAL #4 closure — Dispatch has a live hub caller
The closure rationale for audit finding #4 claimed in five places that
nothing in the server calls EventSink.Dispatch. That is disprovable by
grep: ws/hub.go:1034 calls Dispatch on every broadcast message, and
api/router.go:134-139 wires h.pluginSink whenever plugins are enabled.
The call site is pre-existing on main, not introduced by this branch.

Restate the closure on the claim the evidence actually supports:
Dispatch has exactly one caller outside the plugin package's tests
(ws/hub.go, on the hub's broadcast goroutine under seqMu), but its loop
body invokes no guest code and no production code calls Subscribe, so
the subscriber set is always empty and no guest code executes on the
event path. Finding #4 stays closed; the reason changes.

Also warn on Subscribe that adding the first production caller turns
Dispatch's loop live on the hub's hot path, and note in the SECURITY
GATE that the call site already exists so wiring delivery is not a new
integration.

Corrected in: plugin/host_events.go (Dispatch + Subscribe comments),
plugin/audit_closure_test.go, docs/audit-2026-04-07.md (row 4 and the
structural-mitigation paragraph), docs/audit-2026-07-19.md §1 row,
docs/plans/audit-2026-07-19-decisions.md D11.

Comments and docs only — no behaviour change.
2026-07-20 14:36:24 +02:00

132 lines
4.7 KiB
Go

// Phase C Step 9 — `events` host capability.
//
// Plugins that subscribe to events declare topic names in their manifest.
// At activation time the wazero-tagged build wires each subscription into
// the WS pub/sub hub via Hub.Subscribe; the default build records the
// subscription in-memory only.
package plugin
import (
"context"
"sync"
)
// Broadcaster is a function that sends a raw JSON payload to a WS channel.
// channelID=0 broadcasts to all connected clients. It is set by the WS
// wiring code (api/router.go) so the wazero-tagged build can emit events to
// clients without importing the ws package (avoids an import cycle).
type Broadcaster func(channelID int64, payload []byte)
// EventSink is the channel a subscribed plugin reads from. The wazero-tagged
// build forwards each event to the plugin's `on_event` exported function.
type EventSink struct {
mu sync.Mutex
subs map[string][]*Instance
broadcaster Broadcaster // set via SetBroadcaster; nil = no WS delivery
}
// NewEventSink returns a fresh sink. Used by the registry as the central
// fan-out for plugin event delivery.
func NewEventSink() *EventSink {
return &EventSink{subs: make(map[string][]*Instance)}
}
// SetBroadcaster wires a WS-layer delivery function into the sink so that
// the wazero-tagged build can push plugin-generated events to WS clients.
// Safe to call from any goroutine; subsequent Emit calls use the new value.
func (s *EventSink) SetBroadcaster(b Broadcaster) {
s.mu.Lock()
s.broadcaster = b
s.mu.Unlock()
}
// Emit delivers payload to all WS clients subscribed to channelID (or every
// client when channelID==0). It is a no-op when no broadcaster has been set.
// Called by the wazero-tagged build's host-function implementation.
func (s *EventSink) Emit(channelID int64, payload []byte) {
if s == nil {
return
}
s.mu.Lock()
b := s.broadcaster
s.mu.Unlock()
if b != nil {
b(channelID, payload)
}
}
// Subscribe binds inst to topic. Multiple plugins may subscribe to the same
// topic — events fan out to every subscriber.
//
// No production code calls Subscribe today (only this package's tests), so
// subs is always empty at runtime and Dispatch's loop never iterates. The
// first caller added here turns Dispatch's loop live on the hub's broadcast
// path — see the SECURITY GATE comment on Dispatch before adding one.
func (s *EventSink) Subscribe(topic string, inst *Instance) error {
if !inst.Manifest.HasCapability(CapEvents) {
return ErrCapabilityNotGranted
}
s.mu.Lock()
defer s.mu.Unlock()
s.subs[topic] = append(s.subs[topic], inst)
return nil
}
// UnsubscribeAll removes every subscription owned by inst (called on disable).
func (s *EventSink) UnsubscribeAll(inst *Instance) {
s.mu.Lock()
defer s.mu.Unlock()
for topic, list := range s.subs {
kept := list[:0]
for _, e := range list {
if e != inst {
kept = append(kept, e)
}
}
if len(kept) == 0 {
delete(s.subs, topic)
} else {
s.subs[topic] = kept
}
}
}
// Dispatch invokes every subscriber's on_event for topic.
//
// SECURITY GATE (audit 2026-04-07 finding #4 — "no rate limit on event
// delivery to plugins"). Read this before adding anything to the loop below.
//
// Dispatch already has a production caller: ws/hub.go calls it on every
// broadcast message when an operator has enabled plugins (api/router.go wires
// h.pluginSink whenever the registry is non-nil). That call site runs on the
// hub's broadcast goroutine while seqMu is held, so anything this function
// does is on the hub's hot path and must not block or re-enter the hub.
//
// Guest delivery is nonetheless NOT implemented in either build: the loop
// below touches no module, and no production code calls Subscribe (only this
// package's tests), so subs is empty and the loop never iterates. No guest
// code executes on the event path today — that, not an absent call site, is
// why a plugin cannot currently slow the hub by handling events slowly.
//
// Wiring guest delivery is what makes the finding real, so whoever does it
// must land, in the same change:
//
// - a per-plugin delivery rate limit (drop, never block the caller), and
// - the same per-call CPU-budget deadline invokeCommand applies
// (sandbox_wazero.go), and
// - delivery off the hub's broadcast goroutine so a slow guest cannot
// backpressure fan-out to WS clients or extend the seqMu hold.
//
// Until then this stays inert on purpose.
func (s *EventSink) Dispatch(ctx context.Context, topic string, payload []byte) {
s.mu.Lock()
subs := append([]*Instance(nil), s.subs[topic]...)
s.mu.Unlock()
for _, inst := range subs {
_ = inst // wazero-tagged build calls inst.module.invoke("on_event", payload)
_ = ctx
_ = payload
}
}