fix(web): close sign-up until Forgejo 16.0.2 is deployed #448

Stängd
supernaut vill sammanfoga 77 incheckningar från s[2]s in i main
Ägare

Interim mitigation for #447. To be reverted with the tag bump, not a policy change.

Why

Forgejo 16.0.2 fixes an arbitrary file read in org-mode rendering (upstream PR 13682). Production
runs 16.0.1-rootless and has since 16.0.2 shipped on 2026-07-30.

Reaching that bug needs a repository holding an attacker-crafted .org file, so it needs an account.
Forgejo's own registration is already off (forgejo_disable_registration: true), which means the
portal is the only route to an account, and it was open. Closing it severs the chain.

What makes this worth mitigating now rather than scheduling: anything readable by the Forgejo process
includes app.ini, holding SECRET_KEY, INTERNAL_TOKEN, the database credentials, the mailer
credentials and the OIDC client secret. The first two are what forge sessions and decrypt stored
values, so a read of that one file escalates rather than merely leaking.

This is the ADR 0029 kill switch used exactly as its own comment describes.

Scope

One variable. web_signups_open is an Environment= in bitborg-web.container.j2, so the apply
re-renders the unit and restarts the portal. Seconds of portal downtime, nothing else touched.

The inline note carries the date, the reason and the revert condition, so this cannot quietly become
the new default.

Revert condition, stated so it is not forgotten

Set back to "true" in the same session that lands forgejo_image_tag: "16.0.2-rootless", after the
ADR 0038 concealment surfaces have been verified against 16.0.2 and any CSS they broke has been fixed.
Tracked as a checklist in #447.

Not in scope here

The upgrade itself. It needs the ADR 0038 gate cleared first: the concealment surfaces verified
against 16.0.2, then forgejo_image_tag and health_check_forgejo_concealment_verified_tag bumped in
one change. Verification is being done in the local/ preview rather than on prod, since
local/Makefile pins the floating 16-rootless and so pulls 16.0.2 today.

Interim mitigation for #447. **To be reverted with the tag bump**, not a policy change. ## Why Forgejo 16.0.2 fixes an **arbitrary file read in org-mode rendering** (upstream PR 13682). Production runs `16.0.1-rootless` and has since 16.0.2 shipped on 2026-07-30. Reaching that bug needs a repository holding an attacker-crafted `.org` file, so it needs an account. Forgejo's own registration is already off (`forgejo_disable_registration: true`), which means the portal is the **only** route to an account, and it was open. Closing it severs the chain. What makes this worth mitigating now rather than scheduling: anything readable by the Forgejo process includes `app.ini`, holding `SECRET_KEY`, `INTERNAL_TOKEN`, the database credentials, the mailer credentials and the OIDC client secret. The first two are what forge sessions and decrypt stored values, so a read of that one file escalates rather than merely leaking. This is the ADR 0029 kill switch used exactly as its own comment describes. ## Scope One variable. `web_signups_open` is an `Environment=` in `bitborg-web.container.j2`, so the apply re-renders the unit and restarts the portal. Seconds of portal downtime, nothing else touched. The inline note carries the date, the reason and the revert condition, so this cannot quietly become the new default. ## Revert condition, stated so it is not forgotten Set back to `"true"` in the same session that lands `forgejo_image_tag: "16.0.2-rootless"`, after the ADR 0038 concealment surfaces have been verified against 16.0.2 and any CSS they broke has been fixed. Tracked as a checklist in #447. ## Not in scope here The upgrade itself. It needs the ADR 0038 gate cleared first: the concealment surfaces verified against 16.0.2, then `forgejo_image_tag` and `health_check_forgejo_concealment_verified_tag` bumped in one change. Verification is being done in the `local/` preview rather than on prod, since `local/Makefile` pins the floating `16-rootless` and so pulls 16.0.2 today.
supernaut lade till 1 incheckning 2026-08-19 06:57:36 +00:00
fix(web): close sign-up until Forgejo 16.0.2 is deployed
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m42s
904290d41a
Interim mitigation, to be reverted with the tag bump. Not a policy change.

Forgejo 16.0.2 fixes an arbitrary file read in org-mode rendering (upstream PR
13682). Production runs 16.0.1-rootless and has since 16.0.2 shipped on
2026-07-30.

Reaching that bug needs a repository holding an attacker-crafted .org file,
which needs an account. Forgejo's own registration is already disabled
(forgejo_disable_registration: true), so the portal is the ONLY route to an
account, and it was open. Closing it severs the chain.

What makes this worth mitigating rather than just scheduling: anything readable
by the Forgejo process includes app.ini, which holds SECRET_KEY, INTERNAL_TOKEN,
the database credentials, the mailer credentials and the OIDC client secret.
SECRET_KEY and INTERNAL_TOKEN are what forge sessions and decrypt stored
values, so reading that one file escalates rather than merely leaking.

This is the ADR 0029 kill switch used as designed. The variable's own comment
already names this shape of use.

Revert in the same session that lands forgejo_image_tag: "16.0.2-rootless",
after the ADR 0038 concealment surfaces are verified against 16.0.2. The
inline note and #447 both say so, so this cannot quietly become the new default.

Refs #447
supernaut stängde denna ändringsförfrågan 2026-08-19 07:17:41 +00:00
Upphovsperson
Ägare

Closing unmerged, deliberately. Not abandoned, no longer needed.

This was insurance against one specific outcome: that Forgejo 16.0.2 had restructured the settings
markup and broken the ADR 0038 concealment CSS, making the upgrade slow and leaving the arbitrary
file read exposed meanwhile.

That outcome did not happen. Both concealment selectors were verified against 16.0.2 in the local/
preview, each with a toggle control proving our stylesheet is what hides the field rather than
Forgejo hiding it incidentally:

Surface Prod selector matches State With bitborg.css disabled
/user/settings Full name 1 HIDDEN VISIBLE
/user/settings/account "Set as primary" 1 HIDDEN VISIBLE

So the upgrade is unblocked now, and closing sign-up would cost two extra applies and two portal
restarts to protect a window measured in minutes. Going straight to the tag bump is both faster to
patched and less disruptive.

Kept available rather than deleted: if the apply is delayed for any reason, this branch is one merge
away from shutting the only route to an account. The reasoning is recorded in #447.

Closing unmerged, deliberately. Not abandoned, no longer needed. This was insurance against one specific outcome: that Forgejo 16.0.2 had restructured the settings markup and broken the ADR 0038 concealment CSS, making the upgrade slow and leaving the arbitrary file read exposed meanwhile. That outcome did not happen. Both concealment selectors were verified against 16.0.2 in the `local/` preview, each with a toggle control proving our stylesheet is what hides the field rather than Forgejo hiding it incidentally: | Surface | Prod selector matches | State | With `bitborg.css` disabled | | --- | --- | --- | --- | | `/user/settings` Full name | 1 | HIDDEN | VISIBLE | | `/user/settings/account` "Set as primary" | 1 | HIDDEN | VISIBLE | So the upgrade is unblocked now, and closing sign-up would cost two extra applies and two portal restarts to protect a window measured in minutes. Going straight to the tag bump is both faster to patched and less disruptive. Kept available rather than deleted: if the apply is delayed for any reason, this branch is one merge away from shutting the only route to an account. The reasoning is recorded in #447.
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m42s
Obligatorisk
Detaljer

Ändringsförfrågan stängd

Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!448
Ingen beskrivning angiven.