Problem
Two further pre-existing routing divergences between the equal-peer implementations, surfaced during the merge-gate review of #43 (both set aside there as out of scope):
- TS denies
exec anywhere in the path. ts/src/proxy.ts (~line 35) rejects any path containing an /exec segment, so e.g. GET /images/exec is denied in TypeScript but allowed (passthrough) in Go and Rust.
- Go's
matchEndpoint accepts subpaths of exact endpoints. POST /containers/create/extra reaches routeCreate in Go, while Rust and TypeScript exact-match the endpoint and fall through to default-deny.
Impact
Low severity. Neither is exploitable by itself (gates still apply to whatever is routed), but which requests reach the daemon — and which gate chain they go through — depends on the implementation language, which the equal-peers rule exists to prevent. Behaviour should converge; in both cases the stricter behaviour looks correct (deny POST /containers/create/extra everywhere; scope TS's exec check to the positions Go/Rust check).
Proposed solution
Decide the canonical row for each case, converge all three implementations, and pin each row with same-named unit tests in all three languages plus integration checks — the #24/#43 pattern. The Quint routing model should gain the two rows as well so the table stays the source of truth.
Alternatives considered
Which implementation(s) would this affect?
Problem
Two further pre-existing routing divergences between the equal-peer implementations, surfaced during the merge-gate review of #43 (both set aside there as out of scope):
execanywhere in the path.ts/src/proxy.ts(~line 35) rejects any path containing an/execsegment, so e.g.GET /images/execis denied in TypeScript but allowed (passthrough) in Go and Rust.matchEndpointaccepts subpaths of exact endpoints.POST /containers/create/extrareachesrouteCreatein Go, while Rust and TypeScript exact-match the endpoint and fall through to default-deny.Impact
Low severity. Neither is exploitable by itself (gates still apply to whatever is routed), but which requests reach the daemon — and which gate chain they go through — depends on the implementation language, which the equal-peers rule exists to prevent. Behaviour should converge; in both cases the stricter behaviour looks correct (deny
POST /containers/create/extraeverywhere; scope TS's exec check to the positions Go/Rust check).Proposed solution
Decide the canonical row for each case, converge all three implementations, and pin each row with same-named unit tests in all three languages plus integration checks — the #24/#43 pattern. The Quint routing model should gain the two rows as well so the table stays the source of truth.
Alternatives considered
Which implementation(s) would this affect?