DAV Journal accepts VALARM without a trigger property #379

Closed
opened 2026-09-29 00:47:09 +00:00 by kayg · 2 comments
Owner

The one-time adversarial API run sent a Journal event with BEGIN:VALARM, ACTION:DISPLAY, and no TRIGGER. The DAV PUT returned 201; the probe logged DAV alarm: ACCEPTED hostile input at tests/adversarial/attack.py:2522-2528.

crates/calternal-dav/src/lib.rs says that Journal entries ignore Apple's optional VALARM components and reject invalid nested components. Please confirm if accepting and ignoring an alarm without its required fields is intentional. Keep the current probe expectation until the owner decides. No DAV code changed in touch-369.

The one-time adversarial API run sent a Journal event with `BEGIN:VALARM`, `ACTION:DISPLAY`, and no `TRIGGER`. The DAV PUT returned `201`; the probe logged `DAV alarm: ACCEPTED hostile input` at `tests/adversarial/attack.py:2522-2528`. `crates/calternal-dav/src/lib.rs` says that Journal entries ignore Apple's optional VALARM components and reject invalid nested components. Please confirm if accepting and ignoring an alarm without its required fields is intentional. Keep the current probe expectation until the owner decides. No DAV code changed in touch-369.
Author
Owner

Fixed on job/sec-batch in commits cd152bd3 and 71acd832. A Journal Log entry has no alarm field. The CalDAV parser now rejects both a VALARM without TRIGGER and a valid VALARM instead of accepting a PUT that silently drops reminder data. The parser regression covers both forms, and the real-server Journal DAV adversarial section completed without an alarm-acceptance finding. I kept the Apple Reminders implementation in reminders.rs untouched.

Fixed on job/sec-batch in commits cd152bd3 and 71acd832. A Journal Log entry has no alarm field. The CalDAV parser now rejects both a VALARM without TRIGGER and a valid VALARM instead of accepting a PUT that silently drops reminder data. The parser regression covers both forms, and the real-server Journal DAV adversarial section completed without an alarm-acceptance finding. I kept the Apple Reminders implementation in reminders.rs untouched.
Author
Owner

Fixed in cd6419620 (origin/dev); malformed Journal VALARM without TRIGGER is rejected by the DAV regression probe.

Fixed in cd6419620 (origin/dev); malformed Journal VALARM without TRIGGER is rejected by the DAV regression probe.
kayg closed this issue 2026-10-03 11:55:29 +00:00
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#379
No description provided.