Skip to content

Fix DirectoryRoleBinding RoleRef mutability and RoleBinding ownership - #522

Merged
0x0013 merged 2 commits into
masterfrom
fri-22756
Sep 14, 2026
Merged

0x0013 merged 2 commits into
masterfrom
fri-22756

Conversation

@0x0013

@0x0013 0x0013 commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

roleRef mutability

Previously, DirectoryRoleBinding .spec.roleRef was mutable, but not properly parsed on change. Thus, a change in roleRef would leave existing and new members of DirectoryRoleBinding assigned to the previous roleRef.

Changing the RoleRef of an existing DirectoryRoleBinding was not intended behavior, thus we resolve this by setting the field as immutable. This mirrors the behavior of native Kubernetes primitives such as ClusterRoleBinding.

RoleBinding ownership

DRB reconciliation loop did not check controller ownership of a RoleBinding, thus it could mutate a RoleBinding resource of the same name, even when the parent DirectoryRoleBinding was not the owner of the resource. We now ensure ownership, and fail with "NotOwned" event if an existing resource was not created for this resource.

Jira: FRI-22756

@leonard-tesnov
leonard-tesnov requested a review from a team September 14, 2026 08:16

@leonard-tesnov leonard-tesnov left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Seems good to me. It fixes 2 vulns that were identified by the researchers.

@0x0013
0x0013 merged commit b74ed94 into master Sep 14, 2026
7 checks passed
@0x0013
0x0013 deleted the fri-22756 branch September 14, 2026 09:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants