Skip to content

docs(changelog): add the missing SE-273 security fragment - #198

Merged
Lionear merged 1 commit into
developfrom
fix/SE-273-mcp-readonly-pragma
Sep 29, 2026
Merged

Lionear merged 1 commit into
developfrom
fix/SE-273-mcp-readonly-pragma

Conversation

@Lionear

@Lionear Lionear commented Sep 29, 2026

Copy link
Copy Markdown
Owner

SE-273: MCP read-only authorization let writing SQLite PRAGMAs through.

The fix itself is already on develop

The classifier change landed in 80761cd, merged via #178 on 2026-08-31. PRAGMA is no longer a read
keyword. Only allow-listed introspection pragmas without an assignment (table_info, index_list,
foreign_key_list, integrity_check, …) classify as Read. Every other pragma is Ddl, which
includes the = value and name(value) setter forms and anything not on the list. Ddl is only
permitted for Sandbox. The tests the ticket requires are in McpSqlClassifierTests:
PRAGMA user_version = 999 and PRAGMA journal_mode = OFF are refused under ReadOnly, and
PRAGMA table_info('x') is still allowed.

What this PR adds

That merge shipped without a changelog.d fragment, so the next release notes would not have
mentioned a security fix. This PR adds changelog.d/SE-273.security.md and nothing else.

Verification

  • dotnet test tests/DataTray.Core.Tests --filter Mcp: 40 passed, 0 failed.
  • I also ran a throwaway probe (not committed) against the real classifier. Each of these is refused
    under ReadOnly: pragma\tuser_version=1, PRAGMA/**/user_version=1, PRAGMA "user_version" = 1,
    PRAGMA journal_mode('OFF'), PRAGMA wal_checkpoint(TRUNCATE), PRAGMA optimize,
    PRAGMA incremental_vacuum(10), PRAGMA writable_schema and a ;-chained second pragma.

Notes, not changed here

  • A bare PRAGMA journal_mode (a query, not a set) is refused under ReadOnly because it is not on the
    allow-list. That is safe, but stricter than the ticket's example.
  • The name check stops at (, so PRAGMA table_info('x') user_version classifies as Read. SQLite
    itself rejects that as a syntax error, so it gives no write path.

The PRAGMA classification fix (80761cd, PR #178) was merged without a
changelog.d fragment, so the next release notes would not mention it.
@Lionear
Lionear merged commit 5d75fde into develop Sep 29, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant