.gitbay/wiki/Architecture/10-Known-Gaps.org
32 lines · 2699 bytes
1#+title: Known gaps
2
3Open weaknesses. Issues on krz/gitbay are public; this page gives the
4title and the consequence, not a reproduction. The current list is the
5open issues labelled =security=:
6https://gitbay.org/krz/gitbay/issues?label=security. The table below is
7what the 2026-09-27 review found; remove a row when its issue closes.
8
9* Filed
10
11| Issue | Area | Gap | Severity |
12|-------+------------------+-----------------------------------------------------------------------+----------|
13| #259 | Recovery | No restore has been exercised; the drill is written (Admin wiki) and not yet run | high |
14| #260 | CI network | Builds share the runner's source address; no egress policy | medium |
15| #261 | Various | Migration foreign-key check after commit; three web writes bypass dispatch; documentation drift | medium |
16| #297 | Credentials | A browser session can mint tokens and keys that outlive it | low |
17
18* Not filed
19
20| Area | Gap | Severity |
21|-------+-------------------------------------------------------------------------------------------------------------+----------|
22| Audit | Removing the newest audit rows, or writing new rows under their freed ids, is not detectable from the database; only comparing =gitbayd admin audit verify='s last id and hash with the daemon's journal shows it. Rows written by =gitbayd shell= (=ssh.mode = "system"=) and host admin commands have no journal copy, and the refusal caps are per process, so under that mode each connection counts separately | low |
23| Availability | Under =ssh.mode = "system"= each SSH session is a separate =gitbayd shell= process, so the pack-generation limit (=internal/packlimit=, #262) cannot count SSH clones across sessions; only HTTP and git:// share a budget there | low |
24
25* Questions an auditor will ask that have no answer yet
26
27| Question | Status |
28|-----------------------------------------------------------+------------------------------------------|
29| What is the measured recovery time? | unmeasured (#259) |
30| How many concurrent clones does the host sustain? | unmeasured (#262) |
31| What can a build reach on the host's network? | configuration inspected, reachability untested (#260) |
32| Have the collaboration features been used by independent users? | no; one human user, tests only |