Security sweep 2026-09: what was covered, and what was not #149

closed cmc opened this on 2026-09-04 19:27 UTC · security · milestone security

Discussion

cmc 2026-09-04 19:27 UTC

Tracking issue for the sweep that produced this milestone, so its coverage is a matter of record rather than memory.

** Verified against the threat model, and holding

  • Private repositories are indistinguishable from missing ones. Now asserted by TestPrivateRepoIsInvisible, which walks ~50 surfaces — every web route, thirteen control commands, and the listings a stranger legitimately reaches — as both an anonymous visitor and a logged-in stranger. Previously this was tested per feature, in whichever test happened to think of it, so a new surface could leak silently; the search added in v1.11.0 was covered only because it occurred to me at the time. Confirmed load-bearing by removing the visibility predicate and watching it fail on both the web and CLI paths.
  • Security headers. CSP, X-Frame-Options, nosniff, Referrer-Policy, COOP and HSTS are middleware over the whole mux, so a new route inherits them structurally rather than by remembering.
  • Parsers. deploy/audit.sh clean: go vet, govulncheck, and all five fuzz targets (pkt-line, commit, SSHSIG armor, PGP key, tokenizer) with no crashers.
  • #+INCLUDE: and #+SETUPFILE: file disclosure. Covered by internal/httpd/orgrender_test.go, including the relative-path traversal case.
  • Path handling. LFS validates the oid on read and write; release assets are pattern-checked on upload and matched exactly against stored names on download; blob, tree and raw read git objects rather than the filesystem.
  • Org and team commands. They enforce orgAdmin/orgAdminRef rather than policy.Can*, and team grants verify the repository belongs to the org. Correct, just not visible to a policy.Can* grep.

** Found

  • #147 — review verdicts from accounts without write access satisfy and block merge gates.
  • #148 — SSH control commands have no write rate limit while the API has one.

** Not covered, and why

  • The host. systemd sandboxing, sshd on 2222, firewall, unattended-upgrades, fail2ban, disk and file modes, restic append-only credentials. Reading production configuration is a separate exercise from auditing this repository, and needs doing against bay1 rather than the source.
  • Supply chain beyond govulncheck. No review of what the dependency set actually is, who maintains it, or what a compromised release of any of it would reach.
  • The runner host as an execution environment. #144 covers the missing isolation; nobody has tried to escape what is there.
  • Timing and traffic analysis. Token comparison is a hash index lookup by design, but nothing has been measured.
  • Denial of service by resource exhaustion beyond rate: large pushes, pathological diffs, deep histories, zip bombs in LFS.

referenced in commit 6df734dd58 by cmc: tests: a private repository is invisible on every surface, in one test

2026-09-04 19:38 UTC

referenced in commit f70349ad3c by cmc: ci: SonarCloud static analysis, report-only

2026-09-04 19:43 UTC

closed by commit aeedf75018 by cmc: wiki: record what the security sweep did not cover

2026-09-06 18:49 UTC