Tracking issue for the sweep that produced this milestone, so its coverage is a matter of record rather than memory.
** Verified against the threat model, and holding
- Private repositories are indistinguishable from missing ones. Now asserted by
TestPrivateRepoIsInvisible, which walks ~50 surfaces — every web route, thirteen control commands, and the listings a stranger legitimately reaches — as both an anonymous visitor and a logged-in stranger. Previously this was tested per feature, in whichever test happened to think of it, so a new surface could leak silently; the search added in v1.11.0 was covered only because it occurred to me at the time. Confirmed load-bearing by removing the visibility predicate and watching it fail on both the web and CLI paths. - Security headers. CSP,
X-Frame-Options,nosniff,Referrer-Policy, COOP and HSTS are middleware over the whole mux, so a new route inherits them structurally rather than by remembering. - Parsers.
deploy/audit.shclean:go vet,govulncheck, and all five fuzz targets (pkt-line, commit, SSHSIG armor, PGP key, tokenizer) with no crashers. #+INCLUDE:and#+SETUPFILE:file disclosure. Covered byinternal/httpd/orgrender_test.go, including the relative-path traversal case.- Path handling. LFS validates the oid on read and write; release assets are pattern-checked on upload and matched exactly against stored names on download; blob, tree and raw read git objects rather than the filesystem.
- Org and team commands. They enforce
orgAdmin/orgAdminRefrather thanpolicy.Can*, and team grants verify the repository belongs to the org. Correct, just not visible to apolicy.Can*grep.
** Found
- #147 — review verdicts from accounts without write access satisfy and block merge gates.
- #148 — SSH control commands have no write rate limit while the API has one.
** Not covered, and why
- The host. systemd sandboxing, sshd on 2222, firewall, unattended-upgrades, fail2ban, disk and file modes, restic append-only credentials. Reading production configuration is a separate exercise from auditing this repository, and needs doing against bay1 rather than the source.
- Supply chain beyond govulncheck. No review of what the dependency set actually is, who maintains it, or what a compromised release of any of it would reach.
- The runner host as an execution environment. #144 covers the missing isolation; nobody has tried to escape what is there.
- Timing and traffic analysis. Token comparison is a hash index lookup by design, but nothing has been measured.
- Denial of service by resource exhaustion beyond rate: large pushes, pathological diffs, deep histories, zip bombs in LFS.
referenced in commit 6df734dd58 by cmc: tests: a private repository is invisible on every surface, in one test
2026-09-04 19:38 UTC