wiki: record what the security sweep did not cover !286

merged merged by cmc on 2026-09-06 18:49 UTC · krz/gitbay:sweep-149 into main

1 file changed, +26 −0

Layout: unified · split

.gitbay/wiki/Threat-Model.org +26
@@ -141,6 +141,32 @@ Treat the runner host as executing untrusted code: keep it off the
141daemon's host where the database lives, or scope it to repositories 141daemon's host where the database lives, or scope it to repositories
142whose writers you trust. 142whose writers you trust.
143 143
144* What has not been audited
145
146The 2026-09 sweep (krz/gitbay#149) read this repository against the
147claims above. Its two findings — review verdicts from accounts without
148write access deciding merge gates (#147), and control commands having no
149write rate limit while the API had one (#148) — are fixed, as is #173,
150found afterwards in the same milestone. What it did not reach, and why,
151is recorded here rather than in a closed issue:
152
153- *The host.* systemd sandboxing, sshd on 2222, the firewall,
154 unattended-upgrades, fail2ban, disk and file modes, restic append-only
155 credentials. Reading production configuration is a separate exercise
156 from auditing the source, and needs doing against bay1.
157- *The supply chain beyond =govulncheck=.* No review of what the
158 dependency set is, who maintains it, or what a compromised release of
159 any of it would reach.
160- *The runner host as an execution environment.* Nobody has tried to
161 escape what is there. #144 covers the missing isolation.
162- *Timing and traffic analysis.* Token comparison is a hash index lookup
163 by design, but nothing has been measured.
164- *Denial of service by resource exhaustion* beyond rate: large pushes,
165 pathological diffs, deep histories, zip bombs in LFS.
166
167A sweep is a point in time. This section says what a reader should not
168assume has been checked.
169
144* Residual risks, accepted 170* Residual risks, accepted
145 171
146- External images in rendered READMEs and profile about text load from 172- External images in rendered READMEs and profile about text load from