Skip to content

Commit e4c7458

Browse files
authored
Merge pull request #332 from anandh8x/agent/docs-correct-security-status
docs: correct security and workspace status
2 parents 50d3cbb + 0b47e1f commit e4c7458

5 files changed

Lines changed: 55 additions & 33 deletions

File tree

‎CONTRIBUTING.md‎

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,9 @@ crates/
3131
├── gitlawb-core/ crypto primitives (DID, CID, HTTP sigs, UCAN, ref certs)
3232
├── gitlawb-node/ axum HTTP server, git smart HTTP, P2P, GraphQL
3333
├── gl/ CLI — identity, repos, MCP server, Base L2 names
34-
└── git-remote-gitlawb/ git remote helper for gitlawb:// URLs
34+
├── git-remote-gitlawb/ git remote helper for gitlawb:// URLs
35+
├── gitlawb-attest/ provenance attestations for ref-update certificates
36+
└── icaptcha-client/ client for the iCaptcha proof-of-intelligence service
3537
docs/ Operator guides
3638
scripts/ Build helpers
3739
```
@@ -106,7 +108,7 @@ cargo test -p gitlawb-node
106108

107109
- **TypeScript SDK** (`@gitlawb/sdk`) — client library for the HTTP API
108110
- **Python SDK** (`gitlawb`) — for ML/agent pipeline integration
109-
- **UCAN chain validation** — complete the auth middleware
111+
- **UCAN authorization** — add trusted issuer anchoring, capability checks, and authorization-aware revocation
110112
- **Filecoin storage tier** — wire up cold storage deals
111113
- **Documentation** — guides, tutorials, API examples
112114
- **Node operators** — run a public node and report issues

‎README.md‎

Lines changed: 12 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -19,14 +19,16 @@ The mission is simple: once code is pushed to the network, it should not disappe
1919

2020
## What is in this repository?
2121

22-
This is a Rust workspace with four crates:
22+
This is a Rust workspace with six crates:
2323

2424
| Crate | Purpose |
2525
|---|---|
2626
| `gitlawb-node` | The node daemon: Axum HTTP server, git smart-HTTP, Postgres metadata, libp2p gossip, optional S3/Tigris/IPFS/Arweave/Base PoS hooks. |
2727
| `gl` | The Gitlawb CLI for identity, repos, issues, PRs, bounties, tasks, peers, node status, MCP, and setup flows. |
2828
| `git-remote-gitlawb` | Git remote helper for `gitlawb://` URLs, so normal `git clone`, `git fetch`, and `git push` can talk to Gitlawb nodes. |
2929
| `gitlawb-core` | Shared primitives: Ed25519 identities, `did:key`, CIDs, RFC 9421 HTTP signatures, certificates, and UCAN tokens. |
30+
| `gitlawb-attest` | Pluggable external provenance attestations for ref-update certificates. |
31+
| `icaptcha-client` | Client for the iCaptcha proof-of-intelligence flow used to protect spam-prone writes. |
3032

3133
---
3234

@@ -54,6 +56,7 @@ Good today:
5456
- Bare git repository storage.
5557
- Git smart-HTTP clone/fetch/push.
5658
- RFC 9421-signed writes.
59+
- Repository and path-scoped visibility enforcement for repository and Git content reads, with 404-shaped repository denials.
5760
- DID identities.
5861
- `gl` CLI workflows.
5962
- libp2p peer discovery/gossip foundation.
@@ -63,11 +66,13 @@ Good today:
6366

6467
Known limitations:
6568

66-
- Private repository read enforcement is not wired yet. Treat public nodes as public infrastructure unless you restrict access at your proxy/firewall.
67-
- UCAN chain validation and revocation are not complete.
68-
- Repository write authorization is not capability-complete yet; HTTP signatures prove identity, not full authorization policy.
69+
- Repository write authorization is not secure by default: `GITLAWB_ENFORCE_OWNER_PUSH` defaults to `false` for compatibility, so a valid HTTP Signature identifies a pusher but does not enforce owner-only pushes.
70+
- UCAN proof chains are validated when supplied, but UCAN capabilities are not consulted by write authorization and the root issuer is not independently trust-anchored. UCANs therefore do not yet grant scoped collaborator access.
71+
- Agent lifecycle revocation is not enforced by HTTP Signature authorization; do not rely on removing or revoking an agent record to block a compromised signer.
72+
- Read visibility is not a blanket data-classification boundary: task, IPFS-pin, and Arweave-anchor listings are not repository-gated; withheld path names can be visible to a root reader; and later visibility changes cannot retract content already announced or externally anchored.
6973
- Peer writes are signed by upgraded nodes, but strict signed-peer enforcement is opt-in during rolling upgrades.
70-
- GraphQL mutations need mutation-aware auth before becoming a public write surface.
74+
- Current GraphQL mutations require an authenticated signer, but there is no mutation-specific guardrail that prevents a future mutation from omitting that check.
75+
- Pull-request review comments do not yet have threaded line-level anchors, and merges do not enforce approval requirements.
7176

7277
See:
7378

@@ -466,8 +471,8 @@ Short-term priorities:
466471
2. Add Docker and installer smoke tests.
467472
3. Improve operator docs and `gl doctor` checks.
468473
4. Harden peer writes and publish the signed-peer rollout plan.
469-
5. Implement repo write authorization: owner checks, protected branches, and UCAN capability checks.
470-
6. Implement private-read enforcement or remove private repo affordances until it exists.
474+
5. Close default-open write authorization and wire trusted UCAN delegation into repository permissions.
475+
6. Add threaded, line-level pull-request discussions and enforce approval requirements on merges.
471476
7. Add metrics for pushes, fetches, pack sizes, peer sync, failed auth, and webhooks.
472477

473478
Product direction:

‎SECURITY.md‎

Lines changed: 32 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -28,10 +28,11 @@ We will acknowledge receipt within 48 hours and aim to release a fix within 14 d
2828
- Every git object is content-addressed via CIDv1 (SHA-256)
2929
- Tamper-evident by construction — a modified object changes its CID
3030

31-
**UCAN capability tokens**
32-
- Bootstrap UCAN tokens issued at registration
33-
- Capability-scoped: `git:push`, `git:fetch`, `issue:create`, `pr:open`
34-
- JWT-format tokens with expiry
31+
**UCAN token validation**
32+
- Bootstrap UCAN tokens are issued at registration.
33+
- A supplied token's signature, audience, expiry, and proof-chain attenuation are validated.
34+
- Tokens use a signed JSON wire format with expiry.
35+
- Capability grants are not yet consulted by repository write authorization; see the limitations below.
3536

3637
**Smart contracts (Base Sepolia testnet)**
3738
- `GitlawbDIDRegistry` — on-chain DID → document registry
@@ -48,21 +49,20 @@ We will acknowledge receipt within 48 hours and aim to release a fix within 14 d
4849

4950
---
5051

51-
## Known Limitations (Planned for v0.2)
52+
## Known Limitations
5253

53-
These are **documented, accepted limitations** for the current live release and should be prioritized without breaking existing nodes during rolling upgrades.
54+
These are documented limitations of the current live release. They should be prioritized without breaking existing nodes during rolling upgrades.
5455

55-
### UCAN chain validation
56-
- The auth middleware verifies HTTP Signatures and token structure, but does not yet walk the full UCAN delegation chain.
57-
- **Impact:** A node cannot yet enforce fine-grained capability delegation. Currently, any registered agent with a valid HTTP Signature can push.
58-
- **Mitigation:** Keep write endpoints signed, treat public nodes as public infrastructure, and treat trust scores as soft rate-limiting signals rather than authorization.
59-
- **Fix target:** v0.2
56+
### Repository write authorization defaults
57+
- `git-receive-pack` verifies HTTP Signatures, but `GITLAWB_ENFORCE_OWNER_PUSH` defaults to `false` for compatibility during rollout.
58+
- **Impact:** With the default setting, a valid signature authenticates the pusher but does not require that DID to be the repository owner.
59+
- **Mitigation:** Set `GITLAWB_ENFORCE_OWNER_PUSH=true` on nodes where owner-only pushes are required. Confirm that every legitimate pusher uses the owner DID before enabling it.
6060

61-
### UCAN revocation
62-
- Issued UCAN tokens cannot be revoked before expiry.
63-
- **Impact:** If a keypair is compromised, the attacker retains access until the UCAN expires (default: 30 days).
64-
- **Mitigation:** Regenerate your identity (`gl identity new --force`) and re-register to issue a new UCAN. Until revocation/blocklisting is implemented, operators should remove compromised DIDs directly from their local database.
65-
- **Fix target:** v0.2
61+
### UCAN delegation and revocation
62+
- The middleware validates a supplied UCAN's complete proof chain, but a root token is accepted without an independently trusted issuer anchor. `Ucan::can` is not yet used by write handlers, so a UCAN does not grant scoped repository access.
63+
- Agent lifecycle revocation is not checked by HTTP Signature authorization. Removing or revoking an agent record does not itself block a compromised DID from authenticating.
64+
- **Impact:** Do not use UCANs for collaborator permissions or rely on agent-record revocation as a key-compromise response.
65+
- **Mitigation:** Keep sensitive deployments behind operational network controls and enable owner-only push enforcement where it fits the deployment until trusted delegation and authorization-aware revocation are implemented.
6666

6767
### git-receive-pack authentication
6868
- The `git-receive-pack` endpoint enforces HTTP Signature auth. Plain Git smart-HTTP clients do not generate those headers, so the `git-remote-gitlawb` helper is required for pushes.
@@ -71,10 +71,20 @@ These are **documented, accepted limitations** for the current live release and
7171
- **Fix target:** v0.2
7272

7373
### Private repository reads
74-
- Repository records have an `is_public` field and the node exposes `GITLAWB_PUBLIC_READ`, but per-repository private-read enforcement is not wired in the current live release.
75-
- **Impact:** Do not store private repositories or secrets on public nodes.
76-
- **Mitigation:** Run isolated nodes for non-public data and restrict network access at the reverse proxy or firewall layer.
77-
- **Fix target:** v0.2
74+
- Repository and path-scoped visibility checks are enforced for repository API and Git content reads. A denied whole-repository or root read returns the same 404 shape as a missing repository, so the denial does not reveal private-repository existence.
75+
- Sparse-clone support exposes withheld path globs to callers who may read the repository root. Do not put sensitive information in withheld path names.
76+
- `GET /api/v1/tasks`, `/api/v1/ipfs/pins`, and `/api/v1/arweave/anchors` are not repository-gated. Task records include a UCAN token; pin and anchor listings expose object and ref metadata.
77+
- Changing a repository's visibility controls future serving, but cannot retract ref metadata or configured external pins and anchors already announced while the repository was public. Do not push secrets to an announceable repository.
78+
- **Impact:** Visibility policies protect the repository and Git content routes they gate, not every metadata endpoint or previously published content.
79+
- **Remaining boundary:** This read control does not address the independent write-authorization and UCAN-delegation limitations described above.
80+
81+
### Pull-request review enforcement
82+
- Pull-request review comments are not yet threaded or line-anchored, and merges do not enforce required approvals.
83+
- **Impact:** Teams must use their own review policy or external controls for merge approval requirements.
84+
85+
### GraphQL mutation coverage
86+
- Existing GraphQL mutations require an authenticated signer, but a mutation-specific source-level guardrail has not yet been added for future mutations.
87+
- **Impact:** A new mutation could accidentally omit its signer check without an explicit test fence.
7888

7989
### Peer route hardening rollout
8090
- Peer announce and sync notification routes accept signed requests and verify DID matches when a signature is present.
@@ -101,15 +111,15 @@ These are **documented, accepted limitations** for the current live release and
101111
| Key storage | PKCS#8 PEM, 0600 permissions |
102112
| Content hashing | SHA-256 via CIDv1 |
103113
| HTTP Signatures | RFC 9421 (Ed25519 + SHA-256 Content-Digest) |
104-
| UCAN tokens | JWT (Ed25519 signatures) |
114+
| UCAN tokens | Signed JSON object (Ed25519 signature) |
105115
| On-chain | ECDSA secp256k1 (Base L2 / Ethereum) |
106116

107117
---
108118

109119
## Threat Model
110120

111121
gitlawb is designed to be secure against:
112-
- **Unauthorized writes** — HTTP Signature auth on all write endpoints
122+
- **Unauthenticated writes** — HTTP Signature auth on protected write endpoints; see Known Limitations for owner and capability authorization gaps
113123
- **Tampered git objects** — CIDv1 content addressing detects modification
114124
- **Identity spoofing** — DIDs derived from public keys, unforgeable without the private key
115125
- **Centralized takedown** — no single point of control; data on IPFS + Arweave

‎docs/MAINTAINER-ROADMAP.md‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -38,8 +38,8 @@ Owner focus: node reliability.
3838

3939
Owner focus: protocol/auth.
4040

41-
- Implement repo write authorization: repo owner checks, protected branches, UCAN capability checks, and clear delegation semantics.
42-
- Implement private-read enforcement or remove private-repo affordances until it exists.
41+
- Close default-open repo write authorization and wire trusted UCAN delegation into repository permissions.
42+
- Close the remaining visibility gaps: restrict or document task, pin, and anchor metadata routes, and publish an irreversible-publication policy.
4343
- Add UCAN revocation or blocklisting, with an emergency compromised-key runbook.
4444
- Add mutation-aware GraphQL auth before GraphQL becomes a public write API surface.
4545
- Harden peer registration and outbound peer calls against SSRF and peer-list poisoning.

‎docs/OSS-READINESS-AUDIT.md‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,11 @@
33
Date: 2026-05-28
44
Repo state inspected: `main` tracking `origin/main`, starting at `b12c6bc feat: per-DID rate limiting on creation endpoints (10/hour) (#13)`.
55

6+
> **Historical snapshot.** This audit describes the repository at the commit above. Its
7+
> statements about incomplete UCAN chain validation and absent per-repository read
8+
> enforcement have been superseded; see [`SECURITY.md`](../SECURITY.md) for the current
9+
> security posture.
10+
611
## Commands run
712

813
```sh

0 commit comments

Comments
 (0)