diff --git a/TODO.md b/TODO.md index 6f19c51..8924db6 100644 --- a/TODO.md +++ b/TODO.md @@ -23,28 +23,48 @@ pre-1.0, working towards the 1.0.0 milestone. Tagged v0.1.0 on 2026-02-27. The milestone is in flight on `next`; its `next` -> `main` PR is -[#190](https://git.eeqj.de/sneak/AutistMask/pulls/190). `make check` verified -green on `next` at `e9fa8be` on 2026-08-10, and `make build` produces -`dist/chrome/` and `dist/firefox/`, verified against the build's own receipt to -hold exactly the regular files and symlinks that build emitted, with `DEBUG` -compiled off. +[#388](https://git.eeqj.de/sneak/AutistMask/pulls/388). `make build` produces +`dist/chrome/` and `dist/firefox/` with `DEBUG` compiled off, and checks them +against the build's own receipt to hold exactly the regular files and symlinks +that build emitted. The backlog lives on the [Gitea tracker](https://git.eeqj.de/sneak/AutistMask/issues), which is authoritative; this file does not duplicate it. Full policy file set present. Real-browser end-to-end suites (`make test-e2e` for Chrome, -`make test-e2e-firefox` for Firefox) sit alongside `make check`, which now does -static analysis as well as formatting, and `.gitea/workflows/e2e.yml` runs both -of them on every push. +`make test-e2e-firefox` for Firefox) sit alongside `make check`, which runs the +tests, static analysis and the formatting check, and `.gitea/workflows/e2e.yml` +runs both of them on every push. # Next Step -Pre-1.0 security review of the extension (key handling, DEBUG mode policy, RPC -input validation) before any 1.0rc tag. Individual filed issues are parts of it, -but the review is broader than any of them. +Cut 1.0.0 once the +[1.0.0 milestone](https://git.eeqj.de/sneak/AutistMask/milestone/6) is empty, +then continue tagging as milestones land. # Completed Steps +- 2026-10-07: Pre-1.0 security review of the extension + ([#383](https://git.eeqj.de/sneak/AutistMask/issues/383)), reading the tree at + `99292b9` for key handling, the DEBUG mode policy, and what the background + accepts from pages, the configured RPC endpoint and the explorer, with what + the approval screens show from it; the site permission model and storage were + read as well. Its summary on that issue lists ten findings, each filed as its + own issue, and all ten are fixed on `next`; one, + [#399](https://git.eeqj.de/sneak/AutistMask/issues/399), put funds at risk. + Three decisions it raised are still open with the owner: the Argon2id cost for + the vault key ([#401](https://git.eeqj.de/sneak/AutistMask/issues/401)), a + connected site switching the network with no prompt + ([#408](https://git.eeqj.de/sneak/AutistMask/issues/408)), and `eth_sign` + signing as a personal message + ([#409](https://git.eeqj.de/sneak/AutistMask/issues/409)). Not covered: the + end-to-end suites were not run, the bundled phishing blocklist and token list + were not checked entry by entry, `ethers` and `libsodium-wrappers-sumo` were + taken as audited, and nothing was tried against a real network with real funds + ([#385](https://git.eeqj.de/sneak/AutistMask/issues/385)). The planned + independent second check of each finding did not run; the findings rest on the + reviewer's own reading of the code. + - 2026-10-07: Stale branches pruned from `origin` ([#167](https://git.eeqj.de/sneak/AutistMask/issues/167)). The issue classifies each branch it lists, with the evidence. The eighteen still on @@ -1887,6 +1907,3 @@ but the review is broader than any of them. Only work that has no issue of its own belongs here; everything else is on the tracker. - -- Cut 1.0.0 once the milestone is empty, then continue tagging as milestones - land.