From 260563af6cec8fed866f1e1355039d890a05331a Mon Sep 17 00:00:00 2001 From: sneak Date: Wed, 7 Oct 2026 07:13:11 +0000 Subject: [PATCH] docs: record the pre-1.0 security review in TODO.md (closes #383) The security review moves from Next Step to Completed Steps, saying what it read (the tree at 99292b9), that its ten findings are filed and fixed on next, which owner decisions it raised are still open, and what it did not cover. Next Step takes the one Future Steps item, cutting 1.0.0 once the milestone is empty. Status drops a dated gate result and links the current milestone PR. Model: opus-5-5 --- TODO.md | 45 +++++++++++++++++++++++++++++++-------------- 1 file changed, 31 insertions(+), 14 deletions(-) diff --git a/TODO.md b/TODO.md index 6f19c51..8924db6 100644 --- a/TODO.md +++ b/TODO.md @@ -23,28 +23,48 @@ pre-1.0, working towards the 1.0.0 milestone. Tagged v0.1.0 on 2026-02-27. The milestone is in flight on `next`; its `next` -> `main` PR is -[#190](https://git.eeqj.de/sneak/AutistMask/pulls/190). `make check` verified -green on `next` at `e9fa8be` on 2026-08-10, and `make build` produces -`dist/chrome/` and `dist/firefox/`, verified against the build's own receipt to -hold exactly the regular files and symlinks that build emitted, with `DEBUG` -compiled off. +[#388](https://git.eeqj.de/sneak/AutistMask/pulls/388). `make build` produces +`dist/chrome/` and `dist/firefox/` with `DEBUG` compiled off, and checks them +against the build's own receipt to hold exactly the regular files and symlinks +that build emitted. The backlog lives on the [Gitea tracker](https://git.eeqj.de/sneak/AutistMask/issues), which is authoritative; this file does not duplicate it. Full policy file set present. Real-browser end-to-end suites (`make test-e2e` for Chrome, -`make test-e2e-firefox` for Firefox) sit alongside `make check`, which now does -static analysis as well as formatting, and `.gitea/workflows/e2e.yml` runs both -of them on every push. +`make test-e2e-firefox` for Firefox) sit alongside `make check`, which runs the +tests, static analysis and the formatting check, and `.gitea/workflows/e2e.yml` +runs both of them on every push. # Next Step -Pre-1.0 security review of the extension (key handling, DEBUG mode policy, RPC -input validation) before any 1.0rc tag. Individual filed issues are parts of it, -but the review is broader than any of them. +Cut 1.0.0 once the +[1.0.0 milestone](https://git.eeqj.de/sneak/AutistMask/milestone/6) is empty, +then continue tagging as milestones land. # Completed Steps +- 2026-10-07: Pre-1.0 security review of the extension + ([#383](https://git.eeqj.de/sneak/AutistMask/issues/383)), reading the tree at + `99292b9` for key handling, the DEBUG mode policy, and what the background + accepts from pages, the configured RPC endpoint and the explorer, with what + the approval screens show from it; the site permission model and storage were + read as well. Its summary on that issue lists ten findings, each filed as its + own issue, and all ten are fixed on `next`; one, + [#399](https://git.eeqj.de/sneak/AutistMask/issues/399), put funds at risk. + Three decisions it raised are still open with the owner: the Argon2id cost for + the vault key ([#401](https://git.eeqj.de/sneak/AutistMask/issues/401)), a + connected site switching the network with no prompt + ([#408](https://git.eeqj.de/sneak/AutistMask/issues/408)), and `eth_sign` + signing as a personal message + ([#409](https://git.eeqj.de/sneak/AutistMask/issues/409)). Not covered: the + end-to-end suites were not run, the bundled phishing blocklist and token list + were not checked entry by entry, `ethers` and `libsodium-wrappers-sumo` were + taken as audited, and nothing was tried against a real network with real funds + ([#385](https://git.eeqj.de/sneak/AutistMask/issues/385)). The planned + independent second check of each finding did not run; the findings rest on the + reviewer's own reading of the code. + - 2026-10-07: Stale branches pruned from `origin` ([#167](https://git.eeqj.de/sneak/AutistMask/issues/167)). The issue classifies each branch it lists, with the evidence. The eighteen still on @@ -1887,6 +1907,3 @@ but the review is broader than any of them. Only work that has no issue of its own belongs here; everything else is on the tracker. - -- Cut 1.0.0 once the milestone is empty, then continue tagging as milestones - land. -- 2.54.0