docs: record the pre-1.0 security review in TODO.md #497
@@ -23,28 +23,48 @@
|
|||||||
|
|
||||||
pre-1.0, working towards the 1.0.0 milestone. Tagged v0.1.0 on 2026-02-27. The
|
pre-1.0, working towards the 1.0.0 milestone. Tagged v0.1.0 on 2026-02-27. The
|
||||||
milestone is in flight on `next`; its `next` -> `main` PR is
|
milestone is in flight on `next`; its `next` -> `main` PR is
|
||||||
[#190](https://git.eeqj.de/sneak/AutistMask/pulls/190). `make check` verified
|
[#388](https://git.eeqj.de/sneak/AutistMask/pulls/388). `make build` produces
|
||||||
green on `next` at `e9fa8be` on 2026-08-10, and `make build` produces
|
`dist/chrome/` and `dist/firefox/` with `DEBUG` compiled off, and checks them
|
||||||
`dist/chrome/` and `dist/firefox/`, verified against the build's own receipt to
|
against the build's own receipt to hold exactly the regular files and symlinks
|
||||||
hold exactly the regular files and symlinks that build emitted, with `DEBUG`
|
that build emitted.
|
||||||
compiled off.
|
|
||||||
|
|
||||||
The backlog lives on the
|
The backlog lives on the
|
||||||
[Gitea tracker](https://git.eeqj.de/sneak/AutistMask/issues), which is
|
[Gitea tracker](https://git.eeqj.de/sneak/AutistMask/issues), which is
|
||||||
authoritative; this file does not duplicate it. Full policy file set present.
|
authoritative; this file does not duplicate it. Full policy file set present.
|
||||||
Real-browser end-to-end suites (`make test-e2e` for Chrome,
|
Real-browser end-to-end suites (`make test-e2e` for Chrome,
|
||||||
`make test-e2e-firefox` for Firefox) sit alongside `make check`, which now does
|
`make test-e2e-firefox` for Firefox) sit alongside `make check`, which runs the
|
||||||
static analysis as well as formatting, and `.gitea/workflows/e2e.yml` runs both
|
tests, static analysis and the formatting check, and `.gitea/workflows/e2e.yml`
|
||||||
of them on every push.
|
runs both of them on every push.
|
||||||
|
|
||||||
# Next Step
|
# Next Step
|
||||||
|
|
||||||
Pre-1.0 security review of the extension (key handling, DEBUG mode policy, RPC
|
Cut 1.0.0 once the
|
||||||
input validation) before any 1.0rc tag. Individual filed issues are parts of it,
|
[1.0.0 milestone](https://git.eeqj.de/sneak/AutistMask/milestone/6) is empty,
|
||||||
but the review is broader than any of them.
|
then continue tagging as milestones land.
|
||||||
|
|
||||||
# Completed Steps
|
# Completed Steps
|
||||||
|
|
||||||
|
- 2026-10-07: Pre-1.0 security review of the extension
|
||||||
|
([#383](https://git.eeqj.de/sneak/AutistMask/issues/383)), reading the tree at
|
||||||
|
`99292b9` for key handling, the DEBUG mode policy, and what the background
|
||||||
|
accepts from pages, the configured RPC endpoint and the explorer, with what
|
||||||
|
the approval screens show from it; the site permission model and storage were
|
||||||
|
read as well. Its summary on that issue lists ten findings, each filed as its
|
||||||
|
own issue, and all ten are fixed on `next`; one,
|
||||||
|
[#399](https://git.eeqj.de/sneak/AutistMask/issues/399), put funds at risk.
|
||||||
|
Three decisions it raised are still open with the owner: the Argon2id cost for
|
||||||
|
the vault key ([#401](https://git.eeqj.de/sneak/AutistMask/issues/401)), a
|
||||||
|
connected site switching the network with no prompt
|
||||||
|
([#408](https://git.eeqj.de/sneak/AutistMask/issues/408)), and `eth_sign`
|
||||||
|
signing as a personal message
|
||||||
|
([#409](https://git.eeqj.de/sneak/AutistMask/issues/409)). Not covered: the
|
||||||
|
end-to-end suites were not run, the bundled phishing blocklist and token list
|
||||||
|
were not checked entry by entry, `ethers` and `libsodium-wrappers-sumo` were
|
||||||
|
taken as audited, and nothing was tried against a real network with real funds
|
||||||
|
([#385](https://git.eeqj.de/sneak/AutistMask/issues/385)). The planned
|
||||||
|
independent second check of each finding did not run; the findings rest on the
|
||||||
|
reviewer's own reading of the code.
|
||||||
|
|
||||||
- 2026-10-07: Stale branches pruned from `origin`
|
- 2026-10-07: Stale branches pruned from `origin`
|
||||||
([#167](https://git.eeqj.de/sneak/AutistMask/issues/167)). The issue
|
([#167](https://git.eeqj.de/sneak/AutistMask/issues/167)). The issue
|
||||||
classifies each branch it lists, with the evidence. The eighteen still on
|
classifies each branch it lists, with the evidence. The eighteen still on
|
||||||
@@ -1887,6 +1907,3 @@ but the review is broader than any of them.
|
|||||||
|
|
||||||
Only work that has no issue of its own belongs here; everything else is on the
|
Only work that has no issue of its own belongs here; everything else is on the
|
||||||
tracker.
|
tracker.
|
||||||
|
|
||||||
- Cut 1.0.0 once the milestone is empty, then continue tagging as milestones
|
|
||||||
land.
|
|
||||||
|
|||||||
Reference in New Issue
Block a user