docs(security-remote): name both Hosted spec sections the e2e-lint rules cite - #919
Closed
dormouse-bot wants to merge 1 commit into
Closed
dormouse-bot wants to merge 1 commit into
dormouse-bot wants to merge 1 commit into
Conversation
The e2e-lint FAIL IF said each rule cites a security-remote.md line or one in security-hosted.md -> "Rendezvous boundary", but the two RelayRoom rules cite "Relay boundary". The lint itself already accepts both sections; the spec text was stale, and the nightly security audit failed on it (#908).
Deploying mouseterm with
|
| Latest commit: |
219544a
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://06c06d72.mouseterm.pages.dev |
| Branch Preview URL: | https://fix-ci-36995871745.mouseterm.pages.dev |
Collaborator
Author
|
Closing in favor of folding the same one-line change into #902 (suggestion). #902 edits the adjacent line, so this PR would conflict with it. |
dormouse-bot
requested a deployment
to
hosted-preview
October 2, 2026 14:20 — with
GitHub Actions
Waiting
This branch is waiting to be deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The 2026-10-02 security audit (run, #908) returned its one
FAILon stale spec text, not on code.docs/specs/security-remote.md-> "Trust boundary" said eachscripts/e2e-lint.mjsrule names a line in that spec "or one indocs/specs/security-hosted.md-> "Rendezvous boundary"". But the twoRelayRoomrules (Hosted's RelayRoom never names, parses, decodes, logs, or stores a frame and The shared frame layer copiesctfield by field and reads it nowhere) cite lines under "Relay boundary". The lint already accepts either section: its header comment and its error message both name "Rendezvous boundary" and "Relay boundary". This change adds "Relay boundary" to theFAIL IFso the spec matches the code.node scripts/e2e-lint.mjspasses (31 rules).Refs #908. The same audit raised WARNINGs that this PR leaves alone:
loopback-lintchecks 2 and 3 have no self-test case, and the one-time/connect/bundle pulls inlocal-json-storereaders through transitive imports. Each needs a separate decision.