Skip to content

docs(security-remote): name both Hosted spec sections the e2e-lint rules cite - #919

Closed
dormouse-bot wants to merge 1 commit into
mainfrom
fix/ci-36995871745
Closed

dormouse-bot wants to merge 1 commit into
mainfrom
fix/ci-36995871745

Conversation

@dormouse-bot

Copy link
Copy Markdown
Collaborator

The 2026-10-02 security audit (run, #908) returned its one FAIL on stale spec text, not on code. docs/specs/security-remote.md -> "Trust boundary" said each scripts/e2e-lint.mjs rule names a line in that spec "or one in docs/specs/security-hosted.md -> "Rendezvous boundary"". But the two RelayRoom rules (Hosted's RelayRoom never names, parses, decodes, logs, or stores a frame and The shared frame layer copies ct field by field and reads it nowhere) cite lines under "Relay boundary". The lint already accepts either section: its header comment and its error message both name "Rendezvous boundary" and "Relay boundary". This change adds "Relay boundary" to the FAIL IF so the spec matches the code. node scripts/e2e-lint.mjs passes (31 rules).

Refs #908. The same audit raised WARNINGs that this PR leaves alone: loopback-lint checks 2 and 3 have no self-test case, and the one-time /connect/ bundle pulls in local-json-store readers through transitive imports. Each needs a separate decision.

The e2e-lint FAIL IF said each rule cites a security-remote.md line or one in
security-hosted.md -> "Rendezvous boundary", but the two RelayRoom rules cite
"Relay boundary". The lint itself already accepts both sections; the spec text
was stale, and the nightly security audit failed on it (#908).
@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying mouseterm with  Cloudflare Pages  Cloudflare Pages

Latest commit: 219544a
Status: ✅  Deploy successful!
Preview URL: https://06c06d72.mouseterm.pages.dev
Branch Preview URL: https://fix-ci-36995871745.mouseterm.pages.dev

View logs

@dormouse-bot

Copy link
Copy Markdown
Collaborator Author

Closing in favor of folding the same one-line change into #902 (suggestion). #902 edits the adjacent line, so this PR would conflict with it.

@dormouse-bot
dormouse-bot deleted the fix/ci-36995871745 branch October 2, 2026 14:20

This branch is waiting to be deployed

1 waiting deployment
hosted-preview — 219544ac Waiting Oct 2, 2026 by dormouse-bot via cleanup #753
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant