From 219544aca3076b991ddf93b96b403c919210f46b Mon Sep 17 00:00:00 2001 From: dormouse-bot <287024035+dormouse-bot@users.noreply.github.com> Date: Fri, 2 Oct 2026 14:15:46 +0000 Subject: [PATCH] docs(security-remote): name both Hosted sections the e2e-lint rules cite The e2e-lint FAIL IF said each rule cites a security-remote.md line or one in security-hosted.md -> "Rendezvous boundary", but the two RelayRoom rules cite "Relay boundary". The lint itself already accepts both sections; the spec text was stale, and the nightly security audit failed on it (#908). --- docs/specs/security-remote.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/specs/security-remote.md b/docs/specs/security-remote.md index abb14b771..5ecc2c08b 100644 --- a/docs/specs/security-remote.md +++ b/docs/specs/security-remote.md @@ -58,7 +58,7 @@ phone, or fabricate a request (rationale). The only path back out is - **FAIL IF** a private key agreement ever leaves WebCrypto. **X25519 stays WebCrypto-only** (`generateKey` / `deriveBits` / `importKey`) and **never a JavaScript curve** (`@noble/curves`, `tweetnacl`, `libsodium`, or any other). The one bundled primitive is ChaCha20-Poly1305, from an exactly-pinned `@noble/ciphers` release; its two import sites and the pin's audit delta are recorded in `remote-lib-common/src/security/noise.ts`'s header, rewritten by any version bump in the same commit (rationale). - **FAIL IF** the Burrow's Noise static is ever sent to the Relay, or a Burrow runs with halves that do not correspond: it is minted locally *before* the enrollment request and never sent in it, persisted only where `burrowToken` is, and `BurrowService` derives the public point from the private half and compares before starting — a mismatch keeps the Burrow down (rationale). - **FAIL IF** `remote-lib-common/src/security/` stops being the shared implementation: the Relay, the Burrow, and the Pocket client must verify assertions, presence challenges, handshakes, and transport framing with the same modules. Conformance is proven against an independent implementation's published vector (`remote-lib-common/test/noise.test.mjs`), never against a value the production state machine computed, and this section's properties are driven end to end by `remote-lib-common/test/security-guarantees.test.mjs`. -- **FAIL IF** `scripts/e2e-lint.mjs` and `scripts/e2e-lint-selftest.mjs` stop running in the root `pnpm test`, or a rule is added to the lint without the self-test proving it load-bearing. Each rule in `RULES` names the line above that it enforces, or one in `docs/specs/security-hosted.md` -> "Rendezvous boundary" (rationale). +- **FAIL IF** `scripts/e2e-lint.mjs` and `scripts/e2e-lint-selftest.mjs` stop running in the root `pnpm test`, or a rule is added to the lint without the self-test proving it load-bearing. Each rule in `RULES` names the line above that it enforces, or one in `docs/specs/security-hosted.md` -> "Rendezvous boundary" or "Relay boundary" (rationale). - **FAIL IF** the self-host Relay (`relay/`) begins admitting an `accountId` other than `SELFHOST_ACCOUNT_ID` (`remote-lib-common/src/remote/wire.ts`), or gains a self-serve signup path. The Hosted Relay's accounts are `docs/specs/security-hosted.md` -> "Relay boundary"; Reserved: the cloud boundary is analyzed in `## Future` -> Cloud-hosted mode before Hosted carries terminal traffic. ### Relay origin