Skip to content
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion docs/specs/security-remote.md
Original file line number Diff line number Diff line change
Expand Up @@ -58,7 +58,7 @@ phone, or fabricate a request (rationale). The only path back out is
- **FAIL IF** a private key agreement ever leaves WebCrypto. **X25519 stays WebCrypto-only** (`generateKey` / `deriveBits` / `importKey`) and **never a JavaScript curve** (`@noble/curves`, `tweetnacl`, `libsodium`, or any other). The one bundled primitive is ChaCha20-Poly1305, from an exactly-pinned `@noble/ciphers` release; its two import sites and the pin's audit delta are recorded in `remote-lib-common/src/security/noise.ts`'s header, rewritten by any version bump in the same commit (rationale).
- **FAIL IF** the Burrow's Noise static is ever sent to the Relay, or a Burrow runs with halves that do not correspond: it is minted locally *before* the enrollment request and never sent in it, persisted only where `burrowToken` is, and `BurrowService` derives the public point from the private half and compares before starting — a mismatch keeps the Burrow down (rationale).
- **FAIL IF** `remote-lib-common/src/security/` stops being the shared implementation: the Relay, the Burrow, and the Pocket client must verify assertions, presence challenges, handshakes, and transport framing with the same modules. Conformance is proven against an independent implementation's published vector (`remote-lib-common/test/noise.test.mjs`), never against a value the production state machine computed, and this section's properties are driven end to end by `remote-lib-common/test/security-guarantees.test.mjs`.
- **FAIL IF** `scripts/e2e-lint.mjs` and `scripts/e2e-lint-selftest.mjs` stop running in the root `pnpm test`, or a rule is added to the lint without the self-test proving it load-bearing. Each rule in `RULES` names the line above that it enforces, or one in `docs/specs/security-hosted.md` -> "Rendezvous boundary" (rationale).
- **FAIL IF** `scripts/e2e-lint.mjs` and `scripts/e2e-lint-selftest.mjs` stop running in the root `pnpm test`, or a rule is added to the lint without the self-test proving it load-bearing. Each rule in `RULES` names the line above that it enforces, or one in `docs/specs/security-hosted.md` -> "Rendezvous boundary" or "Relay boundary" (rationale).
- **FAIL IF** the self-host Relay (`relay/`) begins admitting an `accountId` other than `SELFHOST_ACCOUNT_ID` (`remote-lib-common/src/remote/wire.ts`), or gains a self-serve signup path. The Hosted Relay's accounts are `docs/specs/security-hosted.md` -> "Relay boundary"; Reserved: the cloud boundary is analyzed in `## Future` -> Cloud-hosted mode before Hosted carries terminal traffic.

### Relay origin
Expand Down
Loading