docs(security): qualify GRASP-06 integrity warning

Motivation: The previous wording could imply that signed Nostr repository state or normal Nostr Git checkouts were themselves compromised.

Approach: Describe the concrete risk as unauthorized server-side objects or refs, while distinguishing conforming Nostr Git clients from direct Git consumers.

Correctness: The wording retains the full v3 integrity-pass requirement and does not weaken the separate unauthenticated-read disclosure.

Excluded scope: No runtime behavior, checker policy, or release procedure changes are included.

Validation: Reviewed both rendered Markdown sources and ran git diff --check.
This commit is contained in:
DanConwayDev
2026-08-20 19:22:23 +00:00
parent cbe48d9ce2
commit 47bfc2015d
2 changed files with 16 additions and 10 deletions
+8 -5
View File
@@ -82,11 +82,14 @@ Expect a bit of downtime as a git data migraiton is performed on startup. The la
repositories accessible to the service. With GRASP-06 enabled, crafted PR
submissions could also write Git objects and PR refs into another hosted
repository without its maintainer authorization. Any deployment that enabled
GRASP-06 on a tagged build through v2.1.2 must treat hosted-repository
integrity as potentially compromised until it completes the v3 checks.
Operators must upgrade to v3.0.0. By default, every v3 startup runs a
non-blocking authorization-integrity pass that compares every served branch,
tag, `HEAD`, and `refs/nostr/*` ref with the
GRASP-06 on a tagged build through v2.1.2 should treat its hosted Git
repositories as potentially containing unauthorized objects or refs until it
completes the v3 integrity checks. Conforming Nostr Git clients that resolve
refs from valid signed State, PR, and PR Update events are not expected to
accept this unauthorized data; direct Git consumers do not have that
protection. Operators must upgrade to v3.0.0. By default, every v3 startup
runs a non-blocking authorization-integrity pass that compares every served
branch, tag, `HEAD`, and `refs/nostr/*` ref with the
accepted State, PR, and PR Update events (including precisely scoped
in-flight events). Owner-view PR refs require either confirmed-maintainer
overlap with the target or an exact standard clone URL naming that owner and
+8 -5
View File
@@ -77,11 +77,14 @@ Remove the scope and observe a successful all-family pair of terminal summaries
before declaring the upgrade complete. The relay stays online during both
scoped and full passes.
Any service that enabled GRASP-06 on a tagged release through v2.1.2 must treat
its hosted repositories as potentially compromised until the full pass has
completed and every reported exception has been resolved. Passing a selected
scope is useful validation evidence, but it does not clear repositories that
were not named.
Any service that enabled GRASP-06 on a tagged release through v2.1.2 should
treat its hosted Git repositories as potentially containing unauthorized
objects or refs until the full v3 integrity pass has completed and every
reported exception has been resolved. Conforming Nostr Git clients that resolve
refs from valid signed State, PR, and PR Update events are not expected to
accept this unauthorized data; direct Git consumers do not have that
protection. Passing a selected scope is useful validation evidence, but it does
not clear repositories that were not named.
These passes are non-blocking: the relay is online while they inspect and heal
the migrated views. In the storage summary, an `unresolved` or `failed` count