diff --git a/CHANGELOG.md b/CHANGELOG.md index 27cf8a5..f92d4d6 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -82,11 +82,14 @@ Expect a bit of downtime as a git data migraiton is performed on startup. The la repositories accessible to the service. With GRASP-06 enabled, crafted PR submissions could also write Git objects and PR refs into another hosted repository without its maintainer authorization. Any deployment that enabled - GRASP-06 on a tagged build through v2.1.2 must treat hosted-repository - integrity as potentially compromised until it completes the v3 checks. - Operators must upgrade to v3.0.0. By default, every v3 startup runs a - non-blocking authorization-integrity pass that compares every served branch, - tag, `HEAD`, and `refs/nostr/*` ref with the + GRASP-06 on a tagged build through v2.1.2 should treat its hosted Git + repositories as potentially containing unauthorized objects or refs until it + completes the v3 integrity checks. Conforming Nostr Git clients that resolve + refs from valid signed State, PR, and PR Update events are not expected to + accept this unauthorized data; direct Git consumers do not have that + protection. Operators must upgrade to v3.0.0. By default, every v3 startup + runs a non-blocking authorization-integrity pass that compares every served + branch, tag, `HEAD`, and `refs/nostr/*` ref with the accepted State, PR, and PR Update events (including precisely scoped in-flight events). Owner-view PR refs require either confirmed-maintainer overlap with the target or an exact standard clone URL naming that owner and diff --git a/docs/how-to/upgrade-git-family-storage.md b/docs/how-to/upgrade-git-family-storage.md index 00bb5ef..15ac253 100644 --- a/docs/how-to/upgrade-git-family-storage.md +++ b/docs/how-to/upgrade-git-family-storage.md @@ -77,11 +77,14 @@ Remove the scope and observe a successful all-family pair of terminal summaries before declaring the upgrade complete. The relay stays online during both scoped and full passes. -Any service that enabled GRASP-06 on a tagged release through v2.1.2 must treat -its hosted repositories as potentially compromised until the full pass has -completed and every reported exception has been resolved. Passing a selected -scope is useful validation evidence, but it does not clear repositories that -were not named. +Any service that enabled GRASP-06 on a tagged release through v2.1.2 should +treat its hosted Git repositories as potentially containing unauthorized +objects or refs until the full v3 integrity pass has completed and every +reported exception has been resolved. Conforming Nostr Git clients that resolve +refs from valid signed State, PR, and PR Update events are not expected to +accept this unauthorized data; direct Git consumers do not have that +protection. Passing a selected scope is useful validation evidence, but it does +not clear repositories that were not named. These passes are non-blocking: the relay is online while they inspect and heal the migrated views. In the storage summary, an `unresolved` or `failed` count