docs(security): qualify GRASP-06 integrity warning

Motivation: The previous wording could imply that signed Nostr repository state or normal Nostr Git checkouts were themselves compromised.

Approach: Describe the concrete risk as unauthorized server-side objects or refs, while distinguishing conforming Nostr Git clients from direct Git consumers.

Correctness: The wording retains the full v3 integrity-pass requirement and does not weaken the separate unauthenticated-read disclosure.

Excluded scope: No runtime behavior, checker policy, or release procedure changes are included.

Validation: Reviewed both rendered Markdown sources and ran git diff --check.
This commit is contained in:
DanConwayDev
2026-08-20 19:22:23 +00:00
parent cbe48d9ce2
commit 47bfc2015d
2 changed files with 16 additions and 10 deletions
+8 -5
View File
@@ -82,11 +82,14 @@ Expect a bit of downtime as a git data migraiton is performed on startup. The la
repositories accessible to the service. With GRASP-06 enabled, crafted PR repositories accessible to the service. With GRASP-06 enabled, crafted PR
submissions could also write Git objects and PR refs into another hosted submissions could also write Git objects and PR refs into another hosted
repository without its maintainer authorization. Any deployment that enabled repository without its maintainer authorization. Any deployment that enabled
GRASP-06 on a tagged build through v2.1.2 must treat hosted-repository GRASP-06 on a tagged build through v2.1.2 should treat its hosted Git
integrity as potentially compromised until it completes the v3 checks. repositories as potentially containing unauthorized objects or refs until it
Operators must upgrade to v3.0.0. By default, every v3 startup runs a completes the v3 integrity checks. Conforming Nostr Git clients that resolve
non-blocking authorization-integrity pass that compares every served branch, refs from valid signed State, PR, and PR Update events are not expected to
tag, `HEAD`, and `refs/nostr/*` ref with the accept this unauthorized data; direct Git consumers do not have that
protection. Operators must upgrade to v3.0.0. By default, every v3 startup
runs a non-blocking authorization-integrity pass that compares every served
branch, tag, `HEAD`, and `refs/nostr/*` ref with the
accepted State, PR, and PR Update events (including precisely scoped accepted State, PR, and PR Update events (including precisely scoped
in-flight events). Owner-view PR refs require either confirmed-maintainer in-flight events). Owner-view PR refs require either confirmed-maintainer
overlap with the target or an exact standard clone URL naming that owner and overlap with the target or an exact standard clone URL naming that owner and
+8 -5
View File
@@ -77,11 +77,14 @@ Remove the scope and observe a successful all-family pair of terminal summaries
before declaring the upgrade complete. The relay stays online during both before declaring the upgrade complete. The relay stays online during both
scoped and full passes. scoped and full passes.
Any service that enabled GRASP-06 on a tagged release through v2.1.2 must treat Any service that enabled GRASP-06 on a tagged release through v2.1.2 should
its hosted repositories as potentially compromised until the full pass has treat its hosted Git repositories as potentially containing unauthorized
completed and every reported exception has been resolved. Passing a selected objects or refs until the full v3 integrity pass has completed and every
scope is useful validation evidence, but it does not clear repositories that reported exception has been resolved. Conforming Nostr Git clients that resolve
were not named. refs from valid signed State, PR, and PR Update events are not expected to
accept this unauthorized data; direct Git consumers do not have that
protection. Passing a selected scope is useful validation evidence, but it does
not clear repositories that were not named.
These passes are non-blocking: the relay is online while they inspect and heal These passes are non-blocking: the relay is online while they inspect and heal
the migrated views. In the storage summary, an `unresolved` or `failed` count the migrated views. In the storage summary, an `unresolved` or `failed` count