Security Review for v1¶
Date: 2026-10-02 · Release: v0.62.0 · Scope: the v1 deployment profile below, its Network Authority, CLI, signed artifacts and official SDKs.
This review was carried out by the maintainers against the code, with automated checks added wherever a claim could be enforced. It is not an independent audit or penetration test. One is recommended before production use beyond a pilot.
The v1 deployment profile¶
Element |
Profile |
|---|---|
Network Authority |
The Python NA under gunicorn, behind exactly the number of TLS-terminating reverse proxies set in |
Storage |
One instance on SQLite, or one or more instances on PostgreSQL ( |
NA signing key |
Azure Key Vault (managed identity) or a platform-injected environment seed; a key file only for a single SQLite instance |
Operator keys |
Generated and held by the operator; privileged keys for trust changes, standard keys for routine calls |
Governed workloads |
|
Clients |
The TypeScript, Go and .NET SDKs, or raw HTTP with the documented admin signature |
Out of profile |
Mesh routing and Noise transport ( |
Findings¶
ID |
Area |
Severity |
Finding |
Status |
|---|---|---|---|---|
SR-01 |
Packaging |
High |
The wheels on PyPI never contained the migration SQL files. A Network Authority installed with |
Fixed in v0.62.0: |
SR-02 |
Authorization |
High |
A standard-tier operator key could accept an agreement (granting capabilities that boundary decisions then authorize) and make the NA sign a data license policy (granting a licensee access to data). Both are trust changes, which the tier model reserves for privileged keys. |
Fixed: both routes require the privileged tier ( |
SR-03 |
Availability |
Medium |
No request body limit. The public verify routes are unauthenticated, so an arbitrarily large JSON body could exhaust a worker’s memory. |
Fixed: bodies over |
SR-04 |
Rate limiting |
Medium |
The NA always trusted one |
Fixed: |
SR-05 |
Recovery |
Medium |
A release started on a database migrated by a newer release ran on the unknown schema; only |
Fixed: start-up refuses with |
SR-06 |
Key handling |
High |
There is no procedure to rotate the NA signing key while keeping the sovereign’s identity (RFC-001 open question). A compromised NA key means a new identity, with counterparts re-issuing treaties. |
Accepted residual risk for v1. Mitigations: Key Vault custody with managed identity; HA mode refuses key files; operator keys, not the NA key, authenticate admin calls; documented in Operator Exit and Fork and the incident response runbook. |
SR-07 |
Revocation freshness |
Medium |
Imported sovereign revocation feeds have no enforced maximum age. A sovereign keeps accepting a partner’s attestation until it imports the feed that revokes it, so the stale window is the import interval. Within one NA, revocation is immediate. |
Accepted residual risk: replay of older feeds is refused ( |
SR-08 |
Trust bundles |
Low |
Trust bundles are unsigned, so they prove nothing about who assembled them (RFC-003). |
Accepted: bundles are review hints only and never imported into trust state; keys come from the subject’s endpoint or out of band. |
SR-09 |
Revocation import |
Low |
The feed import route accepts issuer keys supplied by the operator, falling back to the treaty’s subject keys. |
Accepted: an operator trust decision behind a privileged key; RFC-004 now says so explicitly. |
SR-10 |
Availability |
Low |
|
Accepted for the profile (mesh nodes are out of it); put the NA behind a proxy or WAF with connection limits. |
SR-11 |
Dependencies |
Info |
The gateway depends on |
Accepted: the gateway is beta and outside the v1 contract. |
Areas reviewed¶
Threat model¶
SECURITY.md was checked against the profile. Its in-scope defenses hold and
are tested. It was updated where the code had moved on: proxy trust is now
configurable (SR-04); /join is rate limited; and the out-of-scope entry for
NA key compromise no longer suggests a rotation procedure that does not
exist (SR-06).
Dependency reports¶
Package |
Tool |
Result |
|---|---|---|
genesis-mesh |
|
No known vulnerabilities |
genesis-mesh-sdk (npm) |
|
0 vulnerabilities; no runtime dependencies |
sdk-go |
|
No vulnerabilities |
genesismesh-sdk-dotnet |
|
No vulnerable packages |
sdk-rust |
|
No advisories |
gateway |
|
One informational advisory (SR-11) |
Key handling¶
NA keys come from one
Signerwith providersfile,envandazure-keyvault; Key Vault seeds stay in memory. HA mode refusesfile.Key files are written owner-only (
0o600) where the filesystem allows it.Operator keys authenticate admin calls; the NA key is never used for that. Operator keys have tiers, and a key revoked at runtime is refused before its signature is checked and before its nonce is consumed.
Errors and logs go through
redacted_exception_text; private keys and seeds are never logged or returned.test_operator_independence.pykeeps key literals and built-in authorities out of runtime code.
Revocation freshness¶
Within a Network Authority, revoking an attestation, treaty or operator key takes effect on the next request (the upgrade rehearsal checks that a revoked attestation is denied). Across sovereigns it depends on feed import (SR-07). Node certificate revocation goes through the signed, monotonic CRL.
Replay protection¶
Admin requests: an Ed25519 signature over
{body, key_id, timestamp, nonce}, a ±300 second timestamp window, and an atomic nonce claim in the database, so a nonce cannot be used twice on any instance.Boundary decisions expire (
decision_valid_until); invocation tokens keep use records; revocation feeds must increase their sequence; evidence submission is idempotent (an identical resubmission is aduplicate).
Recovery¶
Backup and restore: online SQLite backups and
pg_dump; restored databases are verified byna verify-db. The upgrade rehearsal restores a backup and re-verifies every record on each CI run.Failover: two-instance failover under load is tested in CI (v0.60).
Rollback: forward-only migrations, refusal of newer schemas, restore procedure (SR-05).
NA key compromise: new identity (SR-06).
RFC-001 to RFC-004¶
The security considerations of the four normative RFCs were checked against the implementation; see RFC Decision Log. RFC-004 now states that feed issuer keys may be supplied by the importing operator (SR-09); its freshness question stays open (SR-07). No finding blocks acceptance; the acceptance itself is the maintainer’s decision.