Skip to content

[DM-073] Perform adversarial security, revocation, and recovery review #43

Description

@nicoechaniz

Outcome

Perform an independent, adversarial, release-candidate-bound security and recovery review of the complete Daimon Matrix V0 implementation and private canary evidence. Reproduce the declared tests from a clean environment, add independent attack probes, restore canonical and encrypted state through separate drills, audit migration/rollback/adapter disablement, publish all findings and residual risks, obtain exact-head approval after fixes, and require an explicit human go/no-go decision before release.

This card is a gate, not a ceremonial checklist. Green CI, author self-report, prior component reviews, or a plausible threat model do not prove release readiness.

Blocked by

  • DM-055 Tribe runtime cutover is complete and its final provenance/no-history report plus pre-archive handoff plan are available; final source tagging/archive remains sequenced after release and is not a pre-release blocker.
  • DM-061 compatible species update and branching implementation is complete.
  • DM-071 consented external relationship/source canary is complete with participant-approved redacted evidence.
  • DM-072 reversible private CompAII canary is complete with human-approved redacted evidence.
  • DM-074 harness-adoption guide and synthetic fixtures are merged, so the audit reviews them rather than approving an older candidate.
  • DM-076 release-candidate preparation is merged and has frozen all release notes, manifests, build inputs, documentation and proposed artifact bytes on the exact default-branch candidate; publication remains gated by this review.
  • Every other V0 implementation/test/ops issue except the later publication and source-archive cards is closed or has a release-blocking disposition that does not defer required V0 behavior.

Keep status:blocked until all gates close. The candidate commit, package bytes, deployment/config template digests, dependency lock, and evidence set must then freeze for review; any code/schema/dependency/build/config change invalidates the approval and requires scoped re-review.

Independence and review protocol

  • Reviewer must not be the author of the candidate changes and must work read-only in a clean clone/worktree/environment from the exact candidate commit. Separate operator accounts are preferred; when GitHub identity is shared, the report must name the independent reviewer principal and explicit textual APPROVE/REQUEST_CHANGES verdict bound to the exact SHA.
  • Review the complete cumulative diff from the last independently approved release/baseline, not only the final fix commit. Read normative specs, issues/acceptance criteria, source, schemas, migrations, tests/vectors, CI/build/deployment/runbooks, and author review records—the latter last as self-report.
  • Reproduce commands and expected counts independently. Inspect what each test actually covers; a passing count, tautology, mocked shortcut, skipped capability, or synthetic-only assertion cannot support a broader claim.
  • Create independent adversarial probes and retain reproducible redacted scripts/fixtures/results. Do not use production secrets/private state or mutate live services.
  • Every finding has stable ID, severity, affected invariant/artifact/path, evidence/reproducer, exploit/failure impact, required fix or accepted rationale, owner, status, and exact resolving commit/re-review.
  • critical, high, or release-boundary medium findings block. A nonblocking residual risk requires explicit rationale, bounded exposure, mitigation/monitor, future issue and human acceptance; severity cannot be lowered merely to ship.
  • Fixes land under new signed claims/PRs and full relevant CI. The original reviewer verifies the exact new head and states whether each finding is closed; an approval of an older SHA never transfers.

Candidate and evidence manifest

Produce a closed content-addressed v0-security-review-manifest/v0 containing only public/redacted evidence:

  • exact repository, candidate SHA/tree, intended version/tag, source archive/wheel/sdist/container/config-template/schema/migration/vector/doc digests;
  • Python/runtime/platform/dependency lock, SBOM/license/provenance, pinned CI actions/builders and reproducible-build environment;
  • list and immutable digest of every V0 issue, PR/claim/review, conformance corpus, required scenario registry, test command/report, canary/cutover/recovery report and residual-risk register;
  • public deployment topology/authority-role model and digests of private effective configurations—never paths, endpoints, keys, tokens, memory or member rosters;
  • expected release interfaces, artifact/file allowlists, secret/private-state scan policy, restore inputs and stop/rollback procedures;
  • reviewer identity, clean-environment attestations, review start/end head and final verdict.

Manifest mismatch, missing evidence, dirty tree, mutable dependency/action/tag, unreviewed generated artifact, or candidate head movement fails preflight.

Threat model and attacker roles

Test at least these independent/combined actors:

  • remote unauthenticated sender, malicious authorized peer, revoked former peer/descendant, compromised operational/body/service/adapter/controller key, stale/partitioned observer, malicious hub/gateway/locator/provider/model/worker/reviewer input;
  • local unprivileged user/process, hostile plugin/hook/harness/profile, compromised body/container/Cluster controller, restored stale volume/database/snapshot, competing daemon/writer, crash/disk-full/corruption adversary;
  • malicious species maintainer/bundle, source publisher, Tribe resource controller/delegator, /we governance signer, birth parent/bootstrap/witness, and dependency/build/release contributor;
  • operator error: wrong profile/repository/path/key/config/version, leaked secret, partial migration/cutover, unsafe rollback, disabled adapter, missing backup, clock rollback/skew, and accidental live-state fixture.

For every trust boundary identify assets, authority it may and may not exercise, entry points, persistent state, replay/fork/high-water keys, confidentiality/classification, resource bounds, failure mode, recovery authority, and observable evidence.

Identity, custody, and presence review

  • Independently recompute me_id, content/key/certificate/genesis/control/revocation/acceptance IDs/hashes/signatures/domains/thresholds and strict JSON/JCS for fresh and checked-in vectors.
  • Attack forged genesis/control/root rotation/recovery, missing old/new possession, threshold/key aliasing, cross-role/domain/key reuse, wrong control anchor, stale/root-replaced issuer, missing subject acceptance, certificate purpose/prefix/expiry, revocation cutoff, replay and content conflict.
  • Verify root/recovery private keys remain offline/role-separated and never appear in body/adapter/Cluster/harness/provider/backup/log/build/process state. Keystore permissions/symlink/hardlink/path/TOCTOU, passphrase/KDF, atomic write/fsync, backup/restore and generic-signing absence are probed.
  • Exercise identity-wide lease sequence/predecessor/external receipt, expiry/clock rollback, event cutoff, competing active bodies, stale restore/reacquire, witness compromise, route union, and split-brain quarantine. No name/host/harness/Tribe/state snapshot can upgrade unverifiable identity/presence.
  • Prove distinct Codex/Hermes me_id values/roots in one /we and one active body maximum per identity. Shared inputs remain attributed, not shared autobiography.

Canonical artifacts, ledger, persistence, and cursors

  • Fuzz strict I-JSON/JCS, duplicate keys, Unicode/number/base64 forms, unknown fields, depth/size/count limits, typed-ID substitution, signature/domain/key-role confusion, causal parent/HLC/event stream gaps/forks, checkpoints and external receipts.
  • Race the authenticated single-writer daemon with multiple processes/clients, request/idempotency conflicts, commit-before-response, crash/disk full/WAL/corruption/fsync failures, clock skew, transaction interruption and stale connections. Direct database writes/handles are not public protocol.
  • Verify canonical events/CAS are authority; projections/indexes/HMK/Wiki/queues/caches are rebuildable and cannot originate/correct/retract state. Forks quarantine; timestamps/arrival/order/hash never pick winners.
  • Cursor tests cover store generation, monotonic sequence, rollback/restore/GC, same-millisecond events, backlog/page >100, snapshot/page binding, tamper/cross-consumer use, contiguous terminal prefix, skipped retryable row, restart and compaction.
  • Disable each adapter/provider one at a time and all optional adapters together. Canonical state, high-waters, receipts and audit history remain readable/rebuildable; provider-owned projections may disappear but cannot delete or reinterpret ledger/CAS state. Re-enable/replacement rebuilds from immutable refs without duplicate effects.

Cryptography, messages, routes, and privacy

  • Independently implement/check RFC/JCS cryptographic preimages and every DM-011 key/ID/signature/HPKE/AEAD size/domain; probe all-zero/low-order/malformed keys, nonce/CEK reuse, wrong AAD/info/protected metadata, recipient/key/sender/disclosure substitution, ciphertext/tag/signature tampering and oracle behavior.
  • Same logical message/thread IDs survive fan-out/retry/reseal; delivery ID replay conflicts are separate from per-recipient semantic dedup. Direct/hub duplicates and ambiguous timeout ingest/effect once.
  • Forge/expand/swap /we, relationship, direct-reply and sealed recipient sets; test wrong route/body/key/cert/adapter, ACK-versus-intake confusion, terminal receipt conflict, expiry/transport classification, outbox after envelope expiry and crash recovery.
  • Route fallback happens only after typed unavailability, never authenticated crypto/policy/protocol rejection. Hub cannot decrypt/rewrap/expand or claim delivery. @localhost rejects remote/mixed audiences before any remote effect/key wrap.
  • Probe unauthorized .status/resolution/inbox/cursor/directory/route/grant/revocation errors and timing as membership/backlog/capability oracles. /everyone remains explicitly bounded/public/disabled by default.
  • Gateway/mirror escaping, length/chunking, allowlists, provenance, inbound attribution, token/log redaction and disabled-by-default state receive independent tests.

Membership, delegation, source, memory, birth, and species

  • /we: threshold/root acceptance, governance rotation possession, removal/replay, ambiguous alias pin, pending transition, unrepresentable policy, late sibling/fork, active-presence intersection, frozen resolution and no collective key/voice.
  • DM-016: forged cards/handshakes/grants/acceptances, subject/controller/relationship/resource/operation/classification mismatch, delegation attenuation/depth/birth limits, predecessor gaps/forks, expiry/closure/revocation/relinquishment, stale cache/partition, descendant resurrection and disclosure/roster oracles.
  • DM-015: claim signature versus truth/admission, selector binding, assessment observer, publication/provenance/consent/license, fork/retraction/cursor/pull-to-quarantine, source-to-personal-memory promotion, SSRF/ambient fetch, cache/HMK authority.
  • DM-017/030–036: category/author/context/derivation/lane predecessor, correction/retraction/fork, personal versus peer/source/tribal/species/incarnation boundary, policy determinism/stale plan, worker/model/reviewer/Librarian authority, projection overlap and final rendered artifact/secret scan.
  • DM-013: offer/newborn/key precommitment, awakening capability/domain/one-use, genesis/species/context equality, root acceptance/time-witness chain, double acceptance, first-awakening order/lease receipt, no parent key/memory/membership, fresh newborn grants/birth limits and Agent 0 disclaimer.
  • DM-014/061: maintainer authorization/all-key possession/floor/rotation, release high-water/forks/closure, predecessor-selected deterministic suites, WASI sandbox escape/resource/nondeterminism, incoming preview purity/paging/stale cursor, application journal crash/fork rollback, branch delta/two-authority child and no incompatible V0 adoption.

Adapters, harnesses, Librarian, and Matrix↔Cluster

  • DM-018 manifests negotiate exact versions, retain accepted-version high-water, fail unknown/downgrade, enforce all false authority flags, content refs/idempotency, secret/path/DB exclusion, migration/export/apply/verify/commit/rollback monotonicity and no adapter-selected canonical authority.
  • Codex/Hermes effective config, isolated homes/profiles/sessions, prompt/role-prefix stability, native-memory policy, plugin/hook/tool/MCP allowlist and host-default fallback are reviewed. Kill/restart at every harness/daemon boundary and inspect open files/process/env/log/archive leakage.
  • Librarian/service lease exclusivity, key purpose, deterministic queue/work IDs, classification/consent/evidence revalidation, DeepSeek worker isolation, proposal/review/append separation, late result, migration and split-brain receive race/fault probes.
  • Matrix↔Cluster controller authentication/delegation, genuine CAS, permanent monotonic fence, Matrix presence/fence dual admission, park/wake saga, failed wake successor, restored volume/HMK/profile/controller state, FakeSigner/placeholder rejection and no one-gate ACK/effect are independently exercised.
  • Binder/activation/migration TOCTOU: mutate manifest/content/policy/key/head/config between plan/verify/apply/exec/receipt; every effect revalidates exact bytes/high-waters immediately before commit and binds them atomically in its receipt.

Separate recovery drills

A. Ledger/CAS reconstruction

  1. Build a synthetic but complete accepted V0 state through installed daemon interfaces: identities, /we, events/checkpoints, memory lanes, relationships/grants/revocation, source/species/application, messages/receipts/cursors and adapter evidence.
  2. Stop services; preserve only canonical ledger/event/CAS bytes plus required public proofs and separately authorized keys. Remove/move every projection, index, cache, HMK/Wiki DB, route queue, adapter DB, runtime pointer and generated state from the isolated test root.
  3. Install the exact candidate wheel cleanly and rebuild all projections through public recovery APIs. Compare canonical heads/hashes, effective state, exclusions, cursors and rendered approved public outcomes—not implementation DB bytes.
  4. Corrupt/omit/reorder/fork canonical inputs and prove incomplete/quarantine/refusal without invented state or destructive repair. Repeat rebuild and compare deterministic digests.

B. Encrypted backup restoration

  1. Independently create the supported encrypted backup from the same cutoff, binding format/version/KDF/AEAD/content manifest/checkpoint/high-waters and excluding ephemeral caches/secrets not intended for backup.
  2. Restore into a fresh isolated owner-only target with no pre-existing state, using the documented key/recovery ceremony. Verify ciphertext tamper, wrong key/passphrase, truncation, rollback/stale backup, path/symlink/archive traversal, permission, partial write, disk-full and interrupted restore failures.
  3. Revalidate every restored canonical byte/key role/head against current durable anti-rollback evidence before activation. A backup cannot resurrect revoked keys, removed members, stale leases/fences/grants, retracted memory or old runtime pointers.
  4. Rebuild projections and compare to Drill A. Exercise disablement/restart and a new successor event after restore. Preserve a redacted proof of recovery; destroy only exact temporary test roots.

The drills prove different properties. A ledger rebuild is not proof that backup encryption/restore works, and a byte-restored DB is not proof of canonical reconstruction or current authority.

Migration, v0 containment, supply chain, and release artifacts

  • Verify Tribe v0 parser/listener/service/key/history/dual-write/downgrade remains absent and cannot be re-enabled by rollback/config/import. Matrix starts empty and rejects Tribe v0/v1 history/private-state import; DM-050 source provenance is not runtime/state migration.
  • Reproduce DM-018 storage/provider migrations and every rollback as forward successor state; no deleted receipt, regressed high-water, category/identity collapse or restored DB authority.
  • Confirm the DM-055 Tribe cutover report, proposed source-archive target/notice handoff and zero runtime dependency; current Matrix/CompAII review works without Tribe. Final source tagging/archive is sequenced after release and is not evidence for candidate safety.
  • Generate clean sdist/wheel/source archives twice in independent environments; compare allowed deterministic contents/hashes. Inspect generated metadata, schemas/vectors/docs/licenses/SBOM/provenance and entry points.
  • Audit dependency constraints, hashes/signatures/provenance/licenses, typosquatting/confusion, optional extras, build backend, CI action pinning/permissions, release token isolation, untrusted PR behavior, artifact attestations and download verification.
  • Scan Git history/current tree, archives, wheels, containers, fixtures, test reports, caches, logs, crash artifacts and canary/security evidence for secrets, private keys, credentials, endpoints, personal memory/prompts/reasoning, database/state snapshots and unsafe paths. A source-only scan is insufficient.

Findings, residual risk, and release decision

Publish SECURITY-REVIEW-V0.md (or equivalent reviewed report) plus machine-readable findings manifest. It includes scope/head, methodology, reproduced commands/counts, independent probes, coverage matrix, findings/evidence/fixes/reviews, recovery results, artifact digests, limitations and residual risks. Redact private canary/external participant data while retaining independently checkable public evidence.

Final states:

  • REQUEST_CHANGES: any blocking finding, missing evidence, unreproduced required test, unresolved consent/privacy issue, weak recovery proof, mutable candidate, or unacceptable residual risk.
  • APPROVE: exact candidate head/artifacts/config-template/evidence were reviewed; all blockers closed; every nonblocker recorded; reviewer explicitly recommends release subject to human approval.

After exact-head APPROVE, the human release owner reviews the full report/residual-risk register and records an explicit GO or NO-GO tied to the same manifest/candidate. Silence, issue closure, merge permission, or author intent is not approval. A GO authorizes only DM-075 publication/tagging of the already reviewed commit and bytes. Any candidate-affecting code, schema, dependency, build, configuration, fixture, documentation, release-metadata or artifact change reopens review.

Acceptance criteria

  • An independent reviewer binds scope and verdict to the exact immutable release-candidate SHA/artifacts/evidence and reproduces the full declared suite in a clean environment.
  • Independent attacks cover forged identity, replay, recipient confusion, roster/oracle disclosure, revoked descendants, split brain, key/domain/authority substitution, cursor/high-water rollback, adapter/provider compromise, TOCTOU, crash/corruption and resource abuse.
  • Ledger/CAS-only reconstruction and encrypted-backup restore are run separately, adversarially mutated, compared, repeated and proven not to restore stale authority.
  • Disabling every adapter/provider leaves canonical retained state/history intact and rebuildable; replacement/re-enable cannot duplicate or reinterpret it.
  • Matrix↔Cluster, Codex/Hermes, Librarian/DeepSeek, external relationship/source, Tribe cutover/archive-handoff, birth/species and canary privacy evidence withstand exact-boundary review.
  • Source and final generated artifacts pass reproducible-build, provenance/SBOM/license/dependency/CI and full secret/private-state scans.
  • Every finding is resolved on an exact re-reviewed head or explicitly retained as a bounded nonblocking residual risk with owner/mitigation/follow-up.
  • Reviewer issues exact-head APPROVE, then the human owner records explicit same-candidate release GO; otherwise release remains blocked.

Non-goals

  • No live production penetration test, unsolicited external probing, disclosure of secrets/private canary data, destructive production recovery, or vulnerability publication before coordinated remediation.
  • No production code fix hidden inside the review claim; fixes use focused claims/PRs and exact-head re-review.
  • No claim of formal verification, perfect confidentiality, sentience, global freshness, forward secrecy/PCS/MLS, or elimination of every operational risk beyond the documented V0 threat model.

Safety and rollback

All destructive/fault/recovery tests target validated synthetic temporary roots or separately approved isolated backups. Never signal processes by broad name, scan external systems, alter participant infrastructure, or delete live state. Review failure leaves the candidate unreleased and canary disabled/parked through its documented successor procedure; it never regresses high-waters or enables Tribe v0.

Canonical references

Concurrent-work gate

Do not claim until every blocker is complete and the candidate/evidence manifest is frozen. The signed review claim may add only review harnesses/fixtures/reports; any implementation change requires a separate claim and resets exact-head approval.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:federationRemote routing, source, or species exchangearea:identityIdentity, incarnation, birth, or keysarea:ledgerEvent ledger, projections, or cursorsarea:memoryPersonal memory and knowledge boundariesneeds-humanRequires an explicit human decision or actionpriority:P0Critical pathrisk:securitySecurity-sensitive changestatus:blockedBlocked by dependencies or reviewtype:testTest, validation, or audit work

    Type

    No type

    Projects

    No projects

      Milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions