Skip to content

Security: Roblis0n/Sestina

SECURITY.md

Security policy

Supported public-preview version: 0.2.0. Security fixes are applied to the current public-preview line; older private candidates are not supported public distribution channels. / 当前支持的公开预览版本为 0.2.0;旧私有候选不属于受 支持的公开分发渠道。

Sestina is a local research-process debugger. Its security boundary is the local project, the project-owned .sestina/ state directory, explicitly generated project-scoped Codex configuration, and the two-tool/one-resource read-only MCP surface. External models, host responses, and Capsule responses cannot mutate research authority.

Reporting a vulnerability

Report vulnerabilities through the repository's private GitHub Security Advisory form. Do not put a vulnerability report in a public GitHub Issue.

Use a synthetic reproduction. Never attach unpublished research content, a real .sestina/ database, a Research Brief, a Provider response, a secret, token, API key, host credentials, project path, personal absolute path, device identifier, raw logs, stdout/stderr, or a private screenshot. A useful report includes the affected command, the expected boundary, the observed safe synthetic result, the supported operating system and Node version, and the smallest reproduction that demonstrates the problem.

请只使用合成复现;禁止提交研究内容、真实 .sestina 数据库、Research Brief、 Provider 响应、密钥/token/API key、项目或个人路径、设备标识、原始日志、 stdout/stderr 或隐私截图。

Published v0.2.0 preview security boundaries

  • The default Core, CLI, deterministic review, backup/restore, Capsule file operations, and stdio MCP do not require a network connection.
  • connection-status --verify-host --yes is an explicit exception: it starts a Codex host/model operation and may send the bounded categories declared by sestina privacy show to the user-selected Codex model provider.
  • Research Room Semantic Judge and second-opinion calls are explicit exceptions only after separate user configuration, an exact user-visible Context Manifest, and confirmation of that bound request. Saving config performs no probe; connection testing is metadata-only GET /models. No automatic discovery, fallback, retry, or background research request is allowed.
  • A RI-50 Deliberation Room freezes two exact participant requests before either result is accepted. Each request excludes the other participant's output, private Context, and session; user-only Resolution data is excluded from both. Both Manifests require explicit confirmation, tool/file/shell/search access is disabled, total calls are capped at four, and there is no automatic retry/fallback or third synthesis call.
  • The original Judge and second-opinion connection have separate config generations, secret references, and runtime identities. Same-runtime or unverifiable identity cannot be labelled independent. Provider raw responses, authentication headers, hidden reasoning, and full network payloads are not persisted.
  • A Provider assessment, comparison, signature, or agreement cannot resolve an appeal or mutate the original Finding. Only an expected-version direct-user command with a public reason can create the append-only Resolution.
  • Deliberation attempts use project/room/round/participant/request/hash binding, idempotent command receipts, expected-version CAS, and late-result fencing. Same-runtime, stale, cancelled, restart-uncertain, cross-project, malformed, duplicate, or oversized results fail closed. Difference is deterministic Core output, not a security or authority verdict; only a direct user command can append Room Resolution.
  • MCP exposes exactly health, get_research_context, and sestina://research/current-brief. All are read-only; research text is untrusted data and conveys no authority.
  • Restore accepts only a managed backup ID. It verifies containment, strict manifest shape, hashes, SQLite integrity, schema and project/Brief binding before committing.
  • SQLite database open failures are classified as unavailable, read-only, busy/locked, corrupt, or generic storage failure. Failed open/migration preserves existing files; corrupt authority state fails closed instead of being guessed or rebuilt.
  • Secret storage remains delegated to the existing DPAPI, Keychain, Secret Service, or explicit environment backend. Recovery bundles contain project research state, not host authentication stores.
  • Automatic telemetry, automatic crash upload, session replay, background content logging, and automatic upload are disabled. The package gate rejects known automatic telemetry/crash-upload SDKs and uninstall lifecycle scripts.

See PRIVACY.md, the local-first guarantee, the data-flow inventory, and backup and restore.

Internal schema-25 application boundary

The internal candidate connects the shared application service to typed HTTP and restricted Electron IPC. Public migration cutover has not occurred. Its Manifest stores a prepared request body inside the target database for exact recovery; this differs from the legacy payload-retention statements above. Secrets, authentication headers, raw Provider responses and hidden reasoning remain outside its structured record contract.

The target requires one canonical transaction owner, live user authorization, project/version binding, immutable proof records and read-only legacy tables. Staged migration validates the source, backup and target before a journaled switch. Incomplete operations fence ordinary writes; unknown replacements or WAL data are preserved and refused. These checks do not grant user authority or prove Provider semantics. Electron IPC and connect-time Provider security are implemented with targeted local verification; complete three-platform lifecycle, signature and release verification remain outstanding. See the implemented foundation and evidence.

Internal desktop boundary

The G10 candidate uses sandboxed, context-isolated renderer windows, a local resource allowlist, restrictive CSP and main-frame/window checks on each named IPC entry. Kernel remains the research authority boundary; main-owned confirmation is required for commits and external sends. Provider connections validate all DNS results and pin one fresh socket, with no redirects, proxy environment, connection reuse or retries. These mechanisms have targeted local tests; they do not establish completion of the three-platform attack/installation matrix. See candidate status.

Managed restore binds a single-use confirmation to the session, backup and current state, then revalidates under maintenance and writer locks. Interrupted pair swaps and cleanup fence normal opening until explicit verified recovery. Update metadata is checked against installed trust roots, target/channel/sequence and schema/source identity; bounded downloads and physical program copies are hashed again before installation. The renderer cannot provide trust roots, installer paths or credentials. No trusted update source is configured for this internal candidate. Earlier-settings migration rejects changed sources/targets and preserves existing data; encrypted credential read-back is required before configuration publication.

There aren't any published security advisories