docs: comprehensive ARCHITECTURE, DEPLOYMENT, API, and THREAT_MODEL

ARCHITECTURE.md
- Full component map with ASCII diagram
- Complete session lifecycle (init + heartbeat + failure path)
- Cryptographic protocol spec (hash chain formula, canonical JSON)
- Stack machine instruction set table with stack effects
- Behavioral validation thresholds
- SQLite schema, threat model summary, module reference

DEPLOYMENT.md
- Build instructions (WASM + server + convenience script)
- native binary, systemd (with hardened sandbox notes), Docker
- nginx, Nginx Proxy Manager, and HAProxy reverse proxy configs
- Integration options (sidecar vs proxy-only)
- Full configuration table with all constants
- Observability (RUST_LOG levels), health check, security checklist

API.md
- Full /init and /hb request/response schemas with field tables
- Canonical signing payload specification
- Complete validation rules table (all 13 rejection conditions)
- Hash chain byte-level specification
- WASM exported function reference

THREAT_MODEL.md
- Four attacker profiles (script kiddie → sophisticated adversary)
- Eight attack vectors with mitigations (replay, forgery, hijack, DoS…)
- Explicit out-of-scope limitations
- Operational security notes (CORS, TLS, log level, SQLite)
This commit is contained in:
thakares committed 2026-05-09 18:11:15 +05:30
1 parent 4b27a342d1
commit 2840ddfc58
1 file changed
+2 -2
+2 -2
View File
@@ -62,7 +62,7 @@ synchronisation burden alone makes scaled operation expensive.
│ │ ├ sign_message() │ │ │ │ ├ sign_message() │ │
│ │ ├ compute_next_hash() │ │ │ │ ├ compute_next_hash() │ │
│ │ └ run_program() │ │ │ │ └ run_program() │ │
│ └───────────────────────────────┘ │ │ └──────────────────────────────┘ │
└─────────────────────────────────────────────────────────┘ └─────────────────────────────────────────────────────────┘
│ HTTPS │ HTTPS
┌─────────────────────────▼───────────────────────────────┐ ┌─────────────────────────▼───────────────────────────────┐
@@ -138,7 +138,7 @@ Client Server
│ sig = sign_message( │ │ sig = sign_message( │
│ JSON.stringify(signable, keys.sort))│ │ JSON.stringify(signable, keys.sort))│
│ │ │ │
├─── { session_id, prev_hash, timestamp,│ ├─── { session_id, prev_hash, timestamp, │
│ entropy_data, stack_state, │ │ entropy_data, stack_state, │
│ fingerprint, signature } ────────►│ │ fingerprint, signature } ────────►│
│ │ 1. Rate limit check │ │ 1. Rate limit check