Commit Graph
9 Commits
Author SHA1 Message Date
thakares 8d119ac00e Harden validation, improve runtime security and refactor core services
Rust / build (push) Canceled after 0s
2026-06-04 19:58:21 +05:30
thakares 3225509713 Begin post-v1.0.1 protocol and runtime improvements 2026-05-30 21:00:22 +05:30
thakares ecb1721ff4 Align crate versions with v1.0.1 release 2026-05-30 20:58:19 +05:30
thakares 0ed3cb444d Refactor attestation engine and synchronize project documentation
- Refine session and storage lifecycle handling
- Improve VM extension architecture across server, shared, and WASM runtimes
- Enhance synthetic gene mutation engine integration and parity guarantees
- Align deterministic state progression between server and browser execution paths
- Update configuration examples and deployment guidance
- Expand architecture, API, threat model, privacy, and WASM build documentation
- Refresh README with comprehensive project overview, operational workflows,
  browser integration details, storage backend documentation, and security model
- Document v0.6.0 refactoring outcomes and design rationale
- Improve consistency across documentation, configuration, and implementation

This commit consolidates the v0.6.0 architectural refactoring effort,
strengthening deterministic browser/server parity while improving
maintainability, operational clarity, and project documentation.
2026-05-29 21:55:08 +05:30
thakares 2b8afd54e0 docs: update README and docs for v0.6.0 architecture and deployment, preserve current server/shared/wasm updates 2026-05-29 21:27:11 +05:30
thakares ba768da58e feat: implement v0.6.0 mutation engine and db_type runtime selection
Rust / build (push) Canceled after 0s
2026-05-29 14:50:45 +05:30
thakares 9e78daeeba Refactor ChronoSeal daemon for dynamic configurations, connection pooling, custom error handling, and complete tests (v0.5.0)
Rust / build (push) Canceled after 0s
2026-05-22 18:56:28 +05:30
thakares b75d586b86 fix: correct 7 bugs found in security audit
Critical:
- crypto.rs (server): use BTreeMap for canonical JSON so key order
  matches JS client's JSON.stringify sort — sig verification was always
  failing silently
- heartbeat.js: capture sentSalt before rotating to next_salt so both
  sides compute next_chain_hash with the same salt — chain was broken
  after the first heartbeat

High:
- trust.rs: avg_speed = total_dist / total_time_ms (px/ms), not
  distance/event_count — legitimate users were always rejected
- ratelimit.rs: add evict_stale() to drain expired entries and prevent
  unbounded HashMap memory growth
- cleanup.rs: call rl.evict_stale() from the periodic cleanup loop

Medium:
- vm.rs: op 0x08 (NOT) is unary — split from binary-op arm so depth
  is not decremented incorrectly
- wasm/crypto.rs: replace unwrap() panics in sign_message /
  get_public_key with unwrap_or_default(); add JS-side guard

Low:
- shared/Cargo.toml, wasm/Cargo.toml: remove leftover add-this comments
- Dockerfile: rust:1.88-bookworm -> rust:1.87-bookworm (1.88 non-existent)
2026-05-08 14:27:41 +05:30
thakares a66debdece Initial ChronoSeal release 2026-05-07 21:57:47 +05:30