Skip to content

[Audit] v5.1.1 audit remediation #458

Description

@LeadcodeDev

Epic for the 2026-08 security + quality audit of packages/core (mineral v5.1.1).

The audit ran 11 parallel review dimensions over the 516 files of packages/core; every
finding below survived an adversarial refutation pass. Findings are numbered A1-A29
to avoid collision with the H*/M* codes used by the previous audit (#424-#428).

Why this chantier exists

The security posture came out good: the bot token is never logged, IDENTIFY/RESUME
payloads stay out of the logger, inbound gateway traces go through redactSensitiveFields,
HTTPS is enforced at HttpClient construction, CI uses OIDC with SHA-pinned actions, and
all 21 Intent bits plus every Permission position were verified against the Discord spec.

The problem is elsewhere: several public paths are broken 100% of the time in the
published release.

  • message.delete(), message.pin() and every reaction throw a raw TypeError (any 204).
  • guild.roles.get/create/update and guild.emojis.fetch/get throw type 'Null' is not a subtype of type 'String'.
  • Guild.assets.icon, .banner, .splash, settings.permissions, .afkTimeout and
    .vanityUrlCode are silently always null.
  • Every voice-state deserialization throws.
  • Every GIF or LOTTIE sticker throws a StateError.

Root cause (A0)

All five share one cause: the rawDiscordPayload() fixtures were written to match what the
serializer expects, not the real Discord wire shape. The suite validates the code against
itself
— it is green, the analyzer is clean, and the framework does not work.

That is why #459 lands first: it rebuilds the fixtures from real payloads and adds a
round-trip assertion per serializer, turning the suite red so the wave-1 cards turn it green.
Fixing the five call sites without fixing the fixtures brings the whole class straight back.

Branch topology

  • Workstream branch chantier/audit-2026-08, cut from main.
  • One feature branch per card, cut from the chantier branch (never from main).
  • Feature branch -> chantier branch: squash.
  • Chantier branch -> main: a single squash PR, merged by the maintainer.

Sequencing

Wave 0 lands first. Waves 1-5 are otherwise parallel, except for these file collisions:

Cards

Wave 0 — test contract (blocks wave 1)

Wave 1 — payload contracts (the shipped-broken paths)

Wave 2 — HTTP layer

Wave 3 — gateway resilience

Wave 4 — consumer-facing correctness

Wave 5 — security & release

Wave 6 — architecture & debt

Follow-up

Audit scope caveats

The verification pass was budget-capped: one refutation lens instead of two, on a smaller
model, applied to Critical/High/Medium only. 0 of 33 findings were refuted — an
abnormal rate. The evidence supports the findings (several were reproduced in standalone
Dart scripts, and env_guard/eterl sources were read in .pub-cache), but treat the
Low cards as probable rather than confirmed until the regression test is red.

Not covered by this audit: the api/ entity layer has one test file for 202 source files;
packages/cache and packages/test were out of scope.


Status — 18 of 23 cards done

The chantier branch was rebased onto main and shipped (#489). main now carries
the payload-contract, HTTP, gateway-resilience, handler-isolation, security and
CI work; all three packages are green on format, analyze and test.

Still open, and none of it fixes a user-visible bug:

Loose ends found during the work and not yet carded: see the follow-up issue
linked below.

Activity

  1. changed the title [-][Audit] Chantier 6 — v5.1.1 audit remediation (A1–A29)[/-] [+][Audit] v5.1.1 audit remediation[/+] on Aug 2, 2026
  2. LeadcodeDev commented on Aug 3, 2026

    @LeadcodeDev
    MemberAuthor

    Loose ends are now carded in #490.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    tech-debtTechnical debt / refactor

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions