Security¶
Gossamer's implementation forbids unsafe Rust workspace-wide
and audits every external dependency against a small approved
list. This page summarises the posture for users and points at
the hardening roadmap. Reporting details are in
SECURITY.md.
What is done¶
- The compiler front-end forbids
unsafe. The parser, resolver, type checker, MIR, LLVM codegen, lints, diagnostics, LSP, and scheduler crates all carry#![forbid(unsafe_code)]. The runtime, the Cranelift JIT, the stackful-coroutine layer, and the FFI binding surface contain contained, reviewedunsafe- unavoidable for C ABIs, executing generated machine code, and context switching - kept in the smallest possible scope. - No manual memory management in the language: there is no
free, no raw pointers, and nounsafekeyword in Gossamer source. Memory is reclaimed automatically by reference counting on every tier, with a thread-local cycle collector on compiled tiers. The VM and cross-goroutine object graphs can retain strong cycles, so useWeak<T>when the graph can cycle. Use-after-free and double-free are not expressible in ordinary Gossamer code. The one escape hatch is the low-levelruntime::arena_push()/arena_pop()primitive; itsarena { }block form is statically escape-checked (error[GM0003]), but the raw calls are not. - A curated set of well-known external crates, each reviewed before
adoption:
clap,serde/serde_json,toml,parking_lot, thecrossbeamchannels / deques,rayon,mio, theunicode-*family,sha2,ring/rustlsfor TLS,regex, Cranelift and LLVM for codegen, andcorosenseifor stackful coroutines - withinstaas a dev-only snapshot tool.
Known gaps¶
Before shipping production services on Gossamer, you should know:
- The HTTP server enforces
max_header_bytes(default 8 KiB) andmax_body_bytes(default 1 MiB). Tune viahttp::Configif your traffic justifies a larger envelope; the defaults are deliberately conservative. std::tlsis wired throughhttp::serve_tlsandnet::TcpStreamTLS upgrades. TLS configuration constructors are host-runtime internals, not Gossamer callables. The all-tiercrypto::x509::verify_server_certificate_with_crlsAPI verifies supplied private roots and mandatory CRLs, but does not use system roots or retrieve revocation data.crypto::rand::fillusesgetrandomand returns an explicit error if the OS RNG is unavailable. Callers must not silently discard that error in security-sensitive code.env::var/env::args/env::set_varwork in both the interpreter and the compiled tier. Mutation paths (set_env/unset_env) route throughgossamer_runtime::safe_envso they are safe to call before spawning goroutines.- The data-race detector (
gos test --race) catches unsynchronised concurrent writes via vector-clock happens-before analysis. CI gating on--raceis recommended for any code that touches goroutines.
Open caveats:
- HTTP/2 + WebSockets are deferred to v1.x.
- Per-line coverage instrumentation (Phase 2 follow-up) -
the
--coverageoutput today is at the test-file granularity. - Postgres / MySQL drivers belong to the package ecosystem with their own maintainers and CVE response cadence.
Crypto and PKI tier audit¶
The promoted cryptographic source APIs execute on the VM, forced Cranelift
JIT, and LLVM AOT tiers. stdlib_compiled_coverage rejects any advertised
free function without compiled dispatch. Cross-tier fixtures cover known hash
vectors, authenticated-encryption round trips and authentication failures,
signature verification failures, password/KDF wrong-secret failures, and
constant-time unequal inputs.
| Surface | Success and failure evidence |
|---|---|
| Secure random, SHA-256, SHA-512, BLAKE3, HMAC-SHA-256, constant-time equality | stdlib_new_modules, llvm_aot_coverage, crypto_rand_failure, stdlib_encoding_crypto.gos |
| AES-256-GCM and ChaCha20-Poly1305 | crypto_aead.gos, including AES authentication rejection with a wrong key |
| Ed25519 and P-256 ECDSA | crypto_aead.gos and crypto_ecdsa.gos, including altered-message or malformed-signature rejection |
| PBKDF2, scrypt, and Argon2id | crypto_extra.gos and crypto_password.gos, including wrong-password verification |
| X.509 parse and private-root CRL verifier | Generated CA/intermediate/leaf/revoked/expired-CRL parity fixture, plus bench_crypto_x509_crl_verify_observed |
No promoted cryptographic source API is intentionally host-only. Secure random bytes necessarily use the host operating-system CSPRNG on each native tier. Rust TLS configuration constructors are host APIs by design; they are not a missing source-level crypto primitive.
Reporting a vulnerability¶
Email security@gossamer-lang.org with a PoC and a suggested
severity. A SECURITY.md lands in the repository root alongside
the 1.0.0 release.
CI automation¶
cargo denyandcargo auditrun on pull requests and main.- The pull-request fuzz smoke covers lexer, parser, manifest, HTTP, resolver, HIR, type, MIR, bytecode-compile, and bytecode-run targets; longer bounded fuzz runs are scheduled weekly.
- A pinned-nightly Miri suite runs weekly for the runtime, scheduler, coroutine, resolver, type, and MIR crates. It is intentionally scoped to code Miri can execute.
- ASan runs on the runtime, interpreter, coroutine, MIR, and binding crates; TSan covers the runtime, scheduler, and coroutine crates on main and on a nightly schedule.