Report suspected vulnerabilities through GitHub's private advisory form on this repository, or to security@zecbit.net. Please do not open a public issue first.
A bundle that verify() accepts and SPEC.md says it should reject is a
vulnerability. So is a byte string that two conformant implementations parse
differently, because that is disagreement about what a collection contains.
Availability of manifests or metadata is out of scope: these formats bind bytes, they do not store them.
The Orchard cryptography and the node access are interfaces the caller supplies. This package implements the serialization and the order of checks. A defect in a backend is not a defect here, and a correct procedure over a broken backend still gives a wrong answer.
tests/fakes.py contains BLAKE2b stand-ins used to exercise the procedure. They
are not cryptography and must not be used outside the test suite.
These are properties of the construction, documented in SPEC.md section 6, not defects to report:
- There is no public ownership lookup, and there cannot be one.
- Every buyer learns the item's complete prior chain, permanently.
- Settlement is custodial until two parties can co-construct one transaction.
- Verification requires a full node for full privacy.
This construction is new and this is its first implementation. Neither has been independently audited.