Security review

Review date: 2026-10-03. This records the implemented defaults and tested boundaries for the 0.9 stabilization series.

Boundary Default and review result
RPC listener 0.0.0.0:50051; plaintext until tls is configured. Native supports TLS and required client-certificate validation through client_ca.
Admin HTTP 127.0.0.1:9090; read-only probes, metrics and status without authentication or built-in TLS. Keep it on loopback or protect it with network/proxy access controls.
Reflection Disabled in core and production. Rails development enables Native Reflection unless explicitly overridden; Async rejects Reflection configuration.
Message / metadata limits 4MiB per inbound/outbound message and 8KiB metadata; both adapters test bounded wire handling.
Internal RPC errors Redacted message with an error ID by default. Explicit mappings, expose_errors or remote-error passthrough can expose application messages.
Logs Completion records omit RPC payloads; diagnostic error records include message/class/backtrace. Field-name redaction does not sanitize arbitrary secrets embedded in free text. Restrict log access.
Traces Payloads, credentials and exception messages are omitted. Secure collector endpoints and credentials separately.
Fork safety fork_guard :raise; transport resources initialize in workers. Disabling the guard does not make inherited C-core state safe.

Applications implement authentication and authorization in controllers or middleware. Native context.peer_identity returns the verified client's PEM certificate; applications must parse and authorize certificate identity claims. TLS certificate, private-key and optional client-CA paths must name readable regular files before transport allocation. Symlinks to regular files remain supported for rotated secrets; directory and FIFO rejection has a regression test. Transport startup validates certificate content.

Async remains experimental and supports plaintext HTTP/2 only. Use a trusted network or TLS-terminating gRPC proxy; it does not claim Native TLS/mTLS, Health, Reflection or connection-age controls. Its restart limitation is preserved.

All repositories run bundler-audit with the current advisory database in main CI. Release workflows verify source/tag versions and user-facing changes, strict-build and test packages, then publish with RubyGems Trusted Publishing and provenance attestations. The self-hosted performance runner has no host Docker socket or host workspace mount, uses read-only repository permissions, and measures only an arranged idle environment.

This review found and fixed acceptance of directory/FIFO TLS paths before startup. Tests cover valid files and symlinks alongside rejected nonregular paths. The current dependency audit and supported-Ruby CI are required again for the stabilization release. No unresolved critical security defect was identified in this review; this is a bounded source/dependency review, not a claim of external penetration testing.