Repository navigation
Document and rehearse abuse response and destination opt-out handling #19
Description
Activity
- addeddocumentationImprovements or additions to documentationImprovements or additions to documentationP1Core supported-product work to prioritize after the working local alpha.Core supported-product work to prioritize after the working local alpha.Project maintenanceMaintainer responsibilities, support policy, contribution documentation and publication preparation.Maintainer responsibilities, support policy, contribution documentation and publication preparation.Source reviewedCurrent source evidence checked; no new runtime reproduction claimed by backlog creation.Current source evidence checked; no new runtime reproduction claimed by backlog creation.
on Sep 24, 2026 Progress: #186, merged into
devvia #228 (e4a621f), adds a reporting route and a destination opt-out procedure ("Abuse reports and destination opt-out" indocs/SECURITY.md). Still open: rehearsing the procedure, a credential-compromise runbook and drill, and an accountable contact beyond public issues.PR #408 merged as aa3ac6d. The abuse-response procedure now accompanies real authenticated local opt-out and credential-revocation drills. Controlled TCP/UDP receivers stopped after acknowledged policy delivery; lost delivery recovered while probes remained healthy. The revoked credential returned 401 and the replacement returned 200. The fixture distinguishes stopped traffic, unavailable delivery and retained evidence.
Candidate CI and merged-main CI passed. These are owned local fixtures, not a production abuse incident or an external contact rehearsal. The issue stays open for the accountable reporting contact and agreement on incident evidence access and retention.
Problem
Technical destination limits need a human-operable reporting and incident process for disputed traffic, compromised credentials or an opt-out request.
Proposed change
Define report intake, accountable target verification/review, access to evidence, escalation and response runbooks, using the implemented policy propagation and credential controls.
Acceptance criteria
Current evidence
unimplemented requirement. Backlog classification is based on source inspection; this issue does not claim a new runtime reproduction.
Dependencies
Validation must use owned local fixtures on supported Linux environments. Record the implementing merge request and relevant test results before closing this issue.
Imported from GitLab issue 18. Originally opened 2026-09-10. Historical GitLab links may require access to the original project.