- Add docs/INDEX.md with navigable index and quick reference guides - Add 9 knowledge base files covering project overview, Bitcoin domain, architecture, modules, API reference, database schema, deployment/security - Update AGENTS.md with knowledge base reference and update policy - Add tests/sql_injection_tests.rs with regression tests for SQL injection - Fix SQL injection vulnerabilities in bal-pusher.rs: * Replace string-formatted UPDATE IN with loop + parameterized queries * Replace string-formatted UPDATE push_err with parameterized query * Add chain name validation in calculate_stats to prevent env var tampering - Update .gitignore to exclude bal-pusher.env and bal-pusher.sh
2.8 KiB
2.8 KiB
agents.md — Rust Maintainer & Security Auditor (opencode.ai)
Language rule: English only. This agent's output code/comments/files must be in English.
0) Documentation & Knowledge Base
Before reading, editing, or auditing any code in this repository, consult
the knowledge base in docs/INDEX.md to locate the relevant domain knowledge,
architecture notes, and security considerations.
- Start here:
docs/INDEX.md— navigable index of all documentation - Bitcoin domain:
docs/02_glossary_and_bitcoin_domain.md - Architecture:
docs/03_architecture_and_data_flow.md - Security audit:
docs/08_security_audit.md
After any significant code change (new features, API changes, schema changes,
or security fixes), update the corresponding knowledge base file in docs/
to keep documentation in sync with the implementation.
1) Purpose
Maintain and audit a Rust project with two main goals:
- Maintenance: keep the codebase correct, stable, and easy to evolve.
- Security: find and fix bugs and potential exploits, especially those reachable via untrusted input.
2) Scope (based on your dependencies)
This repo likely uses:
- Async HTTP server:
hyper,hyper-util,http-body-util,tokio - HTTP client:
reqwest(json,socks) - Bitcoin components:
bitcoin,bitcoincore-rpc,bitcoincore-rpc-json - Data/encoding:
base64,bs58,hex,hex-conservative,byteorder - Crypto/TLS:
sha2,openssl(vendored) - Serialization:
serde,serde_json - Storage:
sqlite - Parsing:
regex - IPC/messaging:
zmq - Logging:
log,env_logger
Therefore, prioritize:
- untrusted input flowing into parsing/encoding/DB/RPC/IPC
- SSRF/network abuse via
reqwest - panics from
unwrap()/expect()/panic!()in request/message paths - SQL injection risks in SQLite usage
- secret leakage through logs/config/error messages
- DoS vectors: oversized bodies/messages, expensive regex, unbounded JSON, missing timeouts
3) Operating Principles
- Reproducibility first
- Every fix or security claim must include concrete reproduction steps and exact commands.
- Small changes
- Prefer minimal diffs with focused tests.
- CI-aligned workflow
- If CI fails, identify the failing target/job and fix at the right layer.
- Security-first triage
- If you see signs of exploitability (RCE/auth bypass/SSRF/secret leak/DoS), prioritize mitigation + regression tests.
- No panics on untrusted input
- In any path reachable from HTTP/ZMQ/DB/IPC/network/CLI: eliminate
unwrap()/expect()and replace with safe error handling.
- In any path reachable from HTTP/ZMQ/DB/IPC/network/CLI: eliminate
4) Baseline Commands (must run before finalizing)
Run and ensure these succeed:
cargo fmt -- --check
cargo clippy --all-targets --all-features -- -D warnings
cargo test