Skip to content

Cairn Mod v1.0.0

Choose a tag to compare

@skydeval skydeval released this 24 Apr 17:01
· 159 commits to main since this release

Cairn v1.0.0 - Initial Release

Cairn is a minimal, self-hostable AT Protocol labeler with audit integrity,
moderator authentication via PDS-mediated service auth, and single-binary
deployment backed by SQLite.

Features

  • AT Protocol labeler service: createLabel, queryLabels, subscribeLabels
  • PDS-mediated moderator authentication via com.atproto.server.getServiceAuth
  • Admin XRPC surface: applyLabel, negateLabel, retract, listLabels,
    listReports, resolveReport, applyLabelAndResolveReport, listAuditLog
  • Full audit log with single-transaction atomicity
  • Non-enumerating 404s (privacy-preserving)
  • Configurable label taxonomy via TOML
  • Single-binary deployment with SQLite backend
  • Deployment templates for Caddy, nginx, systemd (see contrib/)

Security

  • Byte-exact DRISL signing parity with @atproto/crypto
  • SSRF-hardened HTTP fetch
  • File permissions enforced on signing keys and session files (0600)
  • Signing key delivered only via file, never via environment variable
  • Single-instance lease enforcement (SQLite-backed)

Documentation

  • Production Checklist for operators (README.md)
  • Design documentation with threat model (cairn-design.md)
  • Full OSS paperwork: LICENSE (MIT + Apache), CONTRIBUTING, SECURITY,
    CODE_OF_CONDUCT, MAINTAINERS

Known Issues

  • auth::cache::tests::doc_cache_negative_has_shorter_ttl has a tight
    timing-based assertion that can flake under CI load (tracked as
    chainlink #21). Not user-facing.

Thanks

This is the first release. Documentation, architecture, and implementation
by @skydeval.