Great to see reputable audit firms! Tagging @brentstone and @cwgoes from Heliax eng team for a few Qs:
The security page has interface audit completed July 2024, which may be a typo, since the report itself says July 2023. In terms of development, has much changed in interface and extension development since the audit and now? And the MASP audit is 2 years old. For software readiness, it would help us to understand if anything critical has changed since these audits.
There are two ongoing audits–what’s the scope for each of these? Should we expect that they be complete before or after mainnet?
@brentstone our understanding is that Heliax intends to red-team internally, and it would be great to know how this is going in your Discord announcement updates, if possible. We ran the Housefire canary network prior to the incentivized testnet, and we intend to do this again to get a better sense for Namada software stability ahead of mainnet. How are things coming with v0.41.0? As soon as this release is cut, we can begin.
We’re also planning to coordinate a decentralized dry-run of the Namada mainnet launch and the Phases of Mainnet with Housefire
I think if these go well, we’ll be more confident that both the protocol and the operators are ready for launch.
@Gavin Yes Heliax will be red-teaming internally, with the idea being to do this alongside the running of the Housefire testnet. Dedicated, full-team red-teaming has not begun in full, thought some engineers have effectively been red-teaming when time has permitted for them. In cases when a bug or issue has been discovered, the fix has been included in the release and sometimes highlighted in the Discord updates.
When we start some larger-scale, more coordinated red-teaming, I will note it in the Discord update.
Regarding v0.41.0, we are very close to having everything, and it should be cut this week. The only true blocker right now is the fix for the campfire liveness issue, which almost done. I’ll describe this in a Discord update today too, but for now check out the PR that addresses this for more details: workaround wasmer leak by tzemanovic · Pull Request #3529 · anoma/namada · GitHub.
Once v0.41.0 is out, this will be the new mainnet release candidate and we can begin Housefire.
That’s a typo, thanks for the catch - will be fixed.
A lot has changed in the interface and extension. I think the lessons from the audit were still helpful but a fresh one would probably be prudent here (perhaps once the extensions and interface stabilize in the next few months).
Nothing about the MASP circuit itself has changed since that audit (we also cannot change it once the trusted setup happens), so we should be alright there (of course, more eyes on the code is always helpful).
Both of the Informal Systems audits listed on that page have completed. Just pinged them regarding report publication.