Skip to content

docs(security): SEC-1.i/.j helpers shipped — trim pending list, propose SEC-1.p Landlock defense-in-depth#4698

Open
oferchen wants to merge 1 commit into
masterfrom
docs/security-sec1-helpers-shipped-followup
Open

docs(security): SEC-1.i/.j helpers shipped — trim pending list, propose SEC-1.p Landlock defense-in-depth#4698
oferchen wants to merge 1 commit into
masterfrom
docs/security-sec1-helpers-shipped-followup

Conversation

@oferchen
Copy link
Copy Markdown
Owner

Summary

Status field intentionally remains "Mostly fixed": the remaining receiver call-site wiring follow-ups (metadata crate carrier plumbing for SEC-1.i; disk_commit / transfer_ops/response / local_copy/executor cross-thread plumbing for SEC-1.j) and the Landlock defense-in-depth layer still preclude a clean Fixed claim.

Test plan

…e SEC-1.p

SEC-1.i (PR #4690) and SEC-1.j (PR #4693) both shipped today, providing
fchmodat/fchownat/utimensat and renameat sandbox helpers respectively. The
prior "Mostly fixed" note still listed them as in flight; this update moves
them into the Shipped list with PR references, trims the Remaining work
list accordingly, and adds a forward-looking SEC-1.p Landlock LSM
defense-in-depth proposal as the next layer.

Status remains "Mostly fixed" pending receiver call-site wiring through
DirSandbox (carrier-first staging) and SEC-1.p resolution.
@github-actions github-actions Bot added the documentation Improvements or additions to documentation label May 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant