docs(security): SEC-1.i/.j helpers shipped — trim pending list, propose SEC-1.p Landlock defense-in-depth#4698
Open
oferchen wants to merge 1 commit into
Open
Conversation
…e SEC-1.p SEC-1.i (PR #4690) and SEC-1.j (PR #4693) both shipped today, providing fchmodat/fchownat/utimensat and renameat sandbox helpers respectively. The prior "Mostly fixed" note still listed them as in flight; this update moves them into the Shipped list with PR references, trims the Remaining work list accordingly, and adds a forward-looking SEC-1.p Landlock LSM defense-in-depth proposal as the next layer. Status remains "Mostly fixed" pending receiver call-site wiring through DirSandbox (carrier-first staging) and SEC-1.p resolution.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
fchmodat/fchownat/utimensat) and SEC-1.j (PR feat(fast_io): renameat sandbox helper (SEC-1.j) #4693,renameat) from the Remaining-work list into the Shipped list with explicit PR references.*athelpers shipped" with receiver wiring tracked separately, so the headline status field is accurate without overclaiming.*athelpers).Status field intentionally remains "Mostly fixed": the remaining receiver call-site wiring follow-ups (metadata crate carrier plumbing for SEC-1.i;
disk_commit/transfer_ops/response/local_copy/executorcross-thread plumbing for SEC-1.j) and the Landlock defense-in-depth layer still preclude a clean Fixed claim.Test plan
git diff SECURITY.mdreviewed — single-file docs change, no source touched