Skip to content

Phase B follow-up: adversarial probes, doc repair, trust scoping - #41

Merged
txmed82 merged 1 commit into
mainfrom
feat/phase-b-followup
Sep 9, 2026
Merged

Phase B follow-up: adversarial probes, doc repair, trust scoping#41
txmed82 merged 1 commit into
mainfrom
feat/phase-b-followup

Conversation

@txmed82

@txmed82 txmed82 commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

What: live adversarial probes (UID/mount/egress/canary), truncated-doc repair, honest scoping of output policing (E) and B5 minting (blocked on cloud owner), HMAC operator-seal semantics.

Why: review gaps — probes lacked teeth, doc truncated, asymmetric-vs-HMAC and cloud-minting positions unstated.

Verify: full suite green; probes pass live digest-pinned; ruff + format + mypy clean. CI + review pending.

- Live container probes: nobody UID, ro mount, no egress, no
  sibling leakage (skip-guarded; verified digest-pinned).
- ISOLATION_MODEL.md repaired truncation; semantic output
  policing scoped to E; B5-cloud blocked explicitly.
- Attestation: operator-held seal semantics documented.
@factory-droid

factory-droid Bot commented Sep 9, 2026

Copy link
Copy Markdown

Droid finished @txmed82's task —— View job


Security Review

Pass 2 (validation) complete.

LGTM. I validated the Phase 1 candidate list and there were no inline comments to post; the added adversarial container probes look well-scoped and should meaningfully catch isolation regressions.

@txmed82
txmed82 merged commit 6c53d16 into main Sep 9, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants