This commit is contained in:
@@ -0,0 +1,24 @@
|
||||
# Phase 1.0AL: offline mdbg copy and restoration audit
|
||||
|
||||
Status: `SDK_MDBG_COPY_NOT_FAIL_CLOSED_DIRECT_REUSE_BLOCKED`
|
||||
|
||||
Date: 2026-07-29
|
||||
|
||||
The exact pinned SDK v0.41 `mdbg_copyin` implementation is unsuitable for
|
||||
direct reuse in the hybrid loader. It changes the service process auth ID
|
||||
before changing capabilities, but a capability-set failure returns without
|
||||
restoring that auth ID. Its normal restoration also returns immediately after
|
||||
an auth-ID restore failure, so capability restoration is not attempted.
|
||||
|
||||
The copy loop neither bounds iterations nor uses a monotonic deadline. It does
|
||||
not reject a reported length larger than the remaining length, check pointer
|
||||
arithmetic, or expose partial progress. A nonzero remote status with zero
|
||||
progress can leave the syscall return value as zero, so return value zero does
|
||||
not prove that the requested copy completed. Any earlier iterations may already
|
||||
have mutated target memory.
|
||||
|
||||
A replacement contract must report exact progress and restoration failures,
|
||||
attempt every required restoration on every exit, and terminate/reap the child
|
||||
after any partial copy or restoration failure. This audit authorizes only a
|
||||
capability-free host model of that contract; it does not authorize target code,
|
||||
a build, connection, transfer or execution.
|
||||
Reference in New Issue
Block a user