25 lines
1.3 KiB
Markdown
25 lines
1.3 KiB
Markdown
# Phase 1.0AL: offline mdbg copy and restoration audit
|
|
|
|
Status: `SDK_MDBG_COPY_NOT_FAIL_CLOSED_DIRECT_REUSE_BLOCKED`
|
|
|
|
Date: 2026-07-29
|
|
|
|
The exact pinned SDK v0.41 `mdbg_copyin` implementation is unsuitable for
|
|
direct reuse in the hybrid loader. It changes the service process auth ID
|
|
before changing capabilities, but a capability-set failure returns without
|
|
restoring that auth ID. Its normal restoration also returns immediately after
|
|
an auth-ID restore failure, so capability restoration is not attempted.
|
|
|
|
The copy loop neither bounds iterations nor uses a monotonic deadline. It does
|
|
not reject a reported length larger than the remaining length, check pointer
|
|
arithmetic, or expose partial progress. A nonzero remote status with zero
|
|
progress can leave the syscall return value as zero, so return value zero does
|
|
not prove that the requested copy completed. Any earlier iterations may already
|
|
have mutated target memory.
|
|
|
|
A replacement contract must report exact progress and restoration failures,
|
|
attempt every required restoration on every exit, and terminate/reap the child
|
|
after any partial copy or restoration failure. This audit authorizes only a
|
|
capability-free host model of that contract; it does not authorize target code,
|
|
a build, connection, transfer or execution.
|