Audit: Rust kernel/host on main (cfccbbb) - #6
Closed
wu1w wants to merge 1 commit into
Closed
Conversation
Documents court unification gaps, lock/timeout races, process lifecycle, and the stale loop_guard test that is failing kernel-ci. No product code changes. Co-authored-by: wu1w <wu1w@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Read-only audit of the Rust kernel/host on latest
main(cfccbbb9ed3a8a489097aa3a6e42ee0049a66e43). No product or application code changes — this PR adds onlydocs/audit-rust-kernel-2026-08-18.md.What was reviewed
Court/authority after the extra_roots /
mcp_*/ session-grant unification, process start/stop/end and detached-backendjwt_fpreuse, tool dispatch/cancel/timeout/hang, token and file_read/glob/loop-guard behavior, lock/channel/shutdown races, unwraps on library paths, and why kernel-ci is red on main.Headlines
decide_toolas authoritative; extra_roots are path-only; session grants can upgradeask) but half-migrated: global last-writer policy,mcp_*allow before capability, steward args still trusted, incomplete write/command lists.spawn_blockingtimeout does not cancel the worker.loop_guard::tests::orch_window_force(expects a trip after ~3 orch rounds; production window is 6/8). Python ABI tests in that workflow never run. This PR does not fix CI.How to read the report
Findings are ranked critical / high / medium / low with file paths and suggested fixes, plus a What looks solid section and the audited SHA.
How to tell this is done