Skip to content

docs(audit): plan post-W7 Rust remediation - #122

Merged
blakinio merged 6 commits into
mainfrom
docs/OTC2-20260801-post-w7-remediation-plan
Aug 1, 2026
Merged

docs(audit): plan post-W7 Rust remediation#122
blakinio merged 6 commits into
mainfrom
docs/OTC2-20260801-post-w7-remediation-plan

Conversation

@blakinio

Copy link
Copy Markdown
Owner

Purpose

Turn the four validated post-W7 Rust-client MEDIUM findings into one durable, bounded remediation execution plan without implementing any remediation.

Accepted decomposition

  • R1-SECRET: secret lifecycle and truthful cleanup claims;
  • R2-SHUTDOWN: nonblocking event-loop shutdown and bounded synchronous I/O, serialized after R1-SECRET;
  • R3-ASSET-OPEN: discovery-first opened-object integrity remediation;
  • R4-ARCH-POLICY: complete fail-closed allowed-edge policy preserving the current 19-member graph.

Delivered scope

Exactly three documentation paths:

  • planning task and checkpoint;
  • canonical remediation plan under the post-W7 audit path;
  • exactly one ready-to-paste Codex prompt for the first package, R1-SECRET.

Live-state evidence

Boundaries

No Rust implementation, manifest, Cargo.lock, workflow, dependency policy, architecture rule, test or external-repository change. No implementation worker launches before this plan and its separate task archive merge.

Validation

Complete changed-file/content review and exact-head emitted CI are required before readiness/merge.

Task

OTC2-20260801-post-w7-remediation-plan

@blakinio
blakinio marked this pull request as ready for review August 1, 2026 06:30
@blakinio
blakinio merged commit 658241f into main Aug 1, 2026
19 checks passed
@blakinio
blakinio deleted the docs/OTC2-20260801-post-w7-remediation-plan branch August 1, 2026 06:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant