Skip to content

fix(security): unify verifier read policy - #31

Merged
1-ztc merged 1 commit into
mainfrom
fix/p2-device-read-policy
Aug 1, 2026
Merged

fix(security): unify verifier read policy#31
1-ztc merged 1 commit into
mainfrom
fix/p2-device-read-policy

Conversation

@1-ztc

@1-ztc 1-ztc commented Aug 1, 2026

Copy link
Copy Markdown
Contributor

Summary

  • share one normalized sensitive-path policy between predicate evaluation and the readonly device executor
  • reject /sys/firmware/... before device execution with
    ead_path_not_allowed`n- cover both telemetry reads and device ile_exist predicates
  • add an atomic security-fix checklist to the PR template

Validation

  • full
    pm run verify passed
  • boundaries, hygiene, benchmark checks, build, typecheck, lint, and all tests passed
  • moss-agent: 227 test files passed

@1-ztc
1-ztc merged commit b93acca into main Aug 1, 2026
3 checks passed
@1-ztc
1-ztc deleted the fix/p2-device-read-policy branch August 1, 2026 19:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant