Keyboard shortcuts

Press or to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Security Verification Track Registry

The S.x labels used across this manual are registry identifiers for the Security Verification Track. They are not product stages. When a section mentions one of these labels, read it as shorthand for the track name below.

TrackNameStatus
S.1CI bootstrapLanded
S.2Miri and proptest on capos-libLanded
S.3Manifest and mkmanifest fuzzingLanded
S.4Ring Loom harnessLanded
S.5Kani on capos-libInitial bounded gate landed
S.6Security review docs stay alignedOngoing
S.7Stage-6-aware security refreshPlanned/ongoing
S.8Untrusted-service hardening gatePlanned
S.9Authority graph and resource accountingDesign landed
S.10Supply-chain and generated-code trusted computing basePartially landed
S.11Device and DMA isolation gateDesign accepted; implementation gates open
S.12Kani harness bounds refreshPlanned
S.13ELF parser arbitrary-input coverageLanded
S.14Telnet IAC filter fuzz coverageLanded
S.15Telnet differential round-trip and line-discipline extractionLanded
S.16Ring SQE wire-validation extraction and fuzz targetLanded
S.17Sanitizers on host testsPlanned

Subtracks Used In This Manual

SubtrackParentMeaning
S.10.0S.10Trusted build input inventory
S.10.2S.10Generated-code drift check
S.10.3S.10Dependency policy and no_std review gate
S.11.1S.11DMA capability invariants
S.11.2S.11Userspace-driver ownership-transition gate

The S.11.2.0 through S.11.2.9 labels in the DMA chapter are local checklist rows for the userspace-driver transition gate. They are acceptance criteria under S.11.2, not separate project tracks.