Skip to content

Security audit (external) #2

@raffaelschneider

Description

@raffaelschneider

Milestone 4.1

Commission an external security audit of the supervisor, syscall boundary, and GPU isolation layer.

Scope

  • Syscall validation (boundary checks, capability enforcement)
  • GPU partition isolation (IOMMU configuration, VRAM zeroing, DMA gating)
  • Capability system (grant/revoke/restrict correctness)
  • Side-channel mitigations (FPU/SSE clearing, IBPB, CR4.TSD)

Context

The supervisor is ~5K LoC with a small attack surface by design. Phase 4 focuses on hardening before multi-vendor GPU support.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions