Vouch request: SproutSeeds #3831
SproutSeeds
started this conversation in
Vouch Request
Replies: 1 comment
|
The tested filesystem restrictions worked. The checks covered two guest kernels. The remaining gap I found was incomplete kernel and security configuration information within the build record. I am proposing the change to preserve and verify the information through firmware packaging. I verified this through 29 new regression tests covering the provenance and packaging change, with 89 total script tests passing. The remaining work is full kernel and wrapper builds, plus complete OpenShell sandbox testing. Will this particular scope be useful to maintainers before proceeding further? |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
What do you want to work on?
I want to follow up on #3095 to discuss a small contribution with maintainers addressing whatever gap remains. I plan to check that the packaged Apple Silicon VM correctly enforces its filesystem restrictions as well as check whether its build record identifies the kernel and effective security configuration.
Why this change?
I believe in the leadership at NVIDIA. It inspires me to dream big and one of my core goals is to work for NVIDIA and be part of progress in AI, robotics, and biological discoveries. To do that, I know we need dependable safeguards we can test. I want to learn the ins and outs of OpenShell through practical testing, understand how its protections work, and continue to make useful contributions over time.
Checklist
All reactions