Document Netix security and Rust migration roadmap #15

Merged
ober merged 1 commit from docs/security-rust-roadmap into main 2026-09-22 17:30:30 -04:00
Owner

Netix needs a durable, risk-ordered plan for replacing C/C++ infrastructure with Rust while completing its NetBSD rump/libc transition and making Jerboa central to services and policy. Adds Roadmap.md with 30 dependent work packages, component disposition, immediate security prerequisites, ABI/ownership contracts, service and canonical Xen acceptance gates, and long-term core/kernel/runtime retirement tracks.

The analysis distinguishes default main, the committed rump development branch, uncommitted integration work, historical artifact evidence, and the separately inspected Jerboa runtime. Current implementation observations are not presented as production exploitability or fresh acceptance results. Primary-source research is linked beside relevant claims. VERSION advances from 26.10.0 to 26.10.2.

Validation:

  • Three independent architecture, deployment, and Jerboa analyses plus follow-up document reviews; their factual/scope corrections incorporated.
  • All 7 existing host deployment unit tests passed; deployment CLI --help smoke passed.
  • Document structure, 17 TOC anchors, 12 invariants, 30 work packages, fenced blocks, and whitespace checks passed.
  • Documentation and version metadata only. No OS code changed, no OS binary built, and no new runtime/production acceptance claimed. The clean default branch has no root make binary target or the later development branch's canonical controller workflow; this review does not certify that development integration.
  • Post-creation status verified through the Forgejo API: exact head 82e2ac8e1f4c15e7c485098b20c0d5fdf0414934, zero commit statuses, zero Actions runs, and no required status contexts. fj pr status failed to decode Forgejo's empty status string. There are no green CI results to claim and no reported failing/running checks.

Human review and merge required. The existing development checkout and its in-progress source changes were preserved.

Netix needs a durable, risk-ordered plan for replacing C/C++ infrastructure with Rust while completing its NetBSD rump/libc transition and making Jerboa central to services and policy. Adds `Roadmap.md` with 30 dependent work packages, component disposition, immediate security prerequisites, ABI/ownership contracts, service and canonical Xen acceptance gates, and long-term core/kernel/runtime retirement tracks. The analysis distinguishes default `main`, the committed rump development branch, uncommitted integration work, historical artifact evidence, and the separately inspected Jerboa runtime. Current implementation observations are not presented as production exploitability or fresh acceptance results. Primary-source research is linked beside relevant claims. `VERSION` advances from 26.10.0 to 26.10.2. Validation: - Three independent architecture, deployment, and Jerboa analyses plus follow-up document reviews; their factual/scope corrections incorporated. - All 7 existing host deployment unit tests passed; deployment CLI `--help` smoke passed. - Document structure, 17 TOC anchors, 12 invariants, 30 work packages, fenced blocks, and whitespace checks passed. - Documentation and version metadata only. No OS code changed, no OS binary built, and no new runtime/production acceptance claimed. The clean default branch has no root `make binary` target or the later development branch's canonical controller workflow; this review does not certify that development integration. - Post-creation status verified through the Forgejo API: exact head `82e2ac8e1f4c15e7c485098b20c0d5fdf0414934`, zero commit statuses, zero Actions runs, and no required status contexts. `fj pr status` failed to decode Forgejo's empty status string. There are no green CI results to claim and no reported failing/running checks. Human review and merge required. The existing development checkout and its in-progress source changes were preserved.
ober merged commit 1aef1e8841 into main 2026-09-22 17:30:30 -04:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
ober/netix!15
No description provided.