Parent: GOLDEN_PATH.md. Raises Security axis toward ≥9.0.
Does not claim “untrusted .ryx is safe.”
| Wave | Theme | Gate | ADR |
|---|---|---|---|
| A | --sandbox=docker|none for clang link (opt-in; default none) |
sandbox_docker_smoke or SANDBOX_SKIP_MATRIX.md |
0022 |
| B | RIR sanitize: reject system/exec*/popen/dlopen escapes |
sanitize_rejects_exec |
0023 |
| C | MSan+UBSan enforce on rt/ smokes (Linux CI) |
msan_ubsan_rt_clean |
— (SANITIZER_SCAFFOLD.md) |
| D | Fuzz targets: parse + seeds | fuzz_new_targets_seeded |
— |
| E | Threat model (STRIDE) | file + link from SECURITY.md | — (SECURITY_THREAT_MODEL.md) |
| F ∥ | Windows Job Object sandbox or deferral | windows_sandbox_or_deferral |
0022 amend (WINDOWS_SANDBOX_DEFERRAL.md) |
| G ∥ | emit-ll / no-clang-link fast path smoke |
emit_ll_no_link_smoke |
— |
| H ∥ | CWE matrix beyond 798 | security_cwe_matrix_or_deferral |
— (CWE_MATRIX.md) |
Contract: contracts/phase27_security.contract.toml.
| Axis | Prior | After | Gates |
|---|---|---|---|
| Security | 7.6 | ≥9.0 (target) | sandbox + sanitize + threat model + CWE honesty |
- seccomp as hard Quality-10 requirement
- Coq fiber proof
- Claiming untrusted
.ryxis safe to compile/run