PR4B: add upstream differential and security-research lab - #24
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Outcome
Implements roadmap PR4B on the frozen
f943ecddbaseline as a reproducible upstream-differential and security-research lab.Finding dispositions
KITSUNE-2026-001: fixed — malformed module IDs reached destructive paths before validation.KITSUNE-2026-002: fixed — truncated boot headers reached unchecked alignment and adjacent parser bounds.KITSUNE-2026-003: reviewed hold — inherited libsepol signed1 << 31; only UBSanshift-baseis suppressed pending the PR6 pin, while every other UBSan class remains fatal.Verification
armeabi-v7a,arm64-v8a,x86, andx86_64.:app:lintDebugpass.127.0.0.1:16384, ARM64, 4 KiB pages: 977 UBSan parser cases, zero crashes, boot sign/verify passed, policy save/reload passed. Parser sandbox only;/system, partitions, and the instance were not modified.46ff502d0e0a1d8f844d29c084a8b797107513d26199825f0d827836a87e84d7; AVD deleted.Scope boundaries
This does not claim persistent System Mode installation or physical-device recovery. MuMu remained read-only because there is not yet a verified snapshot/restore tuple. PR5 remains conditional on actually shipping the frozen current core; otherwise the roadmap proceeds to the pristine v30.7 PR6 baseline and carries these gates forward.
All disposable Android Studio AVDs and task-local host artifacts were removed after testing. The pre-existing local
outandnative/outtrees were restored byte-for-byte, and no MuMu instance was deleted or stopped.