Harden Kitsune release and System Mode lifecycle - #26
Merged
Conversation
Jordan231111
force-pushed
the
codex/production-hardening
branch
3 times, most recently
from
August 1, 2026 11:30
2292696 to
fc10d92
Compare
Jordan231111
force-pushed
the
codex/production-hardening
branch
from
August 1, 2026 11:58
fc10d92 to
fa822a3
Compare
Jordan231111
force-pushed
the
codex/production-hardening
branch
from
August 1, 2026 12:12
fa822a3 to
c840347
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
NO-SOURCE; heavy stress and destructive emulator experiments remain local and disposableDEVELOPMENT_ROADMAP.mdas the detailed source of goals, current position, remaining PRs, evidence, release gates, and the same-day ZygiskNext v1.4.4 black-box research updateExact final local verification
Final code commit:
530f2a3f8PR head:
c840347f4History: exactly two commits over
kitsunec840347f-kitsunewith the correct debug/release modecargo auditagainst official database commit84dd8268still observes one RSA vulnerability and five reviewed warnings; each relevant advisory/affected/version record is fingerprintedTiramisu64instance compared the released backend and hardened candidates, restored the starting payload, and reproduced one unchanged vendor launch/storage failure that passed on immediate retry; this is strong evidence for that specific intermittent BlueStacks failure, not a blanket classification of every future boot failureHosted-gate history
2292696a0passed source, build/JVM/lint/artifact, API 29, API 35, and upstream/security gates; API 23 exposed Android 6 ADB PTY\rin otherwise-correct PackageManager and Magisk readiness outputfc10d9242passed source, release/debug build, JVM/lint/artifact, API 23/29/35, and aggregate product gates; its security job then exposed that an unrelated global RustSec database commit made the exact generated report appear stale despite the same advisory count and the same six observed findingsThe final
c840347f4head passed the complete hosted matrix: Kitsune CI run 30699231707 passed source, release/debug build, JVM/lint/artifact, API 23/29/35, and aggregate Product gate; security run 30699231663 passed the upstream, license/SBOM, historical-submodule, signature, and RustSec ledger. The PR-only UBSan job is intentionally skipped; scheduled/local parser evidence remains recorded in the roadmap.Important limitations
denylistrows and loaded Vector/CorePatch, but its clean namespace still exposed the Kitsune-specific/system/binoverlay, so universal provider/SuList parity is not claimedAfter merge, the next engineering unit is roadmap PR5A: qualify one exact writable, snapshot-capable target by restoring the same baseline between the released comparison and hardened artifact. PR5B is conditional on what that lifecycle proves.
Detailed rationale and evidence are in
DEVELOPMENT_ROADMAP.md; concise current claims remain indocs/status.md.