ChrisOS Research Project Documentação técnica do sistema

Referência de fonte: SECURITY.md

Neste capítulo

Registro determinístico da fonte. O conteúdo completo do arquivo é reproduzido abaixo; esta página não substitui a interpretação arquitetural dos capítulos autorais.

Identidade do arquivo

Campo Valor
Path SECURITY.md
Lines 22
Bytes 1341
SHA-256 664078e5136b30c3e122fbeaec3c8553e866b517276cc2edcd11c2fed201f4f7
ChrisOS revision 92fb561574bd929522ea005b9fd433138bea3236

Dependências sintáticas detectadas

Linha Include
— Nenhum include de preprocessor detectado.

Símbolos detectados

Linha Símbolo
— Nenhuma definição de função no formato C detectada pelo scanner.

Fonte completa

O bloco seguinte é o arquivo textual integral na revisão indicada. Não há elisão, abreviação ou paráfrase.

# Security policy

ChrisOS is an experimental operating-system and systems-research project. It is not presented as a hardened production operating system.

## Supported code

Security fixes should target the current <code>main</code> branch unless a maintainer explicitly identifies another supported branch.

## Reporting a vulnerability

Do not publish exploit details in a normal public issue before a maintainer has had a reasonable opportunity to assess them.

If GitHub private vulnerability reporting is available in the repository Security tab, use that channel. Otherwise, contact the maintainer through the contact method exposed on the maintainer's GitHub profile.

Include the affected commit, subsystem, reproduction conditions, impact, a minimal proof of concept when safe, and whether the issue is reachable only in QEMU/test environments or also in a plausible hardware deployment.

## Scope

Useful reports include memory-safety errors, privilege-boundary failures, filesystem corruption paths, malformed executable/image handling, network parser issues and virtualization-boundary problems.

Because ChrisOS is experimental, a missing hardening feature by itself is not necessarily a vulnerability. Reports are most useful when they identify a concrete violation of an intended boundary or a reproducible security impact.

Papel deste registro

O atlas garante rastreabilidade arquivo-a-arquivo. Responsabilidade, invariantes, ownership, concorrência, segurança, desempenho e interação entre subsistemas pertencem aos capítulos autorais e devem citar este arquivo quando aplicável.

Registro do documento
ID: source-664078e5136b30c3 Source revisado: 92fb561574bd Class: generated-source-reference