Skip to content

Document the enforced isolation boundaries and state the level 3 claim #42

Description

@aidangarske

Context

The docs hedge the isolation level. Once the level 3 work lands, the docs should state each enforced boundary and its properties and make the claim on tested SHAs.

Origin

FF-M isolation level 3 compliance plan, WI-13 and WI-14

What is needed

  • Security-Model and Threat-Model sections for each boundary, the optional rules not implemented (I4 to I6), and the NS-side scope
  • A final Skoll pass over the combined diff with no valid Medium or above, then an independent adversarial audit
  • The claim, listing the tested SHAs per port

Blockers and dependencies

Every other issue in the level 3 tracking issue.

Acceptance criteria

  • Every level 3 PR passed its Skoll gate (security, review and FF-M lenses with no valid High or Medium) before merging
  • The claim merges last, with the review results recorded

Activity

  1. added
    todoDeferred work tracked for later
    P2Medium: needed but not blocking; bug with a workaround; flake
    on Sep 29, 2026
  2. aidangarske commented on Oct 3, 2026

    @aidangarske
    MemberAuthor

    W8 (the Cortex-A part of this issue) landed on wolfTrust-dev2 (PR #29) in eaee0625

    docs/Security-Model.md gains a "Cortex-A isolation level 3" section for the AArch64 port on QEMU virt. It has three parts:

    Skoll blog checked the section against the dev2 code over three rounds and found five overclaims, all fixed: FF-A shared memory, restart semantics, the ACS deviation, profile 0, and the Versal block names. review and review-security are clean.

    The section sits just before "Source anchors", so it does not textually conflict with the H5 level 3 section #31 adds at the top of the file.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    P2Medium: needed but not blocking; bug with a workaround; flaketodoDeferred work tracked for later

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions