Context
The docs hedge the isolation level. Once the level 3 work lands, the docs should state each enforced boundary and its properties and make the claim on tested SHAs.
Origin
FF-M isolation level 3 compliance plan, WI-13 and WI-14
What is needed
- Security-Model and Threat-Model sections for each boundary, the optional rules not implemented (I4 to I6), and the NS-side scope
- A final Skoll pass over the combined diff with no valid Medium or above, then an independent adversarial audit
- The claim, listing the tested SHAs per port
Blockers and dependencies
Every other issue in the level 3 tracking issue.
Acceptance criteria
- Every level 3 PR passed its Skoll gate (security, review and FF-M lenses with no valid High or Medium) before merging
- The claim merges last, with the review results recorded
Context
The docs hedge the isolation level. Once the level 3 work lands, the docs should state each enforced boundary and its properties and make the claim on tested SHAs.
Origin
FF-M isolation level 3 compliance plan, WI-13 and WI-14
What is needed
Blockers and dependencies
Every other issue in the level 3 tracking issue.
Acceptance criteria