What
Update the F-09 register entry (izbad control socket, <data>/daemon/izbad.sock) to record as measured fact, not assumption, that the control socket keeps the implicit Medium integrity label — it is not among VmSpec::confined_write_surfaces, so it never receives the inheritable Low label — and therefore, per spike #248's result (AF_UNIX connect() requires write access), a Low-IL process such as the confined VMM cannot connect to it at all. Cite the spike doc and the build tested.
Why
F-09's Windows residual currently says only that izba does not harden the control socket and that it inherits the %LOCALAPPDATA% DACL. That is true but incomplete: the spike turned the label/connect relationship into a proven barrier, and the control socket happens to sit on the right side of it. The CLI and the desktop app run as the user at Medium, so they are unaffected; the VMM at Low is structurally excluded from the control plane. This is the one place where the #248 result strengthens the register, and it should be written down so a future change (e.g. adding the daemon dir to the labelled surfaces "for convenience") is recognised as removing a proven barrier.
In Scope
- F-09 entry: add the proven Medium-only status of
izbad.sock, the mechanism (not a confined write surface → no Low label → Low-IL connect() denied), and the citation.
- A guard test or doc-comment on
confined_write_surfaces stating that the daemon dir must never be included, so the barrier is not lost silently.
Out of Scope
- Any change to what the control socket enforces (peer auth on Windows stays F-09's open residual for Medium peers).
- Any change to the label scheme.
Acceptance Criteria
INVEST Notes
Independent — depends only on merged code and PR #277's spike doc.
Negotiable — test vs doc-comment guard is open; the register text is fixed in substance.
Valuable — converts an assumption into recorded evidence and protects it with a guard.
Estimable — one paragraph, one small test.
Small — effort XS.
Testable — the guard test is the check.
What
Update the F-09 register entry (izbad control socket,
<data>/daemon/izbad.sock) to record as measured fact, not assumption, that the control socket keeps the implicit Medium integrity label — it is not amongVmSpec::confined_write_surfaces, so it never receives the inheritable Low label — and therefore, per spike #248's result (AF_UNIXconnect()requires write access), a Low-IL process such as the confined VMM cannot connect to it at all. Cite the spike doc and the build tested.Why
F-09's Windows residual currently says only that izba does not harden the control socket and that it inherits the
%LOCALAPPDATA%DACL. That is true but incomplete: the spike turned the label/connect relationship into a proven barrier, and the control socket happens to sit on the right side of it. The CLI and the desktop app run as the user at Medium, so they are unaffected; the VMM at Low is structurally excluded from the control plane. This is the one place where the #248 result strengthens the register, and it should be written down so a future change (e.g. adding the daemon dir to the labelled surfaces "for convenience") is recognised as removing a proven barrier.In Scope
izbad.sock, the mechanism (not a confined write surface → no Low label → Low-ILconnect()denied), and the citation.confined_write_surfacesstating that the daemon dir must never be included, so the barrier is not lost silently.Out of Scope
Acceptance Criteria
izbad.sockis Medium-labelled by construction and that a Low-IL peer'sconnect()is denied, citingdocs/spikes/0001-windows-afunix-connect-write-access.mdand build 26100.4349.confined_write_surfaces()never yields the daemon dir (or a path under it), with a comment naming this finding as the reason.INVEST Notes
Independent — depends only on merged code and PR #277's spike doc.
Negotiable — test vs doc-comment guard is open; the register text is fixed in substance.
Valuable — converts an assumption into recorded evidence and protects it with a guard.
Estimable — one paragraph, one small test.
Small — effort XS.
Testable — the guard test is the check.