You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Isolate an opt-in CPU Serverless adversarial-caller lab from the core assurance claim, with fail-closed immutable-image preflight, signed local-controller records, bounded live execution, and unconditional cleanup.
Copy file name to clipboardExpand all lines: README.md
+29-3Lines changed: 29 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -14,6 +14,7 @@ endorsement, and no upstream issue is claimed closed.
14
14
| Clean verification |`docker compose build --pull --no-cache` followed by `docker compose up --abort-on-container-exit --exit-code-from verify verify`|
15
15
| Expected smoke result | The full suite under branch-enabled combined coverage, real-`swtpm` integration, lint, format, type, security, and installed-package checks pass; the verifier prints `container smoke: PASS` and exits `0`. |
16
16
| Reviewer map |[Audit guide](docs/audit-guide.md) and [threat model](docs/threat-model.md)|
17
+
| Optional adversarial lab |[Runpod as an untrusted disposable holder](examples/runpod-untrusted-caller/README.md); excluded from the core assurance claim, with no Runpod resources or charges in ordinary CI. |
17
18
| Report a vulnerability | Follow the repository's [security policy](SECURITY.md). |
18
19
19
20
## What the experiment establishes
@@ -188,16 +189,38 @@ excludes the Linux-only `swtpm` profile; Compose is authoritative for that path.
0 commit comments