docs: reject the landstrip evaluation for the win32 sandbox rung
User verdict: landstrip is not battle-tested — a days-old, single-maintainer project (~48 GitHub stars at rejection), which a security-invariant dependency cannot be. The note moves proposed/feature -> rejected/feature with the verdict on the Status line; the sandbox note's deferred-phases cross-link now records the rejection instead of instructing an evaluation, and the NIH roll-up's pointer follows. Supersedes this branch's earlier cross-link commit.
This commit is contained in:
@@ -128,7 +128,7 @@ Each phase gets its full design when picked up, validated against the code at th
|
||||
|
||||
- **Second consumer** — `subagent-acp` optionally confines child agents (per-call policy; unconfined default — a child agent must write its own persistence).
|
||||
- **More environments** — an environment-coherent capability group example (e.g. bash+fs against one container).
|
||||
- **Windows chain** — `PLATFORM_CHAINS.win32` is reserved and empty (fail-closed); filling it means a confinement runner from the AppContainer/restricted-token family, shipped from its own repository on the `node-addon-landlock-run` template, plus its profile dialect and denial/runner-failure signatures. Before implementing this rung, complete the [landstrip evaluation gate](../../proposed/feature/2026-07-26-evaluate-landstrip-for-windows-sandbox-rung.md).
|
||||
- **Windows chain** — `PLATFORM_CHAINS.win32` is reserved and empty (fail-closed); filling it means a confinement runner from the AppContainer/restricted-token family, shipped from its own repository on the `node-addon-landlock-run` template, plus its profile dialect and denial/runner-failure signatures. Wrapping the third-party landstrip runner instead was [considered and rejected](../../rejected/feature/2026-07-26-evaluate-landstrip-for-windows-sandbox-rung.md) — not battle-tested enough for a security invariant.
|
||||
|
||||
## Alternatives considered
|
||||
|
||||
|
||||
Reference in New Issue
Block a user