You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
All 8 HIGH-severity findings are fixed and merged: #174 (release.yml || true), #175 (redundancy.hpp promote() race), #176 (udp.hpp/l2.hpp pending_key() truncation), #177 (loan.hpp use-after-free), #178 (.fusa.json ASIL-B→ASIL-C correction + HARA/SAFETY_PLAN staleness).
One MEDIUM finding (dangling REQ-SHMEM-009/REQ-SHMEM-010 test-tag references) was also incidentally fixed as part of #178's second commit (backfilled alongside REQ-RMAP-081/REQ-TIMED-012, discovered as a hard CI blocker) — not tracked below since it's already done.
Remaining (17)
MEDIUMinclude/rcp/respqueue.hpp:304 — RespQueue::plan_batch()'s budget parameter is decoupled from the ceiling push() actually enforced, so its 'always-fits' guarantee can be false
MEDIUMinclude/rcp/deadline.hpp:130 — deadline::Monitor uses unbounded std::map/std::vector, unlike its sibling watchdog::Manager which was explicitly hardened to fixed capacity in the same milestone
MEDIUMinclude/rcp/e2e.hpp:341 — apply_acf_length_adjustment() has no bounds check against the wire's 9-bit acf_msg_length field, silently corrupting the length of a maximal-size CRC-protected ACF message
MEDIUMinclude/rcp/server.hpp — server::Endpoint::submit() misclassifies a genuine timestamped ACF_GBB config-write as CompoundWait, based on raw timestamp byte content
MEDIUMinclude/rcp/uart.hpp:191 — REQ-UART-006's catalog text is false against current code and disproven by its own tagged test
MEDIUMinclude/rcp/config.hpp:398 — hw_pin_map_table.capacity set to populated-row count, contradicting TablePointer's own documented contract
MEDIUMinclude/rcp/rcp.hpp:6 — REQ-ERR-006's requirement text is unsatisfiable: mandates distinctness of ErrZoneMismatch, a sentinel deleted from the codebase
MEDIUMinclude/rcp/rcp.hpp:7 — REQ-ERR-007/008/009 describe closed-Controller/zone-lookup/zone-registration behavior that no longer exists; the only tagged test is a tautological category check
MEDIUMAUDIT_PACK.md:23 — AUDIT_PACK.md's requirement count (417/55 groups) is ~2.7x stale after the Phase 6 catalog re-derivation
MEDIUMREADME.md:14 — README.md's header index omits 18 of 58 headers, including every endpoint-type module, and understates the total as "~40"
MEDIUMROADMAP.md:2221 — ROADMAP.md milestone 68 ("GA v3.0.0") still claims no fragmentation support, contradicting the actual shipped v3.0.0 and the same document's own Phase 17 section
MEDIUMFORMAL_VERIFICATION.md:1 — FORMAL_VERIFICATION.md omits 2 of the 5 shipped TLA+ specs (LifecycleStateMachine.tla, E2ESafePoint.tla) — stale certification-evidence index
LOWinclude/rcp/acf.hpp:588 — decode_acf_messages() silently succeeds on a zero-length buffer, contradicting its own documented 'hard error' contract, and its 'empty buffer' test never actually passes an empty buffer
LOWtests/command_latency_test.cpp — command_latency_test.cpp's TEST_CASE name claims a P99 < 1ms budget it never actually asserts
LOWinclude/rcp/mock.hpp — dispatch_frame_impl() dispatches one fewer member than its own doc comment promises when a frame exceeds kMaxFrameMembers
LOWinclude/rcp/config.hpp:229 — config::detail::parse_server_fields silently truncates out-of-range vendor_id/device_id/magic instead of rejecting them, unlike parse_endpoint_entry's explicit byte_bus_id range check
Each item should get the same treatment as the HIGH batch: independent re-verification against current source before fixing, a real regression test, full rebuild+test (and sanitizer where relevant), and a scoped PR closing this issue's reference to it.
Background
A 14-cluster, adversarially-verified deep audit of cpp-RCP v3.0.0's full 182-file tree found 26 confirmed findings (0 refuted). Full report with evidence/file:line citations: https://claude.ai/code/artifact/1140e3ec-0ec6-4831-883e-579e202fb517
All 8 HIGH-severity findings are fixed and merged: #174 (release.yml
|| true), #175 (redundancy.hpppromote()race), #176 (udp.hpp/l2.hpppending_key()truncation), #177 (loan.hpp use-after-free), #178 (.fusa.jsonASIL-B→ASIL-C correction + HARA/SAFETY_PLAN staleness).One MEDIUM finding (dangling
REQ-SHMEM-009/REQ-SHMEM-010test-tag references) was also incidentally fixed as part of #178's second commit (backfilled alongsideREQ-RMAP-081/REQ-TIMED-012, discovered as a hard CI blocker) — not tracked below since it's already done.Remaining (17)
include/rcp/respqueue.hpp:304— RespQueue::plan_batch()'s budget parameter is decoupled from the ceiling push() actually enforced, so its 'always-fits' guarantee can be falseinclude/rcp/deadline.hpp:130— deadline::Monitor uses unbounded std::map/std::vector, unlike its sibling watchdog::Manager which was explicitly hardened to fixed capacity in the same milestoneinclude/rcp/e2e.hpp:341— apply_acf_length_adjustment() has no bounds check against the wire's 9-bit acf_msg_length field, silently corrupting the length of a maximal-size CRC-protected ACF messageinclude/rcp/server.hpp— server::Endpoint::submit() misclassifies a genuine timestamped ACF_GBB config-write as CompoundWait, based on raw timestamp byte contentinclude/rcp/uart.hpp:191— REQ-UART-006's catalog text is false against current code and disproven by its own tagged testinclude/rcp/config.hpp:398— hw_pin_map_table.capacity set to populated-row count, contradicting TablePointer's own documented contractinclude/rcp/rcp.hpp:6— REQ-ERR-006's requirement text is unsatisfiable: mandates distinctness of ErrZoneMismatch, a sentinel deleted from the codebaseinclude/rcp/rcp.hpp:7— REQ-ERR-007/008/009 describe closed-Controller/zone-lookup/zone-registration behavior that no longer exists; the only tagged test is a tautological category checkAUDIT_PACK.md:23— AUDIT_PACK.md's requirement count (417/55 groups) is ~2.7x stale after the Phase 6 catalog re-derivationREADME.md:14— README.md's header index omits 18 of 58 headers, including every endpoint-type module, and understates the total as "~40"ROADMAP.md:2221— ROADMAP.md milestone 68 ("GA v3.0.0") still claims no fragmentation support, contradicting the actual shipped v3.0.0 and the same document's own Phase 17 sectionCMakeLists.txt:16— Top-level add_compile_options() (including MSVC /WX) leaks into FetchContent-vendored Catch2 sourcesFORMAL_VERIFICATION.md:1— FORMAL_VERIFICATION.md omits 2 of the 5 shipped TLA+ specs (LifecycleStateMachine.tla, E2ESafePoint.tla) — stale certification-evidence indexinclude/rcp/acf.hpp:588— decode_acf_messages() silently succeeds on a zero-length buffer, contradicting its own documented 'hard error' contract, and its 'empty buffer' test never actually passes an empty buffertests/command_latency_test.cpp— command_latency_test.cpp's TEST_CASE name claims a P99 < 1ms budget it never actually assertsinclude/rcp/mock.hpp— dispatch_frame_impl() dispatches one fewer member than its own doc comment promises when a frame exceeds kMaxFrameMembersinclude/rcp/config.hpp:229— config::detail::parse_server_fields silently truncates out-of-range vendor_id/device_id/magic instead of rejecting them, unlike parse_endpoint_entry's explicit byte_bus_id range checkEach item should get the same treatment as the HIGH batch: independent re-verification against current source before fixing, a real regression test, full rebuild+test (and sanitizer where relevant), and a scoped PR closing this issue's reference to it.