Skip to content

docs: accurate Windows sandbox terminology + roadmap entry#237

Merged
domcyrus merged 3 commits intomainfrom
docs/win-sandbox-accuracy
Apr 26, 2026
Merged

docs: accurate Windows sandbox terminology + roadmap entry#237
domcyrus merged 3 commits intomainfrom
docs/win-sandbox-accuracy

Conversation

@domcyrus
Copy link
Copy Markdown
Owner

"Restricted token" in Win32 means CreateRestrictedToken, which RustNet doesn't call. The actual mechanism is AdjustTokenPrivileges + a Job Object. Tightens README + SECURITY.md, and adds a ROADMAP item for further hardening (mitigation policies, low integrity, real restricted token, AppContainer).

@domcyrus domcyrus merged commit d1f184f into main Apr 26, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant