Skip to content

Say "no shared host OS" rather than "no host" in §2.4 - #519

Closed
ulziibay-kernel wants to merge 1 commit into
mainfrom
hypeship/security-docs-isolation-boundary
Closed

ulziibay-kernel wants to merge 1 commit into
mainfrom
hypeship/security-docs-isolation-boundary

Conversation

@ulziibay-kernel

@ulziibay-kernel ulziibay-kernel commented Aug 27, 2026 •

Copy link
Copy Markdown
Contributor

What

One sentence in §2.4 Security Features:

There is no traditional host to escape to — the unikernel is the entire system for that session.

becomes

There is no shared host operating system to escape to — the unikernel is the entire operating system for that session, and the boundary beneath it is the hypervisor rather than a kernel shared with other tenants.

Why

The claim as written overstates the architecture. There is no host operating system shared with other tenants, which is the real and defensible point the paragraph is making. There is still a hypervisor and a physical host beneath every session.

The looser wording invites exactly the reading the paragraph is arguing against — that no boundary exists below the VM. That matters in two places:

  • Vulnerability triage. We treat escape from a session VM to the host or hypervisor as Critical and ask reporters to demonstrate it by reading a file on the host. A reporter can quote this sentence back at us to argue either that such an escape is impossible by construction, or that we contradict ourselves by paying for it. Neither conversation is one we want to have with someone holding a working escape.
  • Enterprise security review. "There is no host" reads as a stronger claim than we make anywhere else, and a reviewer who notices that we do in fact run a hypervisor has a reason to distrust the rest of the section.

The revised sentence keeps the comparison against containers intact — no shared kernel is the substantive difference — while naming the hypervisor as the boundary, which is what the first sentence of the same bullet already says.

Scope

Body text only. No headings changed, so the #2-4-security-features anchor is unaffected (verified against the rendered page, which is what our vulnerability disclosure policy links to).


Note

Low Risk
Documentation-only change to security marketing copy; no code or configuration impact.

Overview
§2.4 Unikernel Isolation wording is tightened so the doc no longer implies there is literally “no host” below a session.

The sentence now states there is no shared host operating system to escape to, that the unikernel is the entire operating system for the session, and that the hypervisor (not a kernel shared with other tenants) is the boundary underneath—aligning the bullet with the hypervisor-level isolation claim earlier in the same paragraph and avoiding an over-strong reading during VDP triage or enterprise review.

Reviewed by Cursor Bugbot for commit 148fa84. Bugbot is set up for automated code reviews on this repo. Configure here.

The sentence read "there is no traditional host to escape to," which
overstates the architecture: there is no host operating system shared
with other tenants, but there is a hypervisor and a physical host beneath
each session. The looser wording invites the reading that no boundary
exists below the VM, which is the opposite of what the paragraph is
arguing.
@mintlify

mintlify Bot commented Aug 27, 2026 •

Copy link
Copy Markdown
Contributor

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated (UTC)
Kernel 🟢 Ready View Preview Aug 27, 2026, 3:17 PM

💡 Tip: Enable Workflows to automatically generate PRs for you.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Risk assessment: Very Low

Verdict: Approve.

Inspected the actual diff (not the PR description). This PR changes one sentence in security.mdx §2.4:

  • Files: security.mdx only (+1 / −1)
  • Change: Rewords “no traditional host to escape to” to “no shared host operating system to escape to,” and names the hypervisor as the boundary beneath the unikernel.
  • Not changed: Code, config, CI, docs.json, navigation, headings/anchors, or LLM instruction files (AGENTS.md and similar).

Why Very Low

  • Documentation-only copy edit on a Mintlify page
  • No production logic, shared services, auth, or infrastructure impact
  • Blast radius is a single user-facing sentence; no behavior change

Ownership: No CODEOWNERS file; branch ruleset does not require code-owner review. No prior approvals on this PR.

Approved on that basis.

Open in Web View Automation 

Sent by Cursor Automation: Assign PR reviewers

This branch was successfully deployed

1 active deployment
staging — 148fa845 Deployed Aug 27, 2026 by mintlify[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant