Apply reviewed SACL plans to explicitly selected local targets (#422)

* Add reviewed configuration for selected native SACL targets

* Link selected SACL changelog to PR 422

* Identify native full-descriptor read failures without partial fallback

* Fix diagnostic variable scope in native C# helper

* Read explicit descriptor sections and retain observation scope
This commit is contained in:
田中ザック Isaac Mathis authored and GitHub committed 2026-09-20 19:36:05 +09:00
1 parent f1c1f74166
commit ff0e5c1890
14 files changed
+778 -4

No files matched your search

+6
View File
@@ -15,5 +15,11 @@
# Full upstream rule artifacts retain their exact pinned bytes on every platform.
/config/provider_rule_sources/*.yml -text whitespace=-blank-at-eol
# Selected SACL review plans pin these exact source bytes.
/config/audit_sacl_targets.json text eol=lf
/scripts/TargetedSaclPlanning.ps1 text eol=lf
/scripts/SelectedSaclConfiguration.ps1 text eol=lf
/scripts/SelectedSaclNative.cs text eol=lf
/modules/AuditCatalog.psm1 text eol=lf
# Fixed public pending-request fixture is pinned by its exact byte hash.
/tests/fixtures/adcs-pending-probe.csr text eol=lf