# Changelog

## Score

- CAI 67 → 68 (+0.5)
- Rubric changed (rubric-2026.09.9 → rubric-2026.09.17) — scores are not directly comparable.

## Lenses

- Code Health 88 → 88 (+0.2)
- Architecture 77 → 77 (-0.2)
- Maturity 80 → 80 (+0.1)
- Readiness 71 → 69 (-1.9)
- Security 57 → 61 (+3.8)

## Resolved (9)

- Documentation: no installation or build instructions (README.md)
- Documentation: no licence statement (README.md)
- Documentation: no usage examples (README.md)
- Hotspot: crates/libcontainer/src/rootfs/utils.rs (crates/libcontainer/src/rootfs/utils.rs)
- Hotspot: crates/libcontainer/src/syscall/linux.rs (crates/libcontainer/src/syscall/linux.rs)
- Hotspot: crates/libcontainer/src/validator.rs (crates/libcontainer/src/validator.rs)
- Off-boarding risk: anonymized user #1
- TodoComment (tests/contest/contest/src/tests/checkpoint_restore/mod.rs)
- TodoComment (tests/contest/contest/src/tests/checkpoint_restore/mod.rs)

## New (14)

- Ambiguous naming for configuration application. `CgroupManager.apply` takes a high-level `ControllerOpt` struct, while `Devices.apply_devices` takes a raw device list. The verb 'apply' is used for both, but the semantic scope differs significantly (general controller config vs. specific device cgroup rules).
- Dependency hygiene PARTLY measured — Cargo dependencies read, dependency currency not (crates.io unreachable)
- End-of-life runtime: Rust 1.96
- Inconsistent naming for single vs. batch operations. `CgroupManager` uses `add_task` (singular) but provides no batch equivalent, while `Emulator` provides both `add_rule` (singular) and `add_rules` (batch). This creates an inconsistent pattern for collection-based mutations across the cgroup module.
- Low cohesion: ContainerBuilder (LCOM4 9) (crates/libcontainer/src/container/builder.rs)
- Low cohesion: SELinux (LCOM4 16) (experiment/selinux/src/selinux.rs)
- Medium vulnerability: RUSTSEC-2026-0285 (Cargo.lock)
- Medium vulnerability: RUSTSEC-2026-0316 (Cargo.lock)
- Off the main sequence: libcgroups
- Off the main sequence: liboci-cli
- Off-boarding risk: anonymized user #1
- Projects may be oversized for their cohesion
- Redundant functionality between instance method and free function. `CgroupManager.get_all_pids` retrieves PIDs for the manager's cgroup, while `common.get_all_pids` takes a path. Since `CgroupManager` already exposes the path (via `cgroup_path` in `CgroupConfig` or internal state), the free function duplicates the capability of the instance method for a specific path.
- TodoComment (tests/contest/contest/src/tests/checkpoint_restore/mod.rs)

## Changes since last survey

- 17 commits — 14 feature/other, 3 fixes

## By area

- tests/contest — 10 commits
- (root) — 3 commits
- (repo) — 2 commits
- .github/workflows — 1 commit
- crates/libcontainer — 1 commit

## Notable commits

- fix: fix(contest): mask /sys/firmware instead of /proc/acpi in mount_test (#3742)
- fix: fix(contest): skip memory_policy tests that need NUMA (#3739)
- fix: fix(contest): skip rsvd hugetlb test when hugetlb is unavailable (#3734)
- change: Merge pull request #3748 from youki-dev/dependabot/cargo/patch-8f8f13f3a4
- change: Merge pull request #3759 from youki-dev/dependabot/cargo/patch-d3036c01b2
- change: chore(deps): bump rand from 0.10.2 to 0.10.3 in the patch group
- change: chore(deps): bump thiserror from 2.0.20 to 2.0.21 in the patch group
- change: chore(deps): bump uuid from 1.26.0 to 1.26.1 in the patch group (#3728)
- change: ci: run contest integration tests on aarch64 (#3738)
- change: feat: implement OCI per-mount propagation options (#3699)
- change: harden mount source (#3745)
- change: refact: utility function for check whether the cgroup v2 interface file exists (#3737)
- change: refactor(contest): extract run_container_with_console helper into test_utils (#3693)
- change: refactor: extract can_run into a helper utility for cgroups v2 tests (#3736)
- change: remove cgroupv1 test (#3727)
- change: test(contest): add cgroup v2 memory integration tests (#3725)
- change: test(contest): add cgroup v2 pids integration tests (#3741)
