Complete final-revision compatibility regression testing

Complete a broad compatibility regression on the final NACRE prototype revision and determine whether the implemented protected fault, user-access, fork/COW, exec, teardown, and service paths operate correctly across a wider Linux-ABI test suite.

Background

The evaluation reports an eight-path functional regression, but that regression was performed on a revision preceding the final fork transaction. A separate protected-fork test covers the newer transaction but does not provide broad path coverage on the same revision.

Consequently, the prototype’s compatibility evidence is incomplete. The authors explicitly identify a complete broad regression on the final revision as still missing, particularly in light of incomplete Linux Test Project coverage.

References

A complete broad regression on the same revision remains missing.

NACRE: Rethinking Confidential Containers through Native Architectural Support  (2609.03849 - Song et al., 3 Sep 2026) in Section 7, subsection “RQ1: Which Linux Paths Does the Prototype Execute?”