[roll] Roll fuchsia [starnix] Secure credentials write API

Introduce a safer, synchronized credentials write API for CurrentTask.

- Introduce `CurrentTaskCredentialsWriteGuard` to enforce synchronized
  updates of both objective and subjective (cached) credentials.
- Move `/proc/pid` ownership updates and override assertions into the
  safe `CurrentTask::write_creds` flow.
- Simplify call-sites (`set_creds`, `exec`) and remove `unsafe` blocks.

TAG=agy
CONV=3b364c05-3ddf-429a-9e33-872eb94d6d3e

Original-Original-Reviewed-on: https://fuchsia-review.googlesource.com/c/fuchsia/+/1648415
Original-Original-Revision: 0c592f0abf522c1ceec727719e1ba7b6ae714b1a
GitOrigin-RevId: e04874637552a3d10a048a2f78c7745ccf864a8a
Change-Id: I8f4ee84e6d4052153eaae17394ea39b7ca49077b
Reviewed-on: https://fuchsia-review.googlesource.com/c/integration/+/1651154
Cr-Commit-Position: refs/heads/main@{#194596}
1 file changed
tree: 0608c402696a9f5e7dbf6cdbaff1ba8e0595c9a9
  1. ctf/
  2. git-hooks/
  3. infra/
  4. third_party/
  5. cobalt
  6. flower
  7. jiri.lock
  8. MILESTONE
  9. minimal
  10. prebuilts
  11. README.md
  12. stem
  13. test_durations
README.md

Integration

This repository contains Fuchsia's Global Integration manifest files.

Making changes

All changes should be made to the internal version of this repository. Our infrastructure automatically updates this version when the internal one changes.

Currently all changes must be made by a Google employee. Non-Google employees wishing to make a change can ask for assistance in one of the communication channels documented at get involved.

Obtaining the source

First install Jiri.

Next run:

$ jiri init
$ jiri import minimal https://fuchsia.googlesource.com/integration
$ jiri update

Third party

Third party projects should have their own subdirectory in ./third_party.