Add an updated security status document replacing the outdated phase 2-5 checklist as the immediate planning reference.
The document classifies each previously listed item as implemented, partial, or still pending based on direct source inspection, and highlights the urgent remaining work around AIO validation, /proc hardening, futex robustness, fixed virtual addresses, tmpfs hardening, socket copyout review, and kernel RNG quality.