Repository navigation
docs(skills): port adversarial-review and trust-boundary skills from runhold - #15
Merged
Merged
Conversation
Routes changed paths to go-style-guide and trust-boundary, lists this repo's invariants (no device grant without a /dev mount and an allow policy, append-only cgroup v2 programs with the daemon-reload exception, NVIDIA provenance of internal/cgroup) and the gates each path owes.
Rewritten from runhold's checklist for this daemon's real boundary: Docker labels, config values and flags turning into cgroup device rules. Cites the enforcing functions and tests, and records the current gaps (empty-mode test, unvalidated log keys, resolved paths not re-checked against /dev, dropped service labels on inspect failure, logging applied before reload validation, untested SIGHUP reload).
Adds sections 18 to 20 (comment rationale, classifying time.Sleep in tests, reuse before writing) after the internal/cgroup exemptions, with this repo's helpers and the 8 unclassified internal/daemon test sleeps as a follow-up. AGENTS.md now says when to load each skill and lists the quality rules no linter enforces.
7 of 11 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Ports the useful agent skills from runhold, adapted to this repository.
adversarial-review(new): the entry point for any review request. It keeps runhold's mindset, adversarial passes and report format, and rewrites the rest for this repo:go-style-guide; config, policy, rule collection,deployments/**andexamples/**go totrust-boundary;internal/cgroupcarries an NVIDIA provenance note;/devmount and an allow policy; cgroup v2 programs are append-only, with the deliberate daemon-reload re-apply exception; the depguard list;make go-test-integrationrather than rawgo test, which skips every test or runs a stale binary whendist/isn't freshly built.trust-boundary(new): rewritten for this daemon's real boundary, where Docker labels, config values and flags turn into cgroup device rules. It covers fail-closed modes, validation at load, labels as untrusted input,/dev-only rules, SIGHUP reload safety and image privilege, citing the enforcing functions and tests. It also records known gaps without changing code:log-formatandlog-levelare not validated;/dev(bounded today by globs on the resolved path);go-style-guide: new §18 (comments carry rationale), §19 (classifytime.Sleepin tests, listing the 7 unclassified sleeps ininternal/daemonas follow-up) and §20 (reuse before writing, a table of this repo's helpers).AGENTS.md: when to load each skill, plus the quality rules no linter enforces.Docs only; no code changes.
Pull request checklist
masterbranchmake checklocally before creating the commit and it has run successfullyWIPcommits in this PRType of changes