Skip to content

docs(skills): port adversarial-review and trust-boundary skills from runhold - #15

Merged
leinardi merged 3 commits into
masterfrom
docs/port-runhold-skills
Sep 25, 2026
Merged

leinardi merged 3 commits into
masterfrom
docs/port-runhold-skills

Conversation

@leinardi

Copy link
Copy Markdown
Owner

Summary

Ports the useful agent skills from runhold, adapted to this repository.

  • adversarial-review (new): the entry point for any review request. It keeps runhold's mindset, adversarial passes and report format, and rewrites the rest for this repo:
    • routing: Go files go to go-style-guide; config, policy, rule collection, deployments/** and examples/** go to trust-boundary; internal/cgroup carries an NVIDIA provenance note;
    • invariants: no device grant without a /dev mount and an allow policy; cgroup v2 programs are append-only, with the deliberate daemon-reload re-apply exception; the depguard list;
    • gates: make go-test-integration rather than raw go test, which skips every test or runs a stale binary when dist/ isn't freshly built.
  • trust-boundary (new): rewritten for this daemon's real boundary, where Docker labels, config values and flags turn into cgroup device rules. It covers fail-closed modes, validation at load, labels as untrusted input, /dev-only rules, SIGHUP reload safety and image privilege, citing the enforcing functions and tests. It also records known gaps without changing code:
    • no test for an empty or unknown policy mode;
    • log-format and log-level are not validated;
    • resolved symlink targets are not re-checked against /dev (bounded today by globs on the resolved path);
    • service-level labels are dropped when a service inspect fails;
    • logging settings are applied before reload validation;
    • the SIGHUP reload path is untested.
  • go-style-guide: new §18 (comments carry rationale), §19 (classify time.Sleep in tests, listing the 7 unclassified sleeps in internal/daemon as follow-up) and §20 (reuse before writing, a table of this repo's helpers).
  • AGENTS.md: when to load each skill, plus the quality rules no linter enforces.

Docs only; no code changes.

Pull request checklist

  • I am targeting the master branch
  • I have rebased this branch on top of the destination branch
  • I have executed make check locally before creating the commit and it has run successfully
  • I have performed a self-review of my own code
  • There are no WIP commits in this PR

Type of changes

  • 🐛 Bug fix
  • ✨ New feature
  • 🔧 Refactoring
  • 📜 Docs
  • 🧰 CI / tooling / infra
  • Other (describe in Summary)

Routes changed paths to go-style-guide and trust-boundary, lists this repo's invariants (no device grant without a /dev mount and an allow policy, append-only cgroup v2 programs with the daemon-reload exception, NVIDIA provenance of internal/cgroup) and the gates each path owes.
Rewritten from runhold's checklist for this daemon's real boundary: Docker labels, config values and flags turning into cgroup device rules. Cites the enforcing functions and tests, and records the current gaps (empty-mode test, unvalidated log keys, resolved paths not re-checked against /dev, dropped service labels on inspect failure, logging applied before reload validation, untested SIGHUP reload).
Adds sections 18 to 20 (comment rationale, classifying time.Sleep in tests, reuse before writing) after the internal/cgroup exemptions, with this repo's helpers and the 8 unclassified internal/daemon test sleeps as a follow-up. AGENTS.md now says when to load each skill and lists the quality rules no linter enforces.
@leinardi
leinardi merged commit 6b47690 into master Sep 25, 2026
6 checks passed
@leinardi
leinardi deleted the docs/port-runhold-skills branch September 25, 2026 14:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant