Repository navigation
docs(runner): record R7 privilege-shape observations from a VM node - #1763
Merged
Merged
Conversation
…RIG-3723) Ran R7's six items with controls on an isolated rootful k3s node in a nested-KVM VM. The run does not meet R7's real-hardware bar, so R7 stays open. S1 shows the spec as written does not boot: passt and virtiofsd also need a user-namespaced pod with unmasked /proc, AppArmor unconfined, a node sysctl, and a world-rw /dev/kvm, which defeats the kvm-gid grant. Section Privilege shape is unchanged pending that decision. Spec-impact: none Refs RIG-3723 Co-authored-by: Matt Wilkinson <matt@rigel.build>
|
😎 This pull request was merged. |
Refs RIG-3723 Co-authored-by: Matt Wilkinson <matt@rigel.build>
|
Compass engineering docs preview: https://compass-managed-rig-3723-r7.compass-eng-docs.pages.dev Deployed from Changed pages: |
rigel-mintaka
marked this pull request as ready for review
October 6, 2026 04:00
This was referenced Oct 6, 2026
mattwilkinsonn
added this pull request to stack #1822
October 7, 2026 00:20
mattwilkinsonn
approved these changes
Oct 7, 2026
|
This pull request was merged into |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR is part of a stack containing 3 PRs:
mainSummary
This PR records the R7 privilege-shape items S1–S6, each with its negative control. The run used an isolated k3s node inside a nested-KVM VM, so R7 stays open until it is re-run on real hardware.
S1: the §Privilege shape as written does not boot. passt and virtiofsd sandboxing also need:
/proc;/dev/kvm, which defeats the kvm-gid grant.No capability and no
privilegedwas needed.S2–S6 support the record. hostPath fails
EPERM. The gid grant gatesEACCES. TheLocalhostseccomp profile is needed. Guest RAM is charged to the pod asshmem. A pid 1 kill strands zero processes.§Privilege shape is unchanged until the design decision is made.
Verification
rumdl checkis clean.Risks
None. This is a docs-only change.
Compatibility
No change.
Documentation
This PR is itself the documentation: it adds the results to
spike-findings.md.Refs RIG-3723