Skip to content

docs(runner): record R7 privilege-shape observations from a VM node - #1763

Merged
trunk-io[bot] merged 2 commits into
mainfrom
compass-managed/rig-3723-r7-findings
Oct 7, 2026
Merged

trunk-io[bot] merged 2 commits into
mainfrom
compass-managed/rig-3723-r7-findings

Conversation

@rigel-mintaka

@rigel-mintaka rigel-mintaka commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

This PR is part of a stack containing 3 PRs:

  1. main
  2. "docs(runner): record R7 privilege-shape observations from a VM node" (this PR)
  3. docs(runner): adopt the user-namespaced pod shape from R7 #1771
  4. feat(runner): render the Runner DaemonSet and KVM device request #1773

Summary

This PR records the R7 privilege-shape items S1–S6, each with its negative control. The run used an isolated k3s node inside a nested-KVM VM, so R7 stays open until it is re-run on real hardware.

  • S1: the §Privilege shape as written does not boot. passt and virtiofsd sandboxing also need:

    • a user-namespaced pod with unmasked /proc;
    • AppArmor unconfined;
    • a node sysctl;
    • a world-rw /dev/kvm, which defeats the kvm-gid grant.

    No capability and no privileged was needed.

  • S2–S6 support the record. hostPath fails EPERM. The gid grant gates EACCES. The Localhost seccomp profile is needed. Guest RAM is charged to the pod as shmem. A pid 1 kill strands zero processes.

§Privilege shape is unchanged until the design decision is made.

Verification

  • Every claim was checked against captured evidence by three review rounds. Unverified items are marked as such.
  • rumdl check is clean.

Risks

None. This is a docs-only change.

Compatibility

No change.

Documentation

This PR is itself the documentation: it adds the results to spike-findings.md.

Refs RIG-3723

…RIG-3723)

Ran R7's six items with controls on an isolated rootful k3s node in a
nested-KVM VM. The run does not meet R7's real-hardware bar, so R7 stays
open. S1 shows the spec as written does not boot: passt and virtiofsd also
need a user-namespaced pod with unmasked /proc, AppArmor unconfined, a node
sysctl, and a world-rw /dev/kvm, which defeats the kvm-gid grant. Section
Privilege shape is unchanged pending that decision.

Spec-impact: none
Refs RIG-3723

Co-authored-by: Matt Wilkinson <matt@rigel.build>
@trunk-io

trunk-io Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

😎 This pull request was merged.

@linear-code

linear-code Bot commented Oct 6, 2026

Copy link
Copy Markdown

RIG-3723

Refs RIG-3723

Co-authored-by: Matt Wilkinson <matt@rigel.build>
@rigel-mintaka rigel-mintaka changed the title docs(runner): record R7 privilege-shape observations from a VM node (RIG-3723) docs(runner): record R7 privilege-shape observations from a VM node Oct 6, 2026
@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Compass engineering docs preview: https://compass-managed-rig-3723-r7.compass-eng-docs.pages.dev

Deployed from compass-managed/rig-3723-r7-findings at 1724ae6.

Changed pages:

@trunk-io

trunk-io Bot commented Oct 7, 2026

Copy link
Copy Markdown

This pull request is queued for merge as part of 1771, which will merge 1763, 1771.

@trunk-io
trunk-io Bot merged commit cb0c52b into main Oct 7, 2026
17 checks passed
@trunk-io
trunk-io Bot deleted the compass-managed/rig-3723-r7-findings branch October 7, 2026 02:07
@trunk-io

trunk-io Bot commented Oct 7, 2026

Copy link
Copy Markdown

This pull request was merged into main as part of stacked PR 1771.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants