engine

package
v0.1.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 1, 2026 License: Apache-2.0 Imports: 7 Imported by: 0

Documentation

Overview

Package engine contains the rule model, the rule registry and the scanning engine that turns rule issues into fully described findings.

Index

Constants

View Source
const (
	ReasonExcluded  = "excluded with --exclude"
	ReasonNotInOnly = "not selected with --only"
)

Skip reasons.

View Source
const DocsBaseURL = "https://github.com/6-SlX-6/stacksentry/blob/main/docs/rules.md"

DocsBaseURL is the location of the rule reference documentation.

Variables

This section is empty.

Functions

func BuildFinding

func BuildFinding(meta Metadata, issue Issue, scannerVersion string, ts time.Time) findings.Finding

BuildFinding combines rule metadata with a reported issue.

func ParseRuleIDs

func ParseRuleIDs(values []string) []string

ParseRuleIDs normalizes user supplied rule IDs. Each value may itself be a comma-separated list. IDs are trimmed, upper-cased and de-duplicated while preserving their first occurrence order.

func Select

func Select[T any](reg *Registry[T], sel Selection) (enabled []Rule[T], skipped []SkippedRule)

Select returns the rules to evaluate and the rules skipped by the selection. IDs that are not registered are ignored here; callers validate user input beforehand so that typos are reported as errors.

Types

type FuncRule

type FuncRule[T any] struct {
	Meta Metadata
	Fn   func(target T) []Issue
}

FuncRule adapts a plain function into a Rule.

func (FuncRule[T]) Check

func (r FuncRule[T]) Check(target T) []Issue

Check implements Rule.

func (FuncRule[T]) Metadata

func (r FuncRule[T]) Metadata() Metadata

Metadata implements Rule.

type Issue

type Issue struct {
	TargetType findings.TargetType
	TargetName string
	Location   *findings.Location
	Evidence   []string

	// Severity overrides the rule's default severity when set.
	Severity findings.Severity
	// Confidence defaults to high when empty.
	Confidence findings.Confidence
	// Description overrides the rule's generic description when set.
	Description string
	// Remediation overrides the rule's generic remediation when set.
	Remediation string
}

Issue is what a rule reports. Optional fields left at their zero value are filled from the rule's metadata when the engine builds the final finding.

type Metadata

type Metadata struct {
	ID          string
	Version     string
	Title       string
	Category    findings.Category
	Severity    findings.Severity
	Scope       Scope
	Description string
	Rationale   string
	Remediation string
	Detection   string
	Limitations string
	References  []string
}

Metadata describes a rule independently of its implementation. It is used to build findings and to render "stacksentry rules" output and docs.

func (Metadata) DocumentationURL

func (m Metadata) DocumentationURL() string

DocumentationURL returns the link to the rule's reference entry.

func (Metadata) Validate

func (m Metadata) Validate() error

Validate checks that the metadata is complete and well-formed.

type Registry

type Registry[T any] struct {
	// contains filtered or unexported fields
}

Registry holds the rules available for one scan scope.

func MustRegistry

func MustRegistry[T any](scope Scope, rules ...Rule[T]) *Registry[T]

MustRegistry is like NewRegistry but panics on invalid built-in rules. It is intended for package-level initialization of compiled-in rule sets, whose validity is enforced by unit tests.

func NewRegistry

func NewRegistry[T any](scope Scope, rules ...Rule[T]) (*Registry[T], error)

NewRegistry validates the rules' metadata and indexes them by ID.

func (*Registry[T]) Has

func (r *Registry[T]) Has(id string) bool

Has reports whether a rule with the given ID is registered.

func (*Registry[T]) Lookup

func (r *Registry[T]) Lookup(id string) (Rule[T], bool)

Lookup returns the rule with the given ID.

func (*Registry[T]) Metadata

func (r *Registry[T]) Metadata() []Metadata

Metadata returns the metadata of all rules sorted by ID.

func (*Registry[T]) Rules

func (r *Registry[T]) Rules() []Rule[T]

Rules returns all rules sorted by ID.

type Result

type Result struct {
	Findings   []findings.Finding
	Suppressed []SuppressedFinding
	Evaluated  []string
	Errors     []RuleError
}

Result is the outcome of evaluating a set of rules against one target.

func Run

func Run[T any](rules []Rule[T], target T, cfg RunConfig) Result

Run evaluates every rule against target. A rule that panics is recorded in Result.Errors and does not abort the scan. Findings are de-duplicated by fingerprint and returned in deterministic order.

type Rule

type Rule[T any] interface {
	Metadata() Metadata
	Check(target T) []Issue
}

Rule is a deterministic check against a scan target of type T.

type RuleError

type RuleError struct {
	RuleID  string
	Message string
}

RuleError records a rule that failed during evaluation.

func (RuleError) Error

func (e RuleError) Error() string

Error implements error.

type RunConfig

type RunConfig struct {
	ScannerVersion string
	Now            time.Time
	// Suppress optionally reports whether a finding was suppressed by the
	// scanned configuration itself, returning the documented reason.
	Suppress func(findings.Finding) (reason string, suppressed bool)
}

RunConfig carries scan-wide values stamped onto every finding.

type Scope

type Scope string

Scope identifies which kind of scan a rule belongs to.

const (
	ScopeCompose Scope = "compose"
	ScopeHost    Scope = "host"
)

Rule scopes.

type Selection

type Selection struct {
	Only    []string
	Exclude []string
}

Selection restricts which rules run. Only, when non-empty, is an allow list; Exclude is applied afterwards and always wins.

type SkippedRule

type SkippedRule struct {
	RuleID string `json:"rule_id"`
	Title  string `json:"title"`
	Reason string `json:"reason"`
}

SkippedRule records a rule that was not evaluated and why.

type SuppressedFinding

type SuppressedFinding struct {
	findings.Finding
	SuppressionReason string `json:"suppression_reason"`
}

SuppressedFinding is a finding that matched an explicit, documented exception in the scanned configuration.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL