analyzershell

package
v0.8.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 24, 2026 License: AGPL-3.0, AGPL-3.0-or-later Imports: 12 Imported by: 0

README

Shell analyzer candidate

analyzershell is an unregistered, unselected, Core-unreachable experimental native-Go candidate. It accepts only the shell family and shell.posix-bash input records containing caller-supplied POSIX/Bash source bytes. It statically emits the closed facts shell.import.static, shell.command.static, shell.env.read, shell.env.write, shell.trap.static, and shell.script.entry; dynamic shell forms reject the whole request.

It never opens input paths, follows symlinks, reads an environment, starts a process, sources/evaluates shell, accesses a network, or writes ambient state. The command only consumes bounded stdin and writes one canonical LF-framed JSON response. Registry, launch, admission, selection, packaging, and readiness are NOT_RUN.

The pinned fixture provenance is Beamfall Core da38c59eb30b2121cbac37b912485b30b2e54841, relay 9723152fdd4ead36b32553a171d98749e4fc23e9, and plugin SDK 5536ecde6d12214d6786a6832e537bd5d4feca02. These commits are inputs to future qualification only; this isolated candidate does not resolve, clone, or execute them.

Documentation

Overview

Package analyzershell is an isolated, static-only shell fact candidate.

Index

Constants

View Source
const (
	Profile                 = "corvint-analyzer-candidate/experimental"
	Family                  = "shell"
	MaxRequestBytes         = 1_500_000
	MaxInputBytes           = 1 << 20
	MaxOutputBytes          = 1 << 20
	MaxInputs               = 128
	MaxFeatures             = 64
	MaxAggregateBase64Bytes = 1_398_104
	MaxIdentifierBytes      = 128
	MaxPathBytes            = 4096
	MaxPathSegmentBytes     = 128
	MaxJSONDepth            = 8
	MaxJSONTokens           = 4096
	MaxFactFieldBytes       = 4096
	MaxFacts                = 3000
	MaxSourceBytes          = 65_536
	MaxBinaryBytes          = 6_291_456
	MaxBytesPerOp           = 130_000
	MaxAllocsPerOp          = 900
)

Variables

This section is empty.

Functions

func AnalyzeCanonical

func AnalyzeCanonical(raw []byte) []byte

AnalyzeCanonical never reads paths or executes shell; raw is the sole input.

Types

type Echo

type Echo struct {
	Handle string `json:"handle"`
	SHA256 string `json:"sha256"`
}

type Fact

type Fact struct {
	Kind           string `json:"kind"`
	InputHandle    string `json:"input_handle"`
	RelatedHandle  string `json:"related_handle"`
	Subject        string `json:"subject"`
	Predicate      string `json:"predicate"`
	Value          string `json:"value"`
	InstanceID     string `json:"instance_id"`
	EvidenceSHA256 string `json:"evidence_sha256"`
}

type Input

type Input struct {
	Handle        string `json:"handle"`
	Family        string `json:"family"`
	Path          string `json:"path"`
	SHA256        string `json:"sha256"`
	ContentBase64 string `json:"content_base64"`
}

type Request

type Request struct {
	Profile           string  `json:"profile"`
	Family            string  `json:"family"`
	RequestID         string  `json:"request_id"`
	ScopeID           string  `json:"scope_id"`
	CompilationUnitID string  `json:"compilation_unit_id"`
	Target            Target  `json:"target"`
	Inputs            []Input `json:"inputs"`
}

type Target

type Target struct {
	OS           string   `json:"os"`
	Architecture string   `json:"architecture"`
	ABI          string   `json:"abi"`
	Features     []string `json:"features"`
}

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL