ingest

package
v1.13.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 8, 2026 License: Apache-2.0 Imports: 19 Imported by: 0

Documentation

Index

Constants

View Source
const (
	StateRetentionUnknown            = "unknown"
	StateRetentionEphemeral          = "ephemeral"
	StateRetentionRetained           = "retained"
	StateRetentionRetainedWithExpiry = "retained_with_expiry"
	StateRetentionOperatorManaged    = "operator_managed"
)
View Source
const (
	RecordKindRuntime         = "runtime"
	RecordKindExternalControl = "external_control"

	EvidenceClassPolicyDecision                    = "policy_decision"
	EvidenceClassApproval                          = "approval"
	EvidenceClassJITCredential                     = "jit_credential" // #nosec G101 -- Deterministic runtime evidence label, not credential material.
	EvidenceClassFreezeWindow                      = "freeze_window"
	EvidenceClassKillSwitch                        = "kill_switch"
	EvidenceClassStopRequest                       = "stop_request"
	EvidenceClassCoveredActionDenial               = "covered_action_denial"
	EvidenceClassCapabilityInvalidation            = "capability_invalidation"
	EvidenceClassDescendantInvalidation            = "descendant_invalidation"
	EvidenceClassExternalRevocationAttempt         = "external_revocation_attempt"
	EvidenceClassExternalRevocationAcknowledgement = "external_revocation_acknowledgement"
	EvidenceClassContainmentReceipt                = "containment_receipt"
	EvidenceClassActionOutcome                     = "action_outcome"
	EvidenceClassProofVerify                       = "proof_verification"
	EvidenceClassOwnerAssignment                   = "owner_assignment"
	EvidenceClassPolicyRecord                      = "policy_record"
	EvidenceClassBranchProtection                  = "branch_protection"
	EvidenceClassProtectedEnvironment              = "protected_environment"
	EvidenceClassDeploymentApproval                = "deployment_approval"
	EvidenceClassRequiredCheck                     = "required_check"
	EvidenceClassSecurityGate                      = "security_gate"
	EvidenceClassWorkflowPermission                = "workflow_permission"
	EvidenceClassMergeMetadata                     = "merge_metadata"
	EvidenceClassOther                             = "other"
	CorrelationStatusMatched                       = "matched"
	CorrelationStatusUnmatched                     = "unmatched"
	CorrelationStatusStale                         = "stale"
	CorrelationStatusConflict                      = "conflict"
	ContainmentStatusContained                     = "contained"
	ContainmentStatusPartial                       = "partially_contained"
	ContainmentStatusUnresolved                    = "unresolved"
	ContainmentStatusOutOfScope                    = "out_of_scope"
)
View Source
const (
	SessionProviderCodex      = "codex"
	SessionProviderClaudeCode = "claude_code"
	SessionProviderCursor     = "cursor"
	SessionProviderCopilot    = "copilot"
	SessionProviderGait       = "gait"
	SessionProviderUnknown    = "unknown"
)
View Source
const EvidencePacketSchemaVersion = "v1"
View Source
const SchemaVersion = "v1"
View Source
const SessionSchemaVersion = "v1"

Variables

This section is empty.

Functions

func ApplyActionContractLifecycleEvidence added in v1.12.0

func ApplyActionContractLifecycleEvidence(snapshot state.Snapshot, bundle Bundle) state.Snapshot

ApplyActionContractLifecycleEvidence returns a detached snapshot projection. It records imported Gait/Axym evidence without mutating saved state or the immutable proposed Action Contract identity.

func DefaultEvidencePacketPath added in v1.6.0

func DefaultEvidencePacketPath(statePath string) string

func DefaultPath

func DefaultPath(statePath string) string

func DefaultSessionPath added in v1.6.0

func DefaultSessionPath(statePath string) string

func IsUnrecognizedSessionArtifact added in v1.6.0

func IsUnrecognizedSessionArtifact(err error) bool

func Save

func Save(path string, bundle Bundle) error

func SaveEvidencePacketBundle added in v1.6.0

func SaveEvidencePacketBundle(path string, bundle EvidencePacketBundle) error

func SaveSessionBundle added in v1.6.0

func SaveSessionBundle(path string, bundle SessionBundle) error

func ValidateEvidencePacketJSON added in v1.6.0

func ValidateEvidencePacketJSON(payload []byte) error

func ValidateExternalControlEvidenceJSON added in v1.6.0

func ValidateExternalControlEvidenceJSON(payload []byte) error

func ValidateSessionJSON added in v1.6.0

func ValidateSessionJSON(payload []byte) error

Types

type Bundle

type Bundle struct {
	SchemaVersion string   `json:"schema_version"`
	GeneratedAt   string   `json:"generated_at"`
	Records       []Record `json:"records"`
}

func Load

func Load(path string) (Bundle, error)

func LoadOptional

func LoadOptional(statePath string) (Bundle, string, error)

func MergeRuntimeBundles added in v1.6.0

func MergeRuntimeBundles(bundles ...Bundle) Bundle

func Normalize

func Normalize(bundle Bundle) (Bundle, error)

func ProjectSessionsToRuntimeBundle added in v1.6.0

func ProjectSessionsToRuntimeBundle(bundle SessionBundle) Bundle

type Correlation

type Correlation struct {
	PathID                   string   `json:"path_id"`
	AgentID                  string   `json:"agent_id,omitempty"`
	RecordKinds              []string `json:"record_kinds,omitempty"`
	SourceTypes              []string `json:"source_types,omitempty"`
	Tool                     string   `json:"tool,omitempty"`
	Repo                     string   `json:"repo,omitempty"`
	Service                  string   `json:"service,omitempty"`
	Workflow                 string   `json:"workflow,omitempty"`
	Environment              string   `json:"environment,omitempty"`
	Path                     string   `json:"path,omitempty"`
	Location                 string   `json:"location,omitempty"`
	Target                   string   `json:"target,omitempty"`
	Status                   string   `json:"status"`
	EvidenceClasses          []string `json:"evidence_classes,omitempty"`
	ActionClasses            []string `json:"action_classes,omitempty"`
	Sources                  []string `json:"sources,omitempty"`
	PolicyRefs               []string `json:"policy_refs,omitempty"`
	ProofRefs                []string `json:"proof_refs,omitempty"`
	GraphNodeRefs            []string `json:"graph_node_refs,omitempty"`
	GraphEdgeRefs            []string `json:"graph_edge_refs,omitempty"`
	RecordIDs                []string `json:"record_ids,omitempty"`
	RequiredChecks           []string `json:"required_checks,omitempty"`
	Owners                   []string `json:"owners,omitempty"`
	UnmatchedReasons         []string `json:"unmatched_reasons,omitempty"`
	LatestObservedAt         string   `json:"latest_observed_at,omitempty"`
	FreshnessState           string   `json:"freshness_state,omitempty"`
	FreshnessStates          []string `json:"freshness_states,omitempty"`
	BoundaryLabel            string   `json:"boundary_label,omitempty"`
	ContainmentStatus        string   `json:"containment_status,omitempty"`
	ContainmentScopeRefs     []string `json:"containment_scope_refs,omitempty"`
	AcknowledgedBoundaryRefs []string `json:"acknowledged_boundary_refs,omitempty"`
	UnresolvedBoundaryRefs   []string `json:"unresolved_boundary_refs,omitempty"`
	OutOfScopeBoundaryRefs   []string `json:"out_of_scope_boundary_refs,omitempty"`
}

type EvidencePacket added in v1.6.0

type EvidencePacket struct {
	PacketID                 string   `json:"packet_id,omitempty"`
	Source                   string   `json:"source"`
	SourceType               string   `json:"source_type,omitempty"`
	Provider                 string   `json:"provider,omitempty"`
	ProviderURL              string   `json:"provider_url,omitempty"`
	Repo                     string   `json:"repo,omitempty"`
	Workflow                 string   `json:"workflow,omitempty"`
	PathID                   string   `json:"path_id,omitempty"`
	AgentID                  string   `json:"agent_id,omitempty"`
	PullRequestRef           string   `json:"pull_request_ref,omitempty"`
	Owner                    string   `json:"owner,omitempty"`
	Task                     string   `json:"task,omitempty"`
	Title                    string   `json:"title,omitempty"`
	FilesTouched             []string `json:"files_touched,omitempty"`
	DiffRefs                 []string `json:"diff_refs,omitempty"`
	DiffDigests              []string `json:"diff_digests,omitempty"`
	AutonomyTier             string   `json:"autonomy_tier,omitempty"`
	DelegationReadinessState string   `json:"delegation_readiness_state,omitempty"`
	Permissions              []string `json:"permissions,omitempty"`
	Credentials              []string `json:"credentials,omitempty"`
	Tests                    []string `json:"tests,omitempty"`
	Reviewers                []string `json:"reviewers,omitempty"`
	Approvals                []string `json:"approvals,omitempty"`
	DeploymentEnvironments   []string `json:"deployment_environments,omitempty"`
	PolicyVerdict            string   `json:"policy_verdict,omitempty"`
	ExceptionRefs            []string `json:"exception_refs,omitempty"`
	Result                   string   `json:"result,omitempty"`
	MissingEvidenceState     string   `json:"missing_evidence_state,omitempty"`
	MissingEvidence          []string `json:"missing_evidence,omitempty"`
	RuntimeProvider          string   `json:"runtime_provider,omitempty"`
	RuntimeHost              string   `json:"runtime_host,omitempty"`
	RuntimeKind              string   `json:"runtime_kind,omitempty"`
	ModelProvider            string   `json:"model_provider,omitempty"`
	ModelVersion             string   `json:"model_version,omitempty"`
	ExecutionEnvironment     string   `json:"execution_environment,omitempty"`
	StateRetentionStatus     string   `json:"state_retention_status,omitempty"`
	RetainedStateTypes       []string `json:"retained_state_types,omitempty"`
	StateLocationRefs        []string `json:"state_location_refs,omitempty"`
	StateDigestRefs          []string `json:"state_digest_refs,omitempty"`
	ProofRefs                []string `json:"proof_refs,omitempty"`
	GraphNodeRefs            []string `json:"graph_node_refs,omitempty"`
	GraphEdgeRefs            []string `json:"graph_edge_refs,omitempty"`
	EvidenceRefs             []string `json:"evidence_refs,omitempty"`
	ObservedAt               string   `json:"observed_at"`
	RedactionHints           []string `json:"redaction_hints,omitempty"`
}

type EvidencePacketBundle added in v1.6.0

type EvidencePacketBundle struct {
	SchemaVersion string           `json:"schema_version"`
	GeneratedAt   string           `json:"generated_at"`
	Packets       []EvidencePacket `json:"packets"`
}

func LoadEvidencePacketBundle added in v1.6.0

func LoadEvidencePacketBundle(path string) (EvidencePacketBundle, error)

func LoadOptionalEvidencePacketBundle added in v1.6.0

func LoadOptionalEvidencePacketBundle(statePath string) (EvidencePacketBundle, string, error)

func MergeEvidencePacketBundles added in v1.6.0

func MergeEvidencePacketBundles(bundles ...EvidencePacketBundle) EvidencePacketBundle

func NormalizeEvidencePacketBundle added in v1.6.0

func NormalizeEvidencePacketBundle(bundle EvidencePacketBundle) (EvidencePacketBundle, error)

func ProjectSessionsToEvidencePacketBundle added in v1.6.0

func ProjectSessionsToEvidencePacketBundle(bundle SessionBundle) EvidencePacketBundle

type EvidencePacketCorrelation added in v1.6.0

type EvidencePacketCorrelation struct {
	PacketID             string   `json:"packet_id"`
	PathID               string   `json:"path_id,omitempty"`
	AgentID              string   `json:"agent_id,omitempty"`
	Repo                 string   `json:"repo,omitempty"`
	Workflow             string   `json:"workflow,omitempty"`
	PullRequestRef       string   `json:"pull_request_ref,omitempty"`
	BoundaryLabel        string   `json:"boundary_label,omitempty"`
	Status               string   `json:"status"`
	Result               string   `json:"result,omitempty"`
	MissingEvidenceState string   `json:"missing_evidence_state,omitempty"`
	RuntimeProvider      string   `json:"runtime_provider,omitempty"`
	RuntimeHost          string   `json:"runtime_host,omitempty"`
	RuntimeKind          string   `json:"runtime_kind,omitempty"`
	ModelProvider        string   `json:"model_provider,omitempty"`
	ModelVersion         string   `json:"model_version,omitempty"`
	ExecutionEnvironment string   `json:"execution_environment,omitempty"`
	StateRetentionStatus string   `json:"state_retention_status,omitempty"`
	RetainedStateTypes   []string `json:"retained_state_types,omitempty"`
	StateLocationRefs    []string `json:"state_location_refs,omitempty"`
	StateDigestRefs      []string `json:"state_digest_refs,omitempty"`
	ProofRefs            []string `json:"proof_refs,omitempty"`
	GraphNodeRefs        []string `json:"graph_node_refs,omitempty"`
	GraphEdgeRefs        []string `json:"graph_edge_refs,omitempty"`
	EvidenceRefs         []string `json:"evidence_refs,omitempty"`
	MissingEvidence      []string `json:"missing_evidence,omitempty"`
}

type EvidencePacketSummary added in v1.6.0

type EvidencePacketSummary struct {
	ArtifactPath     string                      `json:"artifact_path,omitempty"`
	BoundaryLabel    string                      `json:"boundary_label,omitempty"`
	TotalPackets     int                         `json:"total_packets"`
	MatchedPackets   int                         `json:"matched_packets"`
	UnmatchedPackets int                         `json:"unmatched_packets"`
	Correlations     []EvidencePacketCorrelation `json:"correlations,omitempty"`
}

func CorrelateEvidencePackets added in v1.6.0

func CorrelateEvidencePackets(snapshot state.Snapshot, artifactPath string, bundle EvidencePacketBundle) EvidencePacketSummary

type Record

type Record struct {
	RecordKind                string   `json:"record_kind,omitempty"`
	SourceType                string   `json:"source_type,omitempty"`
	SourcePrecedenceKey       string   `json:"source_precedence_key,omitempty"`
	RecordID                  string   `json:"record_id"`
	PathID                    string   `json:"path_id,omitempty"`
	ResolutionKey             string   `json:"resolution_key,omitempty"`
	AgentID                   string   `json:"agent_id,omitempty"`
	Tool                      string   `json:"tool,omitempty"`
	Repo                      string   `json:"repo,omitempty"`
	Service                   string   `json:"service,omitempty"`
	Workflow                  string   `json:"workflow,omitempty"`
	Environment               string   `json:"environment,omitempty"`
	Path                      string   `json:"path,omitempty"`
	Location                  string   `json:"location,omitempty"`
	Target                    string   `json:"target,omitempty"`
	ActionClasses             []string `json:"action_classes,omitempty"`
	PolicyRef                 string   `json:"policy_ref,omitempty"`
	ProofRef                  string   `json:"proof_ref,omitempty"`
	GraphNodeRefs             []string `json:"graph_node_refs,omitempty"`
	GraphEdgeRefs             []string `json:"graph_edge_refs,omitempty"`
	Source                    string   `json:"source"`
	Issuer                    string   `json:"issuer,omitempty"`
	ObservedAt                string   `json:"observed_at"`
	ValidUntil                string   `json:"valid_until,omitempty"`
	MaxAge                    string   `json:"max_age,omitempty"`
	Confidence                string   `json:"confidence,omitempty"`
	FreshnessState            string   `json:"freshness_state,omitempty"`
	RedactionHints            []string `json:"redaction_hints,omitempty"`
	EvidenceClass             string   `json:"evidence_class"`
	Status                    string   `json:"status,omitempty"`
	EvidenceRefs              []string `json:"evidence_refs,omitempty"`
	Owner                     string   `json:"owner,omitempty"`
	RequiredChecks            []string `json:"required_checks,omitempty"`
	Branch                    string   `json:"branch,omitempty"`
	ProposedActionContractRef string   `json:"proposed_action_contract_ref,omitempty"`
	ContractFamilyID          string   `json:"contract_family_id,omitempty"`
	ContractRevision          int      `json:"contract_revision,omitempty"`
	ActionContractArtifactRef string   `json:"action_contract_artifact_ref,omitempty"`
	ActionContractEvent       string   `json:"action_contract_event,omitempty"`
	Producer                  string   `json:"producer,omitempty"`
	EvidenceState             string   `json:"evidence_state,omitempty"`
	ReasonCodes               []string `json:"reason_codes,omitempty"`
	ContainmentStatus         string   `json:"containment_status,omitempty"`
	ContainmentScopeRefs      []string `json:"containment_scope_refs,omitempty"`
	AcknowledgedBoundaryRefs  []string `json:"acknowledged_boundary_refs,omitempty"`
	UnresolvedBoundaryRefs    []string `json:"unresolved_boundary_refs,omitempty"`
	OutOfScopeBoundaryRefs    []string `json:"out_of_scope_boundary_refs,omitempty"`
}

type SessionBundle added in v1.6.0

type SessionBundle struct {
	SchemaVersion string          `json:"schema_version"`
	GeneratedAt   string          `json:"generated_at"`
	Sessions      []SessionRecord `json:"sessions"`
}

func LoadOptionalSessionBundle added in v1.6.0

func LoadOptionalSessionBundle(statePath string) (SessionBundle, string, error)

func LoadSessionBundle added in v1.6.0

func LoadSessionBundle(path string) (SessionBundle, error)

func NormalizeSessionBundle added in v1.6.0

func NormalizeSessionBundle(bundle SessionBundle) (SessionBundle, error)

func ParseSessionBundleJSON added in v1.6.0

func ParseSessionBundleJSON(payload []byte) (SessionBundle, error)

type SessionCorrelation added in v1.6.0

type SessionCorrelation struct {
	SessionID            string   `json:"session_id"`
	PathID               string   `json:"path_id,omitempty"`
	AgentID              string   `json:"agent_id,omitempty"`
	Provider             string   `json:"provider,omitempty"`
	RunID                string   `json:"run_id,omitempty"`
	Repo                 string   `json:"repo,omitempty"`
	Workflow             string   `json:"workflow,omitempty"`
	PullRequestRef       string   `json:"pull_request_ref,omitempty"`
	MergeRequestRef      string   `json:"merge_request_ref,omitempty"`
	BoundaryLabel        string   `json:"boundary_label,omitempty"`
	Status               string   `json:"status"`
	Outcome              string   `json:"outcome,omitempty"`
	PromptRef            string   `json:"prompt_ref,omitempty"`
	ResponseRef          string   `json:"response_ref,omitempty"`
	RuntimeProvider      string   `json:"runtime_provider,omitempty"`
	RuntimeHost          string   `json:"runtime_host,omitempty"`
	RuntimeKind          string   `json:"runtime_kind,omitempty"`
	ModelProvider        string   `json:"model_provider,omitempty"`
	ModelVersion         string   `json:"model_version,omitempty"`
	ExecutionEnvironment string   `json:"execution_environment,omitempty"`
	StateRetentionStatus string   `json:"state_retention_status,omitempty"`
	RetainedStateTypes   []string `json:"retained_state_types,omitempty"`
	StateLocationRefs    []string `json:"state_location_refs,omitempty"`
	StateDigestRefs      []string `json:"state_digest_refs,omitempty"`
	ObservedActions      []string `json:"observed_actions,omitempty"`
	ChangedFiles         []string `json:"changed_files,omitempty"`
	FileWrites           []string `json:"file_writes,omitempty"`
	Approvals            []string `json:"approvals,omitempty"`
	PolicyDecisions      []string `json:"policy_decisions,omitempty"`
	ProofRefs            []string `json:"proof_refs,omitempty"`
	GraphNodeRefs        []string `json:"graph_node_refs,omitempty"`
	GraphEdgeRefs        []string `json:"graph_edge_refs,omitempty"`
	SourceArtifactRefs   []string `json:"source_artifact_refs,omitempty"`
	RedactionHints       []string `json:"redaction_hints,omitempty"`
}

type SessionRecord added in v1.6.0

type SessionRecord struct {
	SessionID            string   `json:"session_id,omitempty"`
	Provider             string   `json:"provider"`
	RunID                string   `json:"run_id,omitempty"`
	Status               string   `json:"status,omitempty"`
	PathID               string   `json:"path_id,omitempty"`
	AgentID              string   `json:"agent_id,omitempty"`
	Repo                 string   `json:"repo,omitempty"`
	Workflow             string   `json:"workflow,omitempty"`
	PullRequestRef       string   `json:"pull_request_ref,omitempty"`
	MergeRequestRef      string   `json:"merge_request_ref,omitempty"`
	AuthorRefs           []string `json:"author_refs,omitempty"`
	ReviewerRefs         []string `json:"reviewer_refs,omitempty"`
	Tool                 string   `json:"tool,omitempty"`
	ProviderURL          string   `json:"provider_url,omitempty"`
	PromptRef            string   `json:"prompt_ref,omitempty"`
	ResponseRef          string   `json:"response_ref,omitempty"`
	ChangedFiles         []string `json:"changed_files,omitempty"`
	Commands             []string `json:"commands,omitempty"`
	Actions              []string `json:"actions,omitempty"`
	FileWrites           []string `json:"file_writes,omitempty"`
	Approvals            []string `json:"approvals,omitempty"`
	PolicyDecisions      []string `json:"policy_decisions,omitempty"`
	CredentialSubjects   []string `json:"credential_subjects,omitempty"`
	Declarations         []string `json:"declarations,omitempty"`
	ProofRefs            []string `json:"proof_refs,omitempty"`
	GraphNodeRefs        []string `json:"graph_node_refs,omitempty"`
	GraphEdgeRefs        []string `json:"graph_edge_refs,omitempty"`
	Outcome              string   `json:"outcome,omitempty"`
	StartedAt            string   `json:"started_at,omitempty"`
	CompletedAt          string   `json:"completed_at,omitempty"`
	RuntimeProvider      string   `json:"runtime_provider,omitempty"`
	RuntimeHost          string   `json:"runtime_host,omitempty"`
	RuntimeKind          string   `json:"runtime_kind,omitempty"`
	ModelProvider        string   `json:"model_provider,omitempty"`
	ModelVersion         string   `json:"model_version,omitempty"`
	ExecutionEnvironment string   `json:"execution_environment,omitempty"`
	StateRetentionStatus string   `json:"state_retention_status,omitempty"`
	RetainedStateTypes   []string `json:"retained_state_types,omitempty"`
	StateLocationRefs    []string `json:"state_location_refs,omitempty"`
	StateDigestRefs      []string `json:"state_digest_refs,omitempty"`
	SourceArtifactRefs   []string `json:"source_artifact_refs,omitempty"`
	RedactionHints       []string `json:"redaction_hints,omitempty"`
}

type SessionSummary added in v1.6.0

type SessionSummary struct {
	ArtifactPath       string               `json:"artifact_path,omitempty"`
	BoundaryLabel      string               `json:"boundary_label,omitempty"`
	TotalSessions      int                  `json:"total_sessions"`
	MatchedSessions    int                  `json:"matched_sessions"`
	UnmatchedSessions  int                  `json:"unmatched_sessions"`
	StaleSessions      int                  `json:"stale_sessions,omitempty"`
	ConflictingSession int                  `json:"conflicting_sessions,omitempty"`
	Correlations       []SessionCorrelation `json:"correlations,omitempty"`
}

func CorrelateSessions added in v1.6.0

func CorrelateSessions(snapshot state.Snapshot, artifactPath string, bundle SessionBundle) SessionSummary

type Summary

type Summary struct {
	ArtifactPath           string        `json:"artifact_path,omitempty"`
	BoundaryLabel          string        `json:"boundary_label,omitempty"`
	TotalRecords           int           `json:"total_records"`
	RuntimeRecords         int           `json:"runtime_records,omitempty"`
	ExternalControlRecords int           `json:"external_control_records,omitempty"`
	MatchedRecords         int           `json:"matched_records"`
	UnmatchedRecords       int           `json:"unmatched_records"`
	Correlations           []Correlation `json:"correlations,omitempty"`
}

func Correlate

func Correlate(snapshot state.Snapshot, artifactPath string, bundle Bundle) Summary

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL