runtimeevidence

package
v0.2.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 26, 2026 License: Apache-2.0 Imports: 6 Imported by: 0

Documentation

Overview

Package runtimeevidence is the fleet ingest use case for host runtime-reachability evidence (EPIC #1042 #1060/#1061). A host agent ships the shared libraries it observed loaded plus the OS packages that own them; this use case resolves the agent's canonical host asset and its hidden vulnerability engagement, then joins the evidence to that engagement's findings by PACKAGE OWNERSHIP, raising (never suppressing) the finding for a vulnerable library that actually loaded.

It holds no judgment-minting authority of its own: the join and the raise-only judgment come from the injected runtime attributor (internal/usecase/runtimereach), so this package stays a thin, tenant-bound ingest boundary. It is composition-root-only and must never be reached from the agent tool catalog.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type Result

type Result struct {
	AssetID      shared.ID
	EngagementID shared.ID
	Minted       int
	// Coverage echoes the host's declared runtime-evidence gaps (no eBPF privilege, an unreadable package
	// database, an unsupported platform, a truncated sweep). It is carried back so the caller can record that
	// this host reports partial or no runtime evidence. Coverage never suppresses a finding (runtime
	// reachability is raise-only); it is observability, so the host's absence of evidence is honest, not silent.
	Coverage []runtimereach.CoverageReason
	// Pending is true when the host has no vulnerability engagement yet (its first SCA scan has not produced
	// findings). The evidence is dropped for this sync; because attribution is idempotent and supersede-only,
	// the agent's next report re-attributes against the populated findings. It is not an error.
	Pending bool
}

Result reports what an ingest produced, for the agent-plane response and the audit trail.

type Service

type Service struct {
	// contains filtered or unexported fields
}

Service ingests one agent's runtime-evidence report.

func NewService

func NewService(resolver assetResolver, engagements engagementResolver, attributor runtimeAttributor) (*Service, error)

NewService validates its dependencies and returns the ingest service.

func (*Service) Ingest

func (s *Service) Ingest(ctx context.Context, tenantID, agentID shared.ID, report runtimereach.Report) (Result, error)

Ingest resolves the agent's host asset and its hidden engagement, then attributes the runtime evidence to that engagement's findings. The tenant and agent identity come from the authenticated agent, never the body. A report with no evidence, or a host with no engagement yet, mints nothing and is not an error (runtime reachability is raise-only; its absence changes no verdict).

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL