detect

package
v0.2.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 27, 2026 License: Apache-2.0 Imports: 7 Imported by: 0

Documentation

Overview

Package detect is the agent-side detection engine (issue #422, phase 3). It runs ON THE AGENT: it consumes the per-class event stream from a DetectionSensor, evaluates the clean-room rule catalogue against each event, and emits a detection — with a bounded context window — for every match.

It is deterministic-first and observe-only: the engine matches typed rules and emits detections; it never executes anything (golden rule 1). It enforces a CPU ceiling by SHEDDING whole event classes in a defined order and reporting that it did, and it reports per-class coverage that folds in the sensor's gaps, its own shedding, and back-pressure drops — so a class the agent is not fully observing is never presented as clean.

Index

Constants

View Source
const DefaultContextWindow = 16

DefaultContextWindow is how many recent same-class events accompany a detection as bounded context.

Variables

This section is empty.

Functions

This section is empty.

Types

type Engine

type Engine struct {
	// contains filtered or unexported fields
}

Engine ties a sensor to the rule catalogue.

func NewEngine

func NewEngine(sensor ports.DetectionSensor, sink ports.DetectionSink, host, agentID shared.ID, opts Options) (*Engine, error)

NewEngine validates dependencies and loads the rule catalogue for the enabled classes.

func (*Engine) Coverage

func (e *Engine) Coverage() []detection.ClassCoverage

Coverage returns the honest per-class observation status: the sensor's coverage, with a class the engine has shed downgraded to a degraded gap, and a class the sensor is dropping under back-pressure likewise downgraded. A class the engine does not evaluate is never reported as cleanly observed.

func (*Engine) Run

func (e *Engine) Run(ctx context.Context) (err error)

Run starts the sensor and processes events until the context is cancelled or the sensor's event stream closes. It always closes the sensor on return. It is a single blocking call; do not call it twice.

func (*Engine) ShedLog

func (e *Engine) ShedLog() []ShedEvent

ShedLog returns the classes shed under load pressure, in order — the report that shedding occurred.

type LoadSampler

type LoadSampler interface {
	CPUPercent() float64
}

LoadSampler reports the CPU cost currently attributable to detection, as a percentage of one core. The engine samples it to decide whether to shed load. A real implementation reads getrusage; tests inject a deterministic one.

type Options

type Options struct {
	Classes        []detection.Class // classes to evaluate; defaults to all
	CPUCeilingPct  float64           // shed when the sampler exceeds this; 0 disables shedding
	Sampler        LoadSampler       // load source; nil → never sheds
	SampleInterval time.Duration     // minimum spacing between load samples; 0 → sample every event
	ContextWindow  int               // events of context kept per class; defaults to DefaultContextWindow
	Clock          ports.Clock
}

Options configures an engine.

type ShedEvent

type ShedEvent struct {
	Class      detection.Class
	At         time.Time
	CPUAtShed  float64
	CeilingPct float64
}

ShedEvent records that a class was shed to stay under the CPU ceiling, so the action is auditable and visible rather than a silent drop in coverage.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL