feat(go): enrich snapshots with package ownership
This commit is contained in:
parent
6355fb403d
commit
88d7a6e3b8
8 changed files with 149 additions and 54 deletions
|
|
@ -1,8 +1,8 @@
|
|||
# Go Port Handoff
|
||||
|
||||
Saved: 2026-07-22T02:34:00-07:00
|
||||
Saved: 2026-07-22T02:48:00-07:00
|
||||
Branch: `main`
|
||||
Base commit: `eff31b3` (`feat(go): enrich snapshots asynchronously`)
|
||||
Base commit: `6355fb4` (`feat(go): expose retained incident views`)
|
||||
Status: implemented and green, but uncommitted
|
||||
|
||||
## Worktree warning
|
||||
|
|
@ -11,9 +11,9 @@ The checkout is intentionally dirty and contains work from multiple related
|
|||
continuations. Do not reset, clean, or broadly restage it.
|
||||
|
||||
- The validation-sidecar, incident-persistence, bounded-enrichment, local-
|
||||
assurance, and asynchronous-enrichment tranches are signed commits
|
||||
`f85c2e8`, `538d1d9`, `fd2bbba`, `1ab4add`, and `eff31b3`. The native
|
||||
incident-reader slice is uncommitted.
|
||||
assurance, asynchronous-enrichment, and incident-reader tranches are signed
|
||||
commits `f85c2e8`, `538d1d9`, `fd2bbba`, `1ab4add`, `eff31b3`, and
|
||||
`6355fb4`. The package-ownership enrichment slice is uncommitted.
|
||||
- At this checkpoint, `git status --short` has 20 entries with untracked
|
||||
directories collapsed.
|
||||
- The Python GUI files and tests are separate pre-existing work. Preserve them
|
||||
|
|
@ -103,8 +103,10 @@ static binary.
|
|||
- A single 16-job asynchronous worker now streams SHA-256 only for regular
|
||||
executables at most 8 MiB and adds lstat file metadata. Slow I/O occurs
|
||||
outside the snapshot lock; a full queue simply leaves optional fields unknown.
|
||||
- Package ownership, richer integrity anchors, and notification fan-out are not
|
||||
yet ported.
|
||||
- The asynchronous worker now resolves pacman/dpkg/rpm package-owner strings
|
||||
with a two-second bound and cache; ownership lookup never holds a detector
|
||||
lock or blocks alert capture.
|
||||
- Richer integrity anchors and notification fan-out are not yet ported.
|
||||
- `--incidents-list` and `--incident-show <id>` now read the sidecar's isolated
|
||||
state without starting the agent. The latter returns `enodia.incident.view.v1`
|
||||
with the incident, available snapshots, and time-ordered timeline.
|
||||
|
|
@ -152,8 +154,8 @@ the suite still exits successfully.
|
|||
|
||||
## Resume here
|
||||
|
||||
1. Add bounded package-ownership and integrity-anchor collectors to the existing
|
||||
asynchronous worker without destructive response behavior.
|
||||
1. Add bounded integrity-anchor collectors to the existing asynchronous worker
|
||||
without destructive response behavior.
|
||||
2. Add a read-only management API consumer for isolated Go snapshot/event state
|
||||
while keeping Python authoritative.
|
||||
3. Continue broader Phase 3 rule metadata/state parity before considering any
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue