feat(go): port FIM/pkgdb/rootcheck integrity engines and add go-sidecar dashboard consumer

Adds sidecar-only, --state-dir-gated FIM, package-DB-anchor, and rootcheck
engines to the Go migration sidecar, wired into agent.Sweep/Initialize
behind the existing baseline lifecycle. Adds a read-only, schema-checked
Python dashboard consumer (go_sidecar_state_dir, /api/go-sidecar/*, Sidecar
tab) that never starts, stops, or mutates the Go sidecar's state.

Also fixes drift found while reconciling this work: enodia_sentinel/web.py
had reinvented local schema constants instead of using the canonical
enodia_sentinel/schemas.py catalog (now registers enodia.go.sidecar.v1
there and reuses ALERT_SNAPSHOT_V1/INCIDENT_V1); docs/RULES.md had drifted
from what `rules docs` actually generates for SIDs 100069-100078 (ruleops.py
was missing metadata for four SIDs and had stale drill text for four more),
now back in sync with a regression test pinning them together.

Updates CLAUDE.md, README.md, go-agent/README.md, and docs/{ROADMAP,
GO_PORT_HANDOFF,SURICATA_ASSIMILATION,THREAT_MODEL,OPERATIONS,SCHEMAS,
COMMAND_REFERENCE}.md to reflect the landed work.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NQivSKBqQJsayz1xcYqWzZ
This commit is contained in:
Luna 2026-07-24 09:59:09 -07:00
parent 1d1dee7f6e
commit d835386381
No known key found for this signature in database
43 changed files with 3419 additions and 72 deletions

View file

@ -55,6 +55,26 @@ The default service is hardened and read-mostly. Enabling the bcc eBPF monitor
requires additional capabilities and memory permissions. That tradeoff is
explicit: stronger event visibility for a wider runtime permission set.
### Go Migration-Sidecar Evidence Is Isolated and Read-Only
The experimental `go-agent/` sidecar (see `docs/ROADMAP.md`'s Active Migration
Track) is a separate process with its own state directory, baselines, FIM/
package-DB/rootcheck engines, and hash-chain. It never shares or mutates the
Python daemon's `log_dir`, baselines, or anchors, and it is not the production
agent.
When an operator opts in with `go_sidecar_state_dir`, the Python dashboard adds
a read-only consumer (`/api/go-sidecar/*`, the Sidecar tab) over that directory.
It treats the Go sidecar's retained files as untrusted input from another
process rather than trusted application state: every alert snapshot and
incident record is schema-checked before display, a corrupted retained event
log fails the request closed instead of showing a partial stream, and the web
process never starts, stops, signals, or writes into the Go sidecar's state
directory. Compromising this consumer therefore requires tampering with the Go
sidecar's own retained files, which is the same class of local-tampering
problem `enodia.hash_chain.v1` and the sidecar's own FIM self-watch already
cover.
## Detection Assumptions
Sentinel assumes: