Add baseline reconciliation: accept audited drift with a reason
Implements the v0.9 roadmap item from the approved design spec. Operators accept a specific FIM/package/listener/SUID drift item with a mandatory reason; the ack suppresses that one alert only while the live state still matches the recorded fingerprint. Content kinds (fim/pkgfile) re-alert on further change; identity kinds (listener/suid) retire on TTL or revoke. - reconcile.py: ReconcileStore (mtime-cached, fails closed on missing/corrupt store), fingerprint builders, and the filter_alerts chokepoint. - CLI: baseline accept/revoke/list with --reason/--expires/--force/--stale/--json. - Wired at the daemon sweep + eBPF chokepoint, fim-check, and /api/integrity. - RECONCILE_V1 schema, config knob, COMMAND_REFERENCE/SCHEMAS/OPERATIONS/ROADMAP docs, and reconcile unit/CLI/integration tests. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
parent
3d2047fde2
commit
dbbe35b3fc
18 changed files with 1155 additions and 28 deletions
|
|
@ -145,6 +145,13 @@ Baselines are useful only if they represent a known-good state.
|
|||
- Use `fim-update` only after confirming changes are legitimate. Package hooks
|
||||
already run it for normal package transactions.
|
||||
- Keep a copy of important anchors off-box when possible.
|
||||
- Prefer `baseline accept <kind> <target> --reason "..."` over rebuilding a whole
|
||||
baseline when only one item changed legitimately (an edited config, a new
|
||||
service port, an installed SUID helper). Unlike a rebuild, the acceptance is
|
||||
per-item, carries a recorded reason, is fingerprint-bound (FIM/package items
|
||||
re-alert if the file changes *again*), and can be time-boxed with `--expires`.
|
||||
Review outstanding acceptances with `baseline list`; it exits non-zero and
|
||||
marks rows `stale` when an accepted item has drifted again or its TTL lapsed.
|
||||
|
||||
## Suggested Hardening
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue