Add baseline reconciliation: accept audited drift with a reason
Implements the v0.9 roadmap item from the approved design spec. Operators accept a specific FIM/package/listener/SUID drift item with a mandatory reason; the ack suppresses that one alert only while the live state still matches the recorded fingerprint. Content kinds (fim/pkgfile) re-alert on further change; identity kinds (listener/suid) retire on TTL or revoke. - reconcile.py: ReconcileStore (mtime-cached, fails closed on missing/corrupt store), fingerprint builders, and the filter_alerts chokepoint. - CLI: baseline accept/revoke/list with --reason/--expires/--force/--stale/--json. - Wired at the daemon sweep + eBPF chokepoint, fim-check, and /api/integrity. - RECONCILE_V1 schema, config knob, COMMAND_REFERENCE/SCHEMAS/OPERATIONS/ROADMAP docs, and reconcile unit/CLI/integration tests. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
parent
3d2047fde2
commit
dbbe35b3fc
18 changed files with 1155 additions and 28 deletions
|
|
@ -170,12 +170,16 @@ def pacman_verify(timeout: int = 600) -> list[tuple[str, str, str]]:
|
|||
return parse_pacman_verify(r.stdout + "\n" + r.stderr)
|
||||
|
||||
|
||||
def pkg_alert(pkg: str, path: str, reason: str) -> Alert:
|
||||
return Alert(
|
||||
severity=Severity.CRITICAL,
|
||||
signature="fim_pkg_modified",
|
||||
key=f"fim:pkg:{path}",
|
||||
detail=f"package file altered ({pkg}: {reason}): {path}",
|
||||
sid=SID_PKG, classtype="integrity-violation",
|
||||
)
|
||||
|
||||
|
||||
def pacman_verify_alerts(timeout: int = 600) -> Iterator[Alert]:
|
||||
for pkg, path, reason in pacman_verify(timeout):
|
||||
yield Alert(
|
||||
severity=Severity.CRITICAL,
|
||||
signature="fim_pkg_modified",
|
||||
key=f"fim:pkg:{path}",
|
||||
detail=f"package file altered ({pkg}: {reason}): {path}",
|
||||
sid=SID_PKG, classtype="integrity-violation",
|
||||
)
|
||||
yield pkg_alert(pkg, path, reason)
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue