Record schema-v4 secure runtime qualification

This commit is contained in:
Richard Courtman
2026-08-30 19:38:34 +01:00
parent b0de67332f
commit b0de28c7c4
8 changed files with 1292 additions and 36 deletions
+38
View File
@@ -4,6 +4,44 @@
frontend-modern/browser-verification.json:generic-api-key:11
frontend-modern/browser-verification.json:generic-api-key:12
# Schema-v4 secure-runtime evidence stores SHA-256 source digests beside source
# paths whose names contain auth/token terminology. Suppress only those exact
# generated path/rule/line fingerprints; the transcript remains fully scanned.
docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:80
docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:81
docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:82
docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:83
docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:84
docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:87
docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:97
docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:119
docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:128
docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:129
docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:130
docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:135
docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:144
docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:242
docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:262
docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:277
docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:304
docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:56
docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:57
docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:58
docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:59
docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:60
docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:63
docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:73
docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:95
docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:104
docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:105
docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:106
docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:111
docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:120
docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:218
docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:238
docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:253
docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:280
# Historical findings proven to be deterministic examples, placeholders, or
# public-key/path false positives. Keep these commit-, path-, rule-, and
# line-specific so provider credentials and expired tokens remain visible.
+15 -10
View File
@@ -196,25 +196,30 @@ or generic command path.
| Platform or capability | Preferred boundary | Safe-profile behavior | Qualification and default implication | Residual owner and removal condition |
|---|---|---|---|---|
| Proxmox VE/PBS/PMG inventory, status, storage, and ordinary metrics | API-only connection with a narrowly scoped token; no host agent | No collector, helper, or runner authority is required for this data | Supported independently of the safe host-agent profile; it does not prove host-local SMART, LXC filesystem, or action parity | `agent-lifecycle`: keep API permissions and returned telemetry covered by provider tests |
| Standard Linux systemd host telemetry and collector update | Unprivileged `pulse-agent` plus the root-owned typed helper | Core `/proc`, filesystem, network, RAID, and hwmon telemetry stays in the collector; helper-backed signed update activation is implemented but its live activation/recovery transaction is not qualified | **Qualified on disposable Ubuntu 24.04.4 arm64 at committed main** for install, migration, explicit/automatic profile rollback, helper health, reporting continuity, and process/credential separation. The receipt's ordinary update ran under the downgraded root monitoring profile and does not prove `agent_update.activate.v1`, executable-digest commit, watchdog rollback, interrupted recovery, or last-known-good restoration. Remains opt-in pending those live scenarios, exact-RC reproduction, and external review | `deployment-installability` and `security-privacy`: qualify helper activation/failure/recovery from the designated release candidate and accept the external boundary review |
| Standard Linux systemd host telemetry and collector update | Unprivileged `pulse-agent` plus the root-owned typed helper | Core `/proc`, filesystem, network, RAID, and hwmon telemetry stays in the collector; helper-backed signed update activation is implemented but its live activation/recovery transaction is not qualified | **Qualified on disposable Ubuntu 24.04.4 arm64 at committed main `defc24af837b91428fbee939d09cd31e9559fb4f`** for install, migration, explicit/automatic profile rollback, helper health, reporting continuity, and process/credential separation. The schema-v4 receipt's ordinary update ran under the downgraded root monitoring profile and does not prove `agent_update.activate.v1`, executable-digest commit, watchdog rollback, interrupted recovery, or last-known-good restoration. Remains opt-in pending those live scenarios, exact-RC reproduction, and external review | `deployment-installability` and `security-privacy`: qualify helper activation/failure/recovery from the designated release candidate and accept the external boundary review |
| Linux SMART telemetry | `smart.snapshot` through the no-network helper; no caller-selected device or arguments | Implemented, unqualified on representative physical disks. Helper failure omits/degrades SMART only; the collector does not retry as root | Does not yet justify SMART parity or a default change | `agent-lifecycle`: record live SATA, SAS/controller, USB bridge, and NVMe evidence, including standby, permission failure, timeout, and partial-data cases |
| Proxmox node-local LXC filesystem telemetry | `proxmox.lxc_filesystems` through the no-network helper using fixed bounded `pct` operations | Implemented, unqualified on a representative PVE node. Helper failure omits/degrades this snapshot only | Does not yet justify Proxmox host-agent parity or a default change | `agent-lifecycle`: record live running/stopped LXC, mount, timeout, output-bound, and helper-loss behavior on supported PVE versions |
| Rootful Docker or Podman inventory | No direct collector access to a root-equivalent daemon socket | **Unavailable in the safe profile.** Migration disables the provider visibly. A closed helper `container.inventory` operation exists, but collector integration and live parity are not qualified | Rootful container parity is an explicit default blocker; the legacy/root profile is not safe-profile evidence | `agent-lifecycle`: either integrate and qualify bounded helper inventory or retain the explicit degradation permanently |
| Collector-owned rootless Docker or Podman | Direct access only to one usable runtime socket owned by the `pulse-agent` UID | Implemented, unqualified live. Ambiguous, root-owned, unreadable, unwritable, or unavailable sockets disable container monitoring | Does not yet justify container-runtime parity or a default change | `deployment-installability`: record fresh install, migration, restart, socket-loss, ambiguity, and telemetry parity on both rootless Docker and rootless Podman |
| Separate runner package update and package-cache cleanup | Root-owned `pulse-agent-runner`, host-bound action credential, typed request, postcondition, and durable receipt | A real verified apt-cache mutation, stale-fingerprint refusal, replay, and self-revocation are present in the committed-main systemd receipt. Two-phase credential activation and nonce-bound readiness are implemented but need fresh production-path qualification | Qualified only for the exercised apt-cache mutation; the receipt does not prove the current Router/TLS/durable-persistence credential lifecycle, every runner operation, or an exact release candidate | `agent-lifecycle` and `api-contracts`: reproduce through the production Router over HTTPS from the RC, including failed activation/rollback and representative package-update success/failure/cancellation evidence |
| Separate runner package update and package-cache cleanup | Root-owned `pulse-agent-runner`, host-bound action credential, typed request, postcondition, and durable receipt | The schema-v4 committed-main systemd receipt records a real verified apt-cache mutation, stale-fingerprint refusal, replay, nonce-bound readiness, exact credential rotation, and self-revocation | Qualified only for those exercised fixture paths; the receipt does not prove the production Router/TLS/durable-persistence credential lifecycle, failed activation rollback, every runner operation, or an exact release candidate | `agent-lifecycle` and `api-contracts`: reproduce through the production Router over HTTPS from the RC, including failed activation/rollback and representative package-update success/failure/cancellation evidence |
| Separate runner Proxmox guest and container lifecycle/update actions | Root-owned runner with closed typed protocols; never the monitoring collector | Implemented, unqualified on representative PVE and container-runtime targets | No live-provider action-parity claim and no default change | `agent-lifecycle`: record target-bound success, stale-state refusal, cancellation, reconnect/replay, and independent postconditions on disposable real targets |
| Appliance, non-systemd, Windows, and macOS host-agent profiles | Platform API where sufficient; otherwise an explicitly named legacy/full-trust profile | **Unavailable for safe-profile apply.** The installer fails closed instead of silently installing a root-equivalent profile | Excluded from the Linux safe-profile claim | `deployment-installability`: land a platform-specific service, filesystem, update, helper, migration, rollback, and live-proof contract before marking that platform supported |
The committed-main Linux evidence is recorded in
`docs/release-control/v6/internal/records/secure-agent-runtime-qualification-foundation-2026-08-30.md`.
That receipt is artifact-bound operator self-attestation, not an independently
authenticated external assessment. The safe profile therefore remains opt-in.
The current attester requires a fresh schema-v4 run: it expands a committed
production-source manifest, requires exact source membership, binds ordered
scenario claims to a retained secret-free JSONL transcript, validates typed
receipt/report chronology, and hashes the intended repository record path
inside the receipt. The existing v3 record remains historical and is not
silently promoted to this stronger evidence class.
The current schema-v4 receipt qualifies exact committed main
`defc24af837b91428fbee939d09cd31e9559fb4f`. Its attestation verifies a
345-source production manifest, clean exact-commit identities for all four
artifacts, twelve ordered scenario claims, and a retained secret-free JSONL
transcript containing 81 events. The receipt, transcript, and attestation have
SHA-256 digests
`58da80f7d75d414c12cf6632bd895b821ce759625e7d00ae00c16d56204b1e76`,
`616681aee38202ed922880288b730cd85f746e081f8f9d45bb2d570e48b49f8c`, and
`a48e855fdd2dcbc0cf91717dfaed22f942320c9661dd9b9e8f8f8e97f45d654b`.
This remains artifact-bound operator self-attestation, not an independently
authenticated external assessment or production Router/TLS/durable-store
exercise. The existing v3 record remains historical. The safe profile
therefore remains opt-in.
Monitoring never implies remediation. On the supported Linux systemd profile,
an operator may separately enroll the typed action runner:
@@ -131,10 +131,22 @@ receipt roots; requires the receipt hashes to match that exact set; validates
ordered timestamps and scenario-specific causal claims; binds every scenario
to a retained secret-free JSONL transcript event; validates typed receipt kind
and report chronology; and requires the intended repository record path to be
inside the hashed receipt. No schema-v4 live receipt exists yet. Accepted v4
evidence will remain artifact-bound, self-attested systemd evidence rather than
an independently authenticated assessment. The repository still needs a fresh
exact committed release-candidate run,
inside the hashed receipt.
A fresh Ubuntu 24.04.4/systemd 255 arm64 run at committed main
`defc24af837b91428fbee939d09cd31e9559fb4f` passed all twelve schema-v4
scenarios in 107 seconds. The 345-source manifest matched the commit, all four
artifacts carried its clean Go VCS identity, and the receipt bound 81 retained
transcript events, including 69 raw command-output events. The receipt,
transcript, and attestation are recorded as
`internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json`,
`internal/records/secure-agent-runtime-systemd-transcript-v4-2026-08-30.jsonl`,
and
`internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json`.
This remains artifact-bound, secret-free, self-attested systemd fixture
evidence rather than an independently authenticated assessment or proof of the
production Router/TLS/durable-store credential lifecycle. The repository still
needs a fresh exact committed release-candidate run,
representative Proxmox, SMART, Docker and rootless Podman telemetry/action
parity, appliance profiles, and the external security review. Until those
proofs are recorded, the safe profile remains opt-in and provider degradation
@@ -0,0 +1,429 @@
{
"schema_version": 4,
"attestation_tool": "scripts/release_control/secure_runtime_attestation.py",
"attestation_tool_sha256": "f83c545a95dd6f9c46b4c676e1c28a2ae9b7a8a42ebef11b0af914d580ccecf1",
"proof_classification": "committed-main-artifact-bound-self-attested-systemd",
"qualified_commit": "defc24af837b91428fbee939d09cd31e9559fb4f",
"qualified_ref_at_run": "defc24af837b91428fbee939d09cd31e9559fb4f",
"main_ref_verified": "origin/main",
"main_ref_commit_at_attestation": "defc24af837b91428fbee939d09cd31e9559fb4f",
"qualified_commit_reachable_from_main": true,
"build_checkout": "detached-worktree",
"build_checkout_clean_except_lab_artifacts": true,
"disposable_vm_guard_receipt_claim_validated": true,
"execution_receipt_authentication": "none-secret-free-self-attestation",
"receipt": {
"record_path": "docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json",
"sha256": "58da80f7d75d414c12cf6632bd895b821ce759625e7d00ae00c16d56204b1e76",
"path_bound_inside_receipt": true
},
"transcript": {
"record_path": "docs/release-control/v6/internal/records/secure-agent-runtime-systemd-transcript-v4-2026-08-30.jsonl",
"sha256": "616681aee38202ed922880288b730cd85f746e081f8f9d45bb2d570e48b49f8c",
"event_count": 81,
"scenario_event_count": 12,
"command_output_event_count": 69,
"format": "jsonl-v1"
},
"source_manifest": {
"schema_version": 1,
"manifest_id": "secure-runtime-linux-v4",
"path": "scripts/release_control/secure_runtime_source_manifest_v4.json",
"sha256": "243e6c85640dec80082e3f1bdc5983912c613ad97ff9e9292b110a9f1411bb45",
"target_os": "linux",
"target_arch": "arm64",
"source_count": 345
},
"source_hashes_match_commit": true,
"source_hashes": {
"cmd/pulse-agent-helper/main.go": "3da1978e6e70d29cc22f070c5ada1f6a5f516f6a6643a3b27f23a4adf9ade866",
"cmd/pulse-agent-helper/providers.go": "0a179a2327cca2660f5f24ab3102a7c55ba8c87d06bbfdfd8eff2b206b9b8f88",
"cmd/pulse-agent-runner/main.go": "33707517965ae81a8b42ba86cac98e665f376a4c176572e1f558862cec82c460",
"cmd/pulse-agent/main.go": "73527ea1c0513804fcbf64fa1b924fa7f29dc5441cd98ed2c0e2f53ddd621ca8",
"cmd/pulse-agent/runtime_health.go": "64de01be0472998b5f58b49a446e22d20591802f2679f342da7fb8f2628e0c49",
"cmd/pulse-agent/service_stub.go": "3674fde8d348a121fa6ac278d235ef1634d944dccd44184fecf70cbc5ca818f0",
"cmd/pulse-agent/service_windows.go": "59ac578a598113edc7263d47cfcee5bf3806e2d6310eb49fa8f8a30a8bff8a73",
"internal/actionrunner/runner.go": "2478a333b557c7a50c49e58d0e2872bc5f702bf984b90a94a51396e538e14ef8",
"internal/actionrunner/transport.go": "6e39ea82bc0b31300e9bdbcc3fed5c1fa2348166bbaf6ce0e95ce5adb44ee5d0",
"internal/actionrunner/types.go": "4d52786233ee15d5c832a03980dd9ac460cf76d147f2aba6a8336d06d2f9aa48",
"internal/agentexec/action_preflight.go": "6a2ce9fbbe514e5b70537f6b07ecd16796416a621a0712b7ee4185cf3a5ca7ab",
"internal/agentexec/approval_grant.go": "7a30d1d4699e4a92fcda5edbb972cbb821f3e627241158ce34b970bf2e47f650",
"internal/agentexec/apt_codec.go": "51525b97672d07cb520f1cdb7ce7749c1f0d38629552e3895133a23b6f2f73f2",
"internal/agentexec/docker_lifecycle_codec.go": "c6857d25272add6acfe800ff9dee06d2a812403ca930fd4f9beb0ed9ef5757d8",
"internal/agentexec/docker_observation_codec.go": "dba73ac04672cfd7359de9ecd9ac88a02d42896ca6ee6febe6b40b395bd10cbc",
"internal/agentexec/docker_update_codec.go": "84824476c1e4a250cfebab0b709e60876705141a243af1a2854570b2692f8e16",
"internal/agentexec/export_test_helpers.go": "516445912c3ed26ea71235888a77eca88f90f05dc9d78510f3faa0c97581be41",
"internal/agentexec/policy.go": "f84ec5bf77b33202a0a51907507be93893a4d6a52a291da83616f0936fc15f28",
"internal/agentexec/proxmox_guest_lifecycle_codec.go": "e29463d4f151a3f478c8b9123f5d7e47ecaa88c1b90fc41a2c15f3e9a06fc18e",
"internal/agentexec/server.go": "b252ed4b972afc648f713ea0ab7d1feaf617b7dd4fef3a2ef87e2fb657b90d5a",
"internal/agentexec/types.go": "428a06918af94c803c720d282d5123149e70c5bf2dbdfd06613495d54d8f9b0d",
"internal/agentexec/verifier_postconditions.go": "27f68d4f05e45803f65a1dd3c7e38d41ca39ab88d9f1a574dc4739911b8391cc",
"internal/agenthelper/client.go": "1192d45f3f93a59c07d7d6189767bdc53ea57f8660e0f6558e8dc97b06f420aa",
"internal/agenthelper/container_inventory.go": "ece7672977a3b9584273a942f7ee903b926af500bf80cc0e43784952cca62dfa",
"internal/agenthelper/file_security_other.go": "0bd44450f28b3fbf9eba13bd2ef13773faec850f91518b134770268176400051",
"internal/agenthelper/file_security_unix.go": "457094f8010691b17e08c95aa7191202dff5079e8054ae75619e6c1494c6307c",
"internal/agenthelper/peercred_linux.go": "31db3ba3b565ac9fac73ae7ce94c423cc3fd25791da81c5821b9db10ced94a4d",
"internal/agenthelper/peercred_other.go": "983a2c51fefe378d2605061e17b254825554f28f3b669bed58c36dd13f1ab204",
"internal/agenthelper/protocol.go": "d7a6548f2e7f91d6827b582d5a1becf24fed6ce4c57de0e4c16b3b4fd52bda0d",
"internal/agenthelper/providers.go": "f1ed8226b817b0fa7cea71ba052808be5e4a2e1cab8298029b3cfb1e932fe856",
"internal/agenthelper/registry.go": "0d9a0be8b33e86803daee782e4bffe4e691424c692df25603f4c8ed821d363e1",
"internal/agenthelper/server.go": "70ef4f2299cf5d3347520906e62e8d7307d67624f60232c9bcbafbc6035e3ebe",
"internal/agenthelper/update_activation.go": "cdaae1da9459d5cbbd9f84dce6e6e3234bc03ed4739e78292161d2faa98d2445",
"internal/agentupdate/pending_update_persistence_other.go": "cbfee489c1050744ec440df0627ee0d6cf349efaa57387fed31728504f71a297",
"internal/agentupdate/pending_update_persistence_windows.go": "d5475a26f8446f3c45c869a71cbde79e83731edb3b4e32fd952fb94d3c454211",
"internal/agentupdate/privileged_update.go": "1e27b3d94087e85139dfbfeb86b78e6444ee9b80bd97bdbf698d0d2dadd6c624",
"internal/agentupdate/privileged_update_owner_other.go": "460fcc9619f53d79bf598bc31c4fc34c5ce5bd8fed2300d31b1c6a64144e3a29",
"internal/agentupdate/privileged_update_owner_unix.go": "875f827dd9106ab4aee70b564d264505d76e993e019ec08c687a6b3e823df896",
"internal/agentupdate/restart_unix.go": "cff57a8ee74c0d41e374c40ea8808487095988df118727d95a888f0da1a6d205",
"internal/agentupdate/restart_windows.go": "5d515fb21beb45c82ce6197b2d3154a8f0d9d8ffae86125ac1516a7d0130f3d8",
"internal/agentupdate/update.go": "ad885a99ce679fc30c5155147961f1e970fec031e25f5b69ea9814795d2f335d",
"internal/api/access_admin_handlers.go": "b5ab4a4ace0c3290a49d370eecdedf8b2de8ff50979ce67e25ab4f5589440e6c",
"internal/api/access_admin_recovery.go": "304f63c863e2c5a8104e4da097d4bfbf7e6d400fb7a153bd3ddbe4a59682053a",
"internal/api/access_control_handlers.go": "5ed98baf5f5914f5a5cf9127426ec24b4710fd49dad456844c2502b87e3b5e26",
"internal/api/access_metrics_handlers.go": "9418de69783686f5051a66936d79059b68ba373de8b249d1591292919ea6a849",
"internal/api/access_tenant_provider.go": "1dcb5fdd875e2c41e257e20d41f77c3f6dd6e7cc7787468e0c36c9cb2330b7fe",
"internal/api/action_authority.go": "0a54504b9d8a4a3beb61b9a9329225e5d684ab9eeba70a06ecd22fb0dc8f2db5",
"internal/api/action_executor.go": "be19d610a0b5614b6cacc3239ef60baa88d3c092bf56f322a7e849ba85870e39",
"internal/api/action_runner_credentials.go": "14ff066b3ad8af52c63081f070d2f92c3fdf90bb5672c0a02314c91fdf59ac1f",
"internal/api/actions.go": "0ea3967610dcf5fe00e678a97a982949247b924f3bf1732019aaa2eec7cf276e",
"internal/api/activity_audit_handlers.go": "e314a619e7cdbccad71c5ca0aff2eccd864ed05977e2bc41ed3f043387e4422f",
"internal/api/admin_bypass_mode_dev.go": "05f390ebc02e1ab63661fc3530c174328c72e47ed616feb0f28e2d853c5961db",
"internal/api/admin_bypass_mode_release.go": "8deadaaffd001e014830eb30c46c226fc42700593e74c7e6f8f4fc3d06ecc40b",
"internal/api/agent_activity_telemetry.go": "cd837430d51120c2b1a97341234f4bce44653e2040552122ce2ea6e4ee6c0003",
"internal/api/agent_capabilities.go": "21d6b1925ca458781313d77928f277db2d6225bde1f55dcf1c06dc3e6b8cf5d7",
"internal/api/agent_command_authorization.go": "4e575a2c51d9456e97c531575c243045030d252d00a6c4711362e11e4c5c427c",
"internal/api/agent_command_redaction.go": "623788c5129289c7197e220e41326cba96eef6e919393d50df7ec1824b74c137",
"internal/api/agent_events.go": "0cee3893be3a01d8de0082eec541926544989ffca5c7b2dc8bc056a02c59da19",
"internal/api/agent_exec_token_binding.go": "ac230d99f65616e9134e8942cfe36ddce9e202b63c420c64f2ad0136aaa5e791",
"internal/api/agent_fleet_doctor.go": "425e391fc251ab756e12b6c8196f24c763e4f931ad50c3076d35d2c13d31c840",
"internal/api/agent_handlers_base.go": "c2c834d051715e070febf99b26420050bae08bf4f14c952d864ea25c26a46689",
"internal/api/agent_ingest.go": "79e7e1ee3c8f741fc4e0e17b7d1db3f99ceecb38019f1ebc9176ea8034dfdc97",
"internal/api/agent_install_command_shared.go": "e49ed243070e76d143c9dd96c6b517a08a12a777d99e8c470f0a96b630ff1204",
"internal/api/agent_profiles_tools.go": "31ac7cc3711ec77810d7d6ee530896a25652a350639e60f6ed26c35ab9e05d49",
"internal/api/agent_resource_context.go": "b80065c925cb4f9e95df6f771c1d4636fefd425f9e3d7a0e19b909a72b165501",
"internal/api/agent_version_shared.go": "40e268867f6a7272890e395bc0a97ac00504c41ac81257b60c8826a2d11d5330",
"internal/api/agentbinding/policy.go": "30ead686f253b70dfdca81de13fe329ffba1641141672b6ad8253c4bf88fcf20",
"internal/api/agenttokens/install.go": "fbbb178b7a214562dc88038e1dff0db47faf1664e48d3c2b64e884f52b533174",
"internal/api/ai_chat_transport.go": "b8cd204026714ae1d395cc07f64e0248322b5d24cbb9704fd3a3dea6dbff1eb7",
"internal/api/ai_handler.go": "a9e78b9788c362ffd8561105a36d8b6c0919f56396e7b88b4d8d5268a81bc2a9",
"internal/api/ai_handlers.go": "59d7cdb5af3060f451ad61bcc23e872b6de0575fdf9af12b98bc1a903b92d036",
"internal/api/ai_hosted_runtime.go": "a746418338ceaf577fc5068e34a30819904ae7f0ea5fb1002cb0c27cea0dd6c7",
"internal/api/ai_intelligence_handlers.go": "d9dc1cb7b1aa30ff406307486052f6d5a024d26e90ef6ea2625cab03f0529bf9",
"internal/api/ai_resource_types.go": "78e6276305c4b93bc8fd091c953e58f27417ba75e798a437061d35f6b78fe267",
"internal/api/alerting/alerts.go": "cfa499011224cac15b74c26004fdf6cf6718de380a797759a67d92a2b1f7c2d7",
"internal/api/alerting/external_probe_notifications.go": "3043d331aabf45350f9902acf69c315f4e594d06df7a62b38146bde4dfd8c8dd",
"internal/api/alerting/monitor_wrappers.go": "b1bd97d6a046b30687ad404403cb005be8d61110d605e459aca565fe3f80c43d",
"internal/api/alerting/notification_queue.go": "b1c61e450220f4c5f2b93e2f5907eeaff38e463d0f4fb2a9fdbd562bdd28f995",
"internal/api/alerting/notifications.go": "57fb6046a9f7f9b7a8e4c7a9e5437715ab0a4ad85e37268ad1e09d1c85ab6560",
"internal/api/alerting_compat.go": "7a86c8f7f9a243364159b17f8aa0319b4e4fc61335e2bebc567df4a6985514b6",
"internal/api/api_token_identity.go": "adffc3d27d0359cea29ad14811c9bb82078e30b54ac8ea0e4a445ad307991e50",
"internal/api/apicontext/context.go": "5069c811226ed6654fe3caa99e31fc43e001a0599f8d2275be8773d627d5cf5a",
"internal/api/apihttp/scope.go": "22a7a0af30c656ba0ec7b3ed33d6e5e5456f48b09cf06c440104b7e2a354a7b0",
"internal/api/assistant_typed_action_planner.go": "75f11f96af5eceafce0b80850543f3c976d70b54c193eb7a579cc384a0e6e7e1",
"internal/api/attention_actions.go": "9ff650484508ab4311e824a07dcedae29353543da52f095af78fa1662142a22b",
"internal/api/attention_evidence.go": "dc6b4f2a8a406cc436a33c8c6a1db84204fdbf8702639a1a82f9f7050a399348",
"internal/api/attention_handlers.go": "449ae73617a1bcd191b66909f8b928cd0f739b5c31753d0168183707fd021ea3",
"internal/api/attention_mutations.go": "ca86d76b97d2c72d3bbaf1d4a18d58559bf6f05b8992de62b2f56eac64625210",
"internal/api/attention_receipts.go": "bc177a9d2ea1b1e3feba114329a8f066fd12a564f9c8aeb3666b4bf80c63d08e",
"internal/api/auth.go": "8f6e771181541a252ae478d65d74e97645e86ba9b905f3f81b40c11db074bff4",
"internal/api/auth_denial_signal.go": "cb93d6742af2947dfd5310cdb4df7d035c7950a284cb34e5cbc96f1b889b8d06",
"internal/api/auth_env_path.go": "7938bdc69252a494a1965bbd0ff9d53fa943ae1d4f5160f0257518881d2c5d63",
"internal/api/auth_principal_identity.go": "2dcf138e9294e357ab0abe0d66b553a620752d77fe608ff478be64fd0f13bb2d",
"internal/api/authorization.go": "49349007b4868090373ba8ae4ddca7ef245c1820d2d2fc59db232b1d213b6612",
"internal/api/availability_handlers.go": "68ead5fc26bb34f85a8509e5431d17b1e1c96cef8a32b668759c432d641f4ce3",
"internal/api/availability_history_handlers.go": "dd87da2d197fd085794afbee160dd7706ed3a470dc25d3bcb63936726f7be381",
"internal/api/bootstrap_token.go": "30a338638b388f3b7f24c4f52541683d7807e36513210f6d12969cc63180434b",
"internal/api/chartapi/payload_cache.go": "0562f08e45a44c7a1b8648918f01103e494d0fc2c6e8b3a4a2cb059040ef8189",
"internal/api/chartapi/service.go": "1018fa106466fa4148f390c1a3f7f8f34ebcf52ed2667b524fb5f09f52659af0",
"internal/api/chartapi/types.go": "19204522a2d4303436e335e8b7fe339e2aabfe9601a1508d0be4928c55148643",
"internal/api/charts_compat.go": "e96389b7b9d5543452f9aed7d0f57eb539e6806bd16da9e1e9bcbb4da5819f9e",
"internal/api/chat_service_adapter.go": "ca729ba9bd98da4770343f5ca0095bae92478f7578c461ba5cfc05e111af608f",
"internal/api/cloud_agent_install_command.go": "295de654650ecf191ac4d3c57565f6fdd45f05c3f42c086b80efe7bcb04c6d07",
"internal/api/cloud_handoff.go": "6b6477b33a04588cdd46b5f5ca0d25e6c0b41e2e937da22253778eb44a385dab",
"internal/api/cloud_handoff_handlers.go": "1c3e12ac5465f81f60816f57e0bcaed5682edd07694d9a8b63b4750c127eeb29",
"internal/api/cloud_org_admin_auth.go": "3d4361802f80d58c298b0dd57f0daba7e69f7da4e533338f4e7cee12b9f09c8e",
"internal/api/cloud_org_admin_handlers.go": "11249b2d21394e2bed4869ee39d9bade37a1363b01bc087a5235e96f656936fa",
"internal/api/collector_authority.go": "09e390d33fb952a95dd202bec57aa8a599249dbf1091b915bb7546678a68213a",
"internal/api/config_handlers_compat.go": "7fc41dc53e5301cce10986b753cf846105d0edad595cb9555dfe9a58e41be22a",
"internal/api/config_profiles.go": "f469a466b496e246ec80595daed804b55dffa72742f6972b9070119092df7e8b",
"internal/api/config_transfer_authorization.go": "525d0c0538f11a4e18f01a08bf33f1539a4ef2e26db9cada8ff6eec432ebe33e",
"internal/api/configapi/config_discovery_handlers.go": "d499ff00be90ff9a20e6a213529835c066d298484602d470843db4f925894c80",
"internal/api/configapi/config_export_import_handlers.go": "6a264cad6a31d5485813e80270bb107f28d425dded7425d7f07503b28b74f981",
"internal/api/configapi/config_handlers.go": "2a6b8819a5c6f29ae7182bb63161e25618f9ca11c2cfc53a1e41a8e1d4bc285f",
"internal/api/configapi/config_node_handlers.go": "ab955443d378cf45f884cde701a073f1bd43365e93ad207290d64b70f9429dda",
"internal/api/configapi/config_setup_handlers.go": "0e42842f29647d33c8fe74b39b83163389a2eb0969f8eb1e4b2463c337fea3b9",
"internal/api/configapi/config_system_handlers.go": "795ea62862da3f6597ec5e2a1bffb91f188f1585a18e77af50ba3075dfd027ce",
"internal/api/configapi/dependencies.go": "4f2620778bccbfe58a6010f813aaf24af0123aa79a552e3d1ce0ac7f36dab190",
"internal/api/configapi/install_command.go": "7b819a63a5a755d9affc6229092be95e88c076282632b9ea6d039b696c2427c5",
"internal/api/configapi/setup_script_artifact.go": "aca4b1151d19df5fe6da3965375373127c7a91bb6ab2a3250e24fd15ce5b41be",
"internal/api/configapi/setup_script_render.go": "32759b1860b45c781607ca6b380c3d83e8568b77ab16567cc4236ca7da4eaba0",
"internal/api/connections_aggregator.go": "9c8156d544dd2d814a6a1b25c4239372abae126ec41d382a386619b1cc84f048",
"internal/api/connections_alerts.go": "71efc73848c99d3c799639cf2f48357db2b273175a670b3168b5047de80d936b",
"internal/api/connections_grouping.go": "44f50e6bfc73c2fb844bd1dd36d7045cde3364196053a7fa8898e4d3084cb6f1",
"internal/api/connections_handlers.go": "41975dc288f66888ad84febdb5fb66fe5c6970145b15743a41f5e1de32524dec",
"internal/api/connections_probe.go": "ab7bf1e2f0482328bdee4b134519fa1d5379fc2aaf2ec9e3b390f9e6f58c1f0a",
"internal/api/connections_types.go": "af57732666b1bebabf75d3f0de5bd421b2bdbf2311ddf2b709d5ddf6d4e681fa",
"internal/api/cors_policy.go": "71001daab7062943671f8a2efec59a6dd8d20b77b6b2b8af6f7f2ce8cae20a91",
"internal/api/csrf_store.go": "5768a98f50a61ed31ea83b20e4343c1366b673221eac0d4bce601c9b0a857522",
"internal/api/demo_middleware.go": "192f58c36bc0fc2e3b18cfb914e32f7bccef85d033ee2211473564cde383cd22",
"internal/api/demo_mode_commercial.go": "88e75e594472e0149c196b81b288b5b841d8e3309be2a1664d8135a4dd12fbb3",
"internal/api/demo_mode_operations.go": "48ba980abaca84da215c6f1cb0ad7d4032a1a554c7a6f78e2af3f01ea660f359",
"internal/api/deploy_handlers.go": "af72864e89f6720eaf0f6acce2ce6d5a90c06a6dba5d14ee9f12e49ded391076",
"internal/api/deprecation_metrics.go": "f09c919e23723bc09d324f478a698cb53c56fb9da342ef25b808844a8d2b40c4",
"internal/api/diagnostics.go": "344c7f1cddd1014c35550ac8b478d77619ba9f68030e2cde695c5ae59108e3e9",
"internal/api/discovery_handlers.go": "f5c3f3f5c9a2292dcb0f708e5bde18813d3155dbcec8c3109fb6dda70452769c",
"internal/api/docker_agents.go": "5eabed7a78cd6c0bb8df0a07dc51a0cf55886919e957abfb4f1b0ce2ce44ea85",
"internal/api/docker_container_action_executor.go": "c1aef8384d2cc8ab42a0d83db81fd61411101baceefa5c2539f10dfe2ff06d2a",
"internal/api/docker_container_action_result.go": "70d6c154038416377d533cc2fd0398c3e74c22398ee38d98d35bae9df1130632",
"internal/api/docker_metadata.go": "99598ad8b05638d14fac95e91f1fa93d1e301cba5e486a559c2a0d53c9198df6",
"internal/api/docs_links.go": "467eb1dede5e6d10336683141fa12230e6106f56d4279d7b7120a7416675a4fa",
"internal/api/enterprise_extension_ai_alert_analysis.go": "a00046c2898718359dae5bb178fbc33fdedb5a39871b4769351f251fe4d2caa0",
"internal/api/enterprise_extension_ai_autofix.go": "b632ba3becebbb4f66a05b656982e00c9aa86af90b0d88bb23fe45fcd168d4fe",
"internal/api/enterprise_extension_ai_investigation.go": "109f6cc1b0fe9aa7c1ffec4e6ae3e2ff9a795dbfae9bb23fc1e77f03273ca672",
"internal/api/enterprise_extension_audit_admin.go": "46cb98ef8eb5a80a0ac2c23a7558bedff6cddc6e220885ccf0a3ef863cc2bf12",
"internal/api/enterprise_extension_rbac_admin.go": "c15b58d124246a96104801178b2f621c48822f949b022d1958e07181be1b7be0",
"internal/api/enterprise_extension_reporting_admin.go": "5175036492611300eec523f84d8f33d61133d2ef2b5b17754fbf563d2950885c",
"internal/api/enterprise_extension_sso_admin.go": "9e70e1420e9da8aea788713f9545a9284fd92d6d7d044e91c1774e2d5e4f7a09",
"internal/api/flapping_postmortem.go": "fc6b6f14833000e53f94c61bb3a8749dbe1c2ff74e1cae827cd9c36dc2ed99b4",
"internal/api/frontend_embed.go": "abb2b942f5d59347ab7c6c9d2d3a35f4c094a42704ea3686cd4810c7282a068e",
"internal/api/guest_metadata.go": "d400c8e71cae811869b2abca65be2fba8e3e4cc3a4032ce5dea7be2fad84f0b9",
"internal/api/host_apt_action_result.go": "2c46e66942ccb3cebf4204fc695e297d59c32392afbe42049664fef12adf9ba3",
"internal/api/host_metadata.go": "68d61e98bb7acaf7d148b37e2eb416247c50a317560f9b5421f8f4f42f23b8ac",
"internal/api/host_storage_cleanup_action_executor.go": "4c5a0f21c07bb26b1c8206254e680c5880062f87b9e1eb8c5d3b41745eaa4723",
"internal/api/host_update_action_executor.go": "1b667b667c94a670a5685e4d204fd716ff40e6a5029bae0addf0202104f292cc",
"internal/api/hosted_entitlement_refresh.go": "bb4c8a49f97aedcb7c0b00628f390dc81072184df6f5335c160a04c34cfcc9cb",
"internal/api/http_metrics.go": "81fc091698cf7c1b011af70776dad53db3aa735367e51f4cda8a9bbf4b2b8527",
"internal/api/identity_sso_handlers.go": "fe125dd1e6e39c3dc674fa18ce57497791b93eb1951e3346765557595545717f",
"internal/api/kubernetes_agents.go": "7091a55df3fa214c08998d5528daf2792652bd32b02a51e3e4eed626f605601f",
"internal/api/licensing_bridge.go": "6afb5aefc414af81c44f6eb29e3464e1390972c50d52b9fcb84485bc658175a6",
"internal/api/licensing_handlers.go": "5f04e6a4543cd2bb2c4d782c782b9ab2b7486bda9ba7caa3f4b3b55b36d7a760",
"internal/api/licensing_legacy_retry.go": "23774844f2d42c94e15d9b3fe94aaa4fee00550e862d20a221590cff07d7e32e",
"internal/api/log_handlers.go": "c26cca429175d265f8003da91e57bc4b401d5ce236ed4e10e05023b69aea703e",
"internal/api/log_redact.go": "c02efc8b4d808aeee5c2181f29e6071b15488ec98df18439953f0427080e294c",
"internal/api/magic_link.go": "e89d72b4971d7526b66f67767b49b92c92a312e2cba81e1d6a7aaee12223def7",
"internal/api/magic_link_handlers.go": "ef9290751de30913b80085551893844a81e4e9bc79b6b5e053714e7509fc7dcf",
"internal/api/magic_link_store_sqlite.go": "41a4b043528888c019e06b65ea2bcb03461165dc9ad22bb69801f5b59b492061",
"internal/api/maintenance_verification.go": "6e4c78b090e442ff061e61e89e54271fa630d92a79d6ed34739fd6f1f46fa5e9",
"internal/api/maintenance_verification_wiring.go": "7dcc5bf18b98b9bfbc8303cf5a671629bfbdf76e220e6db4caebabf2c7ae74a5",
"internal/api/metadata_handlers_shared.go": "08407104bcd03fe18ef75f14a5cad82914a342bacd6eb066f61f93cb6f48f5c8",
"internal/api/metadata_helpers.go": "2ae9b6dae0e33bbadc84c9ab6f3241247f7e747111a0eb7d794eab61cae0dbce",
"internal/api/metadata_provider.go": "af146dc07fe00ee30ce49e897919736fdaa3f940cdd7d565e5dbaaf408fdd0ec",
"internal/api/metrics_reporting_handlers.go": "f6ee4261576045add6478798cd12d5eb3da8a91d9940f08e2deef7041b23d008",
"internal/api/middleware.go": "ed09180803ac654ac5e416b0e5b29042632c6a32f95accea591b17b35b3222b1",
"internal/api/middleware_license.go": "4dee04c182e7d2f6a75a32f03543a387068f172dbbd622fbdf5f16085027fb46",
"internal/api/middleware_tenant.go": "53a6304b105f1175962d7a7f621176d4c4e7ff8019cdafc630f6dd096d798d13",
"internal/api/monitored_system_ledger.go": "fd1647aba616bf9e426264dbb803284580ddf7dc8598d90c513774a834532450",
"internal/api/monitored_system_usage.go": "392a08e14642fa7f71d70663b3d4b3edacfc92bc13fc71410759952d9ed3509b",
"internal/api/oidc_handlers.go": "1f3982f69f2b4c8edb72e6e95440efad26c6a21377a566991b80671cdd57b605",
"internal/api/oidc_service.go": "82f21af7da5f05a86bf76561684bd8f356f473e6ed18429f960a81b261581546",
"internal/api/onboarding_handlers.go": "4a47265c65d46a6770c7caf94ccb55602f62e579bf0ed791af26c25602f33ee5",
"internal/api/org_handlers.go": "bb47a7b69ff24f05f8cab7e304fc281837970c1cb75a405a35e54c6d2d8e96ac",
"internal/api/org_lifecycle_handlers.go": "980b4c6e7e3010fdc22e52c5d2ee7a12b6a2b0ff63331feca7398841cecec4fe",
"internal/api/patrol_action_broker.go": "bbc5ebd742c5dc4c3b5cc5b79eab746b074af847ebccc190115605e3cd258f28",
"internal/api/patrol_action_reconciliation.go": "52e339d14ee9715b85d19a93fee21b656a55d8793e9a192fa71b86726c0d48e6",
"internal/api/patrol_finding_notifications.go": "c19e09c9118a67dd64be2e22f1d8f2efa46694a161f3011e2d513d9e66e44997",
"internal/api/patrol_objectives.go": "fc47707db8f337e692b0392fe46f33ade34ffe56ea99300defd246c0c4afdbcc",
"internal/api/payments_webhook_handlers.go": "ec1e1cf664520a9c15b3a8a947dce9186cf5c6bd76cb0b9ef3d1ab3ea598535b",
"internal/api/pbs_backups.go": "788600ff602866f7d5d70408fb7c612036cc6f9d7adde51d4a8ff84635597cc2",
"internal/api/platform_connection_shared.go": "d41aed940a10758167f68752c591225fc9c4a6034e49a0741cd673d417cfd4b8",
"internal/api/platform_mock_connections.go": "34a4a8176a9abedb42aba31b771252387b73ddb9d4c880d1a7d7328e5afa8136",
"internal/api/pmg.go": "efb9ad0037c196cbcf084dab03d3c31c6ade1ca4fa1904d0dd72a5f0493ef5af",
"internal/api/profile_suggestions.go": "b1fcf4548fc28303e9266faa3eecf2e632d1510d3b5cdbf3cddc66836f1ad8e3",
"internal/api/proxmox_guest_action_executor.go": "ddb70d949e8841202618d3ac3fd3dc350b03271701c93ac3a83c139c130e587a",
"internal/api/proxmox_guest_action_observer.go": "11b0146be21c9303315864d4ac0fe7ccf46ed3b1b380ea96e8933586a6e1db8a",
"internal/api/proxmox_guest_action_result.go": "b28f45e197f55dbb7072d229dc24ce70d73ed67dd3f511407f26fd7b091e9e93",
"internal/api/public_signup_handlers.go": "0e180ee90cbc7b65df2eb7075d76fb51c3f308331d2420c8e5a9cb3cce1393d3",
"internal/api/purchase_return_redemptions.go": "e1a0a573773ebb308f6406ad6bdb932f43d48519c1ec6dfccdf0c7cbbd899ca5",
"internal/api/pve_backups.go": "3117c78dbf940bb350aabc10ea999c05942749ed82c549969aacf829536fd012",
"internal/api/rate_limit_config.go": "503bdd861cdb50c917e3d613b56298ca7b83d6b3e14da7a5c774dcf2ab4b0e95",
"internal/api/ratelimit.go": "122c8ac5378e6affdf7b75e609489688bfbee6b019c1592c61a46c68baf9f6a8",
"internal/api/ratelimit_tenant.go": "2a8bd7b5ddbc757c5ac5606c220647b2447e56efd61b1f9f378b576f251c77de",
"internal/api/recovery_handlers.go": "553698c6c21e057adcb888a2fa15c7f488c3db217f3e9136b6bed2e61142b6ef",
"internal/api/recovery_tokens.go": "c05626028329fa15024190782af89eab37592ad080d37b9ddaf630504972e6b9",
"internal/api/relay_hosted_runtime.go": "f4ed4fcf2b2d152c8cbf76e90248ad2d1bd3767761f0f92b18c345307d3a5f53",
"internal/api/relay_mobile_capability.go": "04c7566f9beb22b39e47c5d2591079573ee8244ea554c680576017eb130883d9",
"internal/api/relay_mobile_capability_generated.go": "b62a514754ceb0b6e03251d4873f7755a44bb5dc81787d4f7c8eca4fcfd6dd26",
"internal/api/release_demo_fixtures_dev.go": "f4502a13aa453a50ea967a92959cc6c9013259bdfe596e9e0b9c50da544442d5",
"internal/api/release_demo_fixtures_release.go": "a3d98bfc68d10981676406d1916c13996636c5d5996cf360db26c5d1c14f9026",
"internal/api/replication.go": "9faf8ea8879dd79b33e516acd68f567559c50f7ad5c88e7c34317af9d8b01775",
"internal/api/report_schedules.go": "bc48321b39c6c529b0fc5fa8b0add899831c8574ea0f9ff8eb24c6c7c9fcd834",
"internal/api/reporting_availability.go": "1fb0c3161a742060848da9367f90d68d8c1192ad95111c0caa5c4bd1b40afde1",
"internal/api/reporting_catalog_handlers.go": "6f4bdc73f653c47e397cb6dd9b459523c094a3bbbcf2e9c5950f7fd4a1c1d05f",
"internal/api/reporting_inventory_handlers.go": "8651612acd744975b5b1f4b469a9949ec6017266ead3a29b5b1f6578189eeb85",
"internal/api/reporting_runtime_snapshot.go": "9398bd23e031941c9a6b8ef5cf7debd6a4d8c8e1030bb00ff4e9c3d9650aceb7",
"internal/api/resourceapi/k8s_namespaces.go": "78dda0edba00d8f4d951c0b45e2e7b438c408391dd42143d43bdab3eb107ea0e",
"internal/api/resourceapi/resources.go": "58664371f69e1728963fedab9681521beef12bfbb7d6f994ea0541004346d5b1",
"internal/api/resources_compat.go": "ff90db21381ea3b27ba2199d58f963efae7885e88416b2d6f540d86c2d57fecc",
"internal/api/resources_operator_state.go": "949e74e2698fd90dd8c0f47cd5809b37e95db40b48d3d37e4d4b53489dec0c1e",
"internal/api/router.go": "f1483edbff4d267088af6b6646e58106ca0dae3c6f750727e3c74a4b14fafcd6",
"internal/api/router_helpers.go": "a61f76b9dd9e7883778253bc908d6b6dff55bdb07ca335716a952da57ae89b94",
"internal/api/router_logging.go": "80251a5c997d1a46b21ad6b4291a2aea099ab29553d69553df95efa08a7852d7",
"internal/api/router_routes_ai_relay.go": "5dc12639ef3ff8a6ce2d8b1c0be3d9e83007929c413463d0bea14f141aaa0d94",
"internal/api/router_routes_auth_security.go": "24b6371975952cf6bcc83b2fbb16994104ccee1009bc3693a71c1d9ff9e137c5",
"internal/api/router_routes_cloud.go": "7a47facf452e9f08958036cae38664e116003f2df46e0614b7e84b1cc175db91",
"internal/api/router_routes_debug.go": "92b6bd7d50b829f99f3a1613b87f83727dc099cfe9d75ed2d3d80c82984f9821",
"internal/api/router_routes_licensing.go": "ab6853ef7ad69f1c80fd57022bc8db50964c4854131d9876f25d4da0b1bb8821",
"internal/api/router_routes_monitoring.go": "ed5d592961030cebc1e3851c3ceb94d0760d8ad3c427735132d8551724352f03",
"internal/api/router_routes_registration.go": "5dd74018d9f27552a8e619816825e66cfd66d5848618efd283b4cc15f3055ae7",
"internal/api/runtime_branding.go": "c7fd8070b0fc5e679aad88955c041f423a22127ea971522eb2e2655d245c505d",
"internal/api/runtime_display.go": "974c2c0ad1b4e2d07eec99fcd850de8e0edb29eb5c1e25afb29f487d4a8e57ad",
"internal/api/runtime_inventory_sources.go": "10140e2fc660c4631641152a48fbcb1ca3da68a97a5c205051647342b07ff12a",
"internal/api/saml_handlers.go": "a7f0f4a2822f04ba467597c8c6be71bae52e1727953aa45e96c2c037966f6b0a",
"internal/api/saml_service.go": "598d2e31c2280983984eceffa587feaf1dd54c10477c5205587a1fd0e5182592",
"internal/api/security.go": "4c1e22e52749ad6fac5173f11b51644c500d9195c2b0e2ae0ede7260022b006a",
"internal/api/security_first_run_reset.go": "6b3e04f3e6094a7b0a8a19e0e21a7adba16146cbaf5c266a9997d86f84bf126c",
"internal/api/security_setup_fix.go": "26a9bb880f47caedf850f93a8660f489658b4cf5ddf54202b8f3cd06c153116c",
"internal/api/security_status_capabilities.go": "a384aca3ea0ba7809b94abf7eb5dc6448e5c1f253341b1936d0d12ec5be818eb",
"internal/api/security_tokens.go": "6448fcd31ebd447ca2e01e79dffe614adcfa313a256db8710529cba5c2eb84fb",
"internal/api/session_store.go": "fd56ebc4131d60d7de022ad16ea6240016e35796aa7386b5b4e9a89798e2312c",
"internal/api/slo.go": "c9306f43058eaa2e29768a9e8cdcac06f7bbd6f10e1f9b76dadf4bec48f6ff09",
"internal/api/sso_outbound.go": "9920a49fed5a9415e099f6e5aa01dfdc5bff97212004fa269a71f35b549e724f",
"internal/api/state_provider.go": "56ad65a422d4229079ecc1701c3170bce90e9893f2bdffcd69045967c3c4256b",
"internal/api/state_summary.go": "0da03832e2844b2b4b3d4e659a48aa540664f7ad7671251a617e46fe28ca1a77",
"internal/api/subscription_entitlements.go": "0314f3b64ea57ad3315317cedef28518f10fa54e0c7621097ef8bd5f8cb5bdf8",
"internal/api/subscription_state_handlers.go": "c7b8f94368d62a582e9e2a506c1bfbee2b220cba4a54c129b5056955949cc498",
"internal/api/subscription_state_reconciler.go": "0b66098ee91e87681273f2a9ad6d4ea027a20a99e09e42baf89df0099f94b3ff",
"internal/api/system_settings.go": "c71814a15c49c5da3af9d541d1fea492cfac9131d1a082023cb5eb9e4e0f22f4",
"internal/api/telemetry_audit_reads.go": "7cc72c7428e5bd4fed58c6c0a07a0033d07b324741e9e626fb8a7b2565c6fe98",
"internal/api/telemetry_licensed_features.go": "b11e211705a305d70aaa6977c603fe91aefa9628bd7828c05c2052ffd5f37f2e",
"internal/api/telemetry_pulse_intelligence.go": "0d2dff2276a1d8cbcb07cac9b064343b4896cbb01bc4a53f6eaf5c31e094e3ce",
"internal/api/telemetry_workload_history.go": "62ced9db02d0e04e6723df6142cd6decec9e43c991f5b44a61579e0e73987dd5",
"internal/api/truenas_app_action_provider.go": "ff6b2709ced8ea51887edfa2b1fc4770dfc76b8a5b45b7479e012945fdc5cfd3",
"internal/api/truenas_app_config_provider.go": "b34c12a919c3b9d4ddc8f660ddfa99a06450c8a6ee6269fd93db71ba03b9c3f3",
"internal/api/truenas_app_read_provider.go": "cfb4875315002fd3133b463e27ea09fca5d6dd608ef7954aa8a65ae28aad25bd",
"internal/api/truenas_handlers.go": "bf58c69707ada9d6692861f34d71c1eb2ff32cec0a150d1f331daf2edda3edd2",
"internal/api/types.go": "a5dcb11c6618bd8eaad2eec59cb46d754ddd160e5463987e7cbfa88846cc2ac0",
"internal/api/unified_agent.go": "3ee6bce5cf07652ce1072958d7f4e26183cb62bd8c2cafed3b1903181894bb00",
"internal/api/update_detection.go": "cf8567ff9f6cf3e1902d4a594c48b3fb58bdf6a53c1273e4fc6b386ba615a88f",
"internal/api/update_readiness.go": "f308b143c5c4ffe9344c9c4bbac7a84eb080a33d7a3b55229843e945f3b0c756",
"internal/api/updates.go": "a933c93ed496a401e7fcda3f527443a39e9628dbf64dcc36decfeb8b8d0d25be",
"internal/api/user_limit_enforcement.go": "a4065221e976cfae80182d88346bb9a369777fa5e9fe89d76fb3f310b04cb3a6",
"internal/api/vmware_handlers.go": "a0606e09b10bab5fc899bb42cb57a1089b5a6b1248a52bf46c2c50ce9b613751",
"internal/config/ai.go": "e773d1d1b4bede3aae9a5e1ec640f82c0992826b2bea964724f5de61c01e9ed7",
"internal/config/ai_providers.go": "994c8430b6084616b69fe702bfa4a1602d83e5c37dc60039ac1879e076714eef",
"internal/config/api_tokens.go": "f333752b6da24a85c4342332a8c656cf86d83c8cab45d49d36af9f182fb8af0b",
"internal/config/audit_read_activity.go": "b8fc44fa443112fa94e92c2a2516bd149b9aec12ac7f4b48f87752f9b4f4817a",
"internal/config/availability.go": "72cd69d132a39810940f19c6df10712a0754e6187e2c0bf6b247eb2777217900",
"internal/config/billing_state.go": "b244ad2167d87a20b63189665288008cdbdba3dc97d783add0b9e390ee690a63",
"internal/config/client_helpers.go": "8dd2444ad85af9347f5481bc9c80aa4d91e8eef64f6c966e01a53d3676834757",
"internal/config/config.go": "038725360ef71c31a22d1d79f6b370af07bd25112432b5d8b389ef57a6715818",
"internal/config/detect_root.go": "b1e09c43ae7a8b23edf0639b7c178bbfe8d6db307ce1a0d6864314673c9e4371",
"internal/config/docker_metadata.go": "f6a45c123ffeadbe3481ce5fb744c96afe6a2b2cf2f8f6f400b3913aec78c98e",
"internal/config/entitlement_billing_state.go": "aeb581849ec36021de82d3f3a74eb34bc8051464c5002cc978813a212f465034",
"internal/config/export.go": "8bd4cddcb24ff552185c1e8c7fcfd8ef445e048cb794ad45295f5616945782b7",
"internal/config/file_read_limits.go": "74b877ff7dbd5a7df01edf79fa4033e316facd6acdaf2af01116d4367d48478c",
"internal/config/guest_metadata.go": "63b71837469c85b90e8c7f1f797323b53981dc5e2c6bf414030b960d8910cd09",
"internal/config/host_continuity.go": "cb8408fa70784883a4a62ffd3d7818e16281795d580ce6b9830826a440a14921",
"internal/config/host_metadata.go": "2b3a6f22f9ebec79b69d1327f7b64468e923a1a7fe41e04e88272cd92d7548fa",
"internal/config/import_transaction.go": "c1d8b15b66bd8ec3ca44972d2ebfc45055060ddb37ca9de01f8ee0c0b517740d",
"internal/config/metadata_helpers.go": "73849782962c0d2dec8b8750b4a8ab8c094371536069758eca641a450961743f",
"internal/config/migration.go": "0d48bed7a34c505e413881ebf5cc731aae2ed8d580d0d4ac4bd39422b8817138",
"internal/config/multi_tenant.go": "1873996b514af326a15fc9205f9dee714e3d556ee66db2c8dcb028100c546b6d",
"internal/config/node_test_tally.go": "67ff9908c0c9c5689c23d872d7ed07753f3a117e54aa69de06834346316cb75f",
"internal/config/oidc.go": "11bf532dea4a9ea0f65bef5397dad28629cf79d7b2976d156e2b06589b84e49f",
"internal/config/patrol_autopilot_persistence.go": "31a02f3070cbb4730380efe8e3a4193bcc637c06409c58fc2c09e0f2128ebbb8",
"internal/config/persistence.go": "7271dab3607bfa15312c08e15d8088cfd9278297af10499be4790c56abf55e14",
"internal/config/persistence_alert_intent.go": "187f0e264add73555bfb5c42593b7dcfd841eccdf35c9ecf6eada1f6bac98b43",
"internal/config/persistence_installation_scope.go": "a146e20278fe009166015bc608d34ad411ccfa3ac2884bdc610e96c13807a75c",
"internal/config/persistence_metadata_accessors.go": "51822e30287c314cac91bf822246a3a82d978335697459938b481f7516216b98",
"internal/config/persistence_relay.go": "5874a46e7900b27934fd402533e1a6d7a7b54a45cff25b50f067926579d95c21",
"internal/config/pve_instances.go": "b740964482aaca40d2de5f7f772b79ae093f3e90e4d5fc4aed50c05cf7df20a3",
"internal/config/pve_node_identity.go": "8971e149c1e0c668c2fc8c25abc9b7e86eaf62f0fc19ec0642f4336c9ae8f1d4",
"internal/config/report_branding.go": "bf774484179ab2eadb833013d4b467c10e0af4363a1f220af0e0b2a606d9984c",
"internal/config/report_schedules.go": "1be7c9b681d21a68227d712eaee590d546c5a16bec09dbe68cab3755bb114a8b",
"internal/config/sso.go": "281fa3c5b27aa9dc2ca54c575c800f4fac7397213621540dfa394e4c825e7d30",
"internal/config/truenas.go": "5ab9f0203f8910ffc495ca4249fb36a758dfb3147ce934c514ef3dd01b41d498",
"internal/config/vmware.go": "a29600f8e229ef83577224ba943da9630db0e88203c8e1569385c33e5d485744",
"internal/config/watcher.go": "8efbdc2dcbf9fba9a04ee298bc2118a6ec20c1c4bcf07c5b8a9d2158a2a03467",
"internal/config/workload_history_activity_tally.go": "a2b246c6c1218d6b754cd1bc62ac820ccd6eddb072f14ffed8c5ed1cf9c194e0",
"internal/hostagent/action_runner_client.go": "1a6231c7fdef1c4595b2f0e6660d077374769fa45c0d429d0ea84440a9de3d57",
"internal/hostagent/action_runner_health_persistence_unix.go": "dbc8eb02bcf7129d36a7a6ca91f7abfb102cb6dfbe3ac66b52b74303a06b6887",
"internal/hostagent/action_runner_health_persistence_windows.go": "f16fa2e9f9a2f8aa675777f36582087ead3051e04cdc805ffe7e9200191e9184",
"internal/hostagent/agent.go": "500b7bdd10a2a93b598201e1716e5ad84f98a5a344c9247a5ecab71ef67323d2",
"internal/hostagent/availability.go": "eea45d12922b6859492f562dcfab4dbe248b32a92bc5abd002b5ac51422fdccf",
"internal/hostagent/ceph.go": "fee9561bc972b7bff11a9e87ad879efeac0914fb24b63eae0319f495aceb68f6",
"internal/hostagent/cluster_sensors.go": "6d6104dd2046dc6f9626d2f08f6990923bfad9b37f8028e555b590e368316e26",
"internal/hostagent/command_authority.go": "212ba17cef8beda1cd6250067513ac4ab68faa808844aacd7e5a03691f2dc9a3",
"internal/hostagent/commands.go": "03e1da3a0874645cc8dda0fd03ca307ba754ce61ecbab731e74513822b11b4f0",
"internal/hostagent/commands_deploy.go": "73ac6378c23ba4665dd98459fb941691b114be9ffd2307dbeb8c7ffb1bfd9571",
"internal/hostagent/commands_procgroup_unix.go": "1303d4227ded53ac3668b7a15092d50ff92cb3ffc581d594f9de2ee633fcd884",
"internal/hostagent/commands_procgroup_windows.go": "a2137b47610613beb3748b19eec798091081a800cf162b6f6bf1de9ebf6f40c4",
"internal/hostagent/custom_sensor_security_unix.go": "fa4175df3610c35432a60fdb5c0935800b995b6f89556b3ff00a480999eaf896",
"internal/hostagent/custom_sensor_security_windows.go": "e8ce8bec788b28c75d1734ec7746ec0f467919e05da10d5c382d31fca71877ba",
"internal/hostagent/custom_sensors.go": "301f134d27f8766bb671e4a6576d09f4894916547880585c312c227d3cc68166",
"internal/hostagent/docker_lifecycle.go": "3c6f4ebbbd3ebbe48b29deae6fdec4648e7c9617e5cde0aca432a210997df6c4",
"internal/hostagent/docker_update.go": "03324b0ca29b63609d6078bb5900cc501ab40bed9ff1c46c50992b1d07e0f539",
"internal/hostagent/enroll.go": "5d72a553cdaad74aa77942404c7f1da7537dde0920dcabba0bccc927bd8d36b9",
"internal/hostagent/libvirt.go": "0c4ee6346169e06bc26d2e006ff85cc7749da435c2f59db17adb8c4ad334d7e5",
"internal/hostagent/mdadm.go": "f2714ec89953361aec92cb09dfaaf89b25af97eb24360c5b464ba723f3261cf4",
"internal/hostagent/nvidia_smi.go": "9a4c4657604f1cf0d365b64a6ac4b289b21fc7cb7b7ef1b85888bb4381473beb",
"internal/hostagent/os_identity.go": "0ab3306f5219ec8534cd4862962297169df055e1d62012ac999c01137b374bdf",
"internal/hostagent/package_manager_lease.go": "e8879c39780a1712596cc8dd4ce25d45f28eef6c698878bb20a9cd1fd4aecbe2",
"internal/hostagent/package_updates.go": "64e0f3042ad176a874c724c91e05d7012b4c5f3b08d4df15d00ae29ea327423a",
"internal/hostagent/privilege.go": "9973b39fce82be4989ae64515d43bbfd4e3195330d64a388573bf7ebe69454dd",
"internal/hostagent/privilege_helper_client.go": "90313c33de1006895fbe1cfa001943b5ed79a02f5a7f296d529d9862de2b6cf1",
"internal/hostagent/proxmox_guest_lifecycle.go": "14d0a882859a44b3f3ff300c6f547db77e966881b742003fcb3e52db04431a89",
"internal/hostagent/proxmox_lxc_filesystems.go": "101007cd8ff35cb2f7d80140aaab0df162092ddd27d7c30bcb9972f28763d0ad",
"internal/hostagent/proxmox_lxc_filesystems_linux.go": "05424af10374cff45163a25eb8149e1bc2d3604b336b5f699a3fbaa480a2615d",
"internal/hostagent/proxmox_setup.go": "6101db7876fa63f305d27276ea8193e35435cf485f628a196048b5a9b9636391",
"internal/hostagent/smartctl.go": "83d75343e1a7496d987f128f4084f290de81db2a6cc63b463528207696dfb1d0",
"internal/hostagent/storage_cleanup.go": "6bf8a9457ae63fb4cdf375660cb85a15302aa29fdc303e1ed9a2cfc71abf3c0f",
"internal/hostagent/sysinfo.go": "768558142a26526f99edc0e55e8408e165e6f272b8bdb63d871d1659a3f08b44",
"internal/hostagent/unraid.go": "e317ae5ba0432e1cfedf853ee69288473631e5cd0300910a9c0f54f54ce32e6f",
"internal/hostagent/version.go": "fd06f8a2f9360b1e82a0687f76fe13f6b16786a2e2dca3fbc5d668717ec6b04b",
"internal/hostagent/windows_librehardwaremonitor.go": "aa9f67de011c2f23ba7ac1ffd66d566c12bfc920446b1151b8d08abe02349c9c",
"internal/hostagent/windows_storage_sensors.go": "c0b43fd797a79887c7b24f18f36185b35885d1328b207549ab7f3eae05a00789",
"internal/hostagent/xcpng.go": "24334380d87e6e0ea0559e03ffdcb5ce754f1f23340038ecf482758d6e51d28c",
"internal/hostagent/zfs.go": "75fe80d6fb8c2ecd7495589bf006800065f0c51caa3c454c3ccf828e2d905437",
"internal/operationreceipt/store.go": "6f40b4422fde09e81fc989b9b5f35066ebb3276e20bb0903a554414b69e6f6fe",
"internal/operationreceipt/types.go": "08b86678dfe55b5ec29c94ef96de15e9e3f416a9db656481f8ae833b38538dfa",
"scripts/install.sh": "63d1609fd1a3c02d07ee9034b7f177b4f00e523c97ea91b74bce2946407c5c9a",
"scripts/installtests/secure_runtime_systemd_lab_test.go": "5f6929162d8067c454b6c676481c6fd739053565c910419da65ee85e263c454a",
"scripts/release_control/secure_runtime_attestation.py": "f83c545a95dd6f9c46b4c676e1c28a2ae9b7a8a42ebef11b0af914d580ccecf1",
"scripts/release_control/secure_runtime_source_manifest_v4.json": "243e6c85640dec80082e3f1bdc5983912c613ad97ff9e9292b110a9f1411bb45"
},
"artifact_hashes_match_receipt": true,
"artifact_hashes": {
"collector_v1": "6ebdbc3b54c9cfdfa69419024d676d239309c8b100e614bbb1c5d7d58ff244a4",
"collector_v2": "d11bc3387cfe4cd775df00ab4ec869aa53c2b9a41ff82186d67347b7a1d24b7c",
"helper": "717faf13d6931b048ecc545f2064919bde61ca891c7e53fe36989a91085d88d9",
"runner": "baf14412a7c8b74ad5ab70c3eab15a106d46ec6e6e742df38a11fc2671156a46"
},
"artifact_build_identity": {
"collector_v1": {
"package": "github.com/rcourtman/pulse-go-rewrite/cmd/pulse-agent",
"vcs_revision": "defc24af837b91428fbee939d09cd31e9559fb4f",
"vcs_modified": "false"
},
"collector_v2": {
"package": "github.com/rcourtman/pulse-go-rewrite/cmd/pulse-agent",
"vcs_revision": "defc24af837b91428fbee939d09cd31e9559fb4f",
"vcs_modified": "false"
},
"helper": {
"package": "github.com/rcourtman/pulse-go-rewrite/cmd/pulse-agent-helper",
"vcs_revision": "defc24af837b91428fbee939d09cd31e9559fb4f",
"vcs_modified": "false"
},
"runner": {
"package": "github.com/rcourtman/pulse-go-rewrite/cmd/pulse-agent-runner",
"vcs_revision": "defc24af837b91428fbee939d09cd31e9559fb4f",
"vcs_modified": "false"
}
},
"host": {
"os": "Ubuntu 24.04.4 LTS",
"kernel": "Linux 6.8.0-117-generic #117-Ubuntu SMP PREEMPT_DYNAMIC Thu May 7 17:26:37 UTC 2026 aarch64 GNU/Linux",
"systemd": "systemd 255 (255.4-1ubuntu8.15)",
"architecture": "arm64"
},
"scenario_count": 12,
"all_scenarios_passed": true,
"test_elapsed_seconds": 107.0,
"default_changed": false,
"residual_proof": [
"exact-release-candidate",
"representative-provider-and-appliance",
"external-security-review"
]
}
@@ -95,7 +95,7 @@ scenario outcomes. It proves neither a successful action-runner host mutation
nor the post-audit credential, rollback, update-artifact, and runner-unit
hardening. It is retained as historical, hash-bound self-attested evidence.
## Current schema-v3 committed-main evidence
## Historical schema-v3 committed-main evidence
A newly created disposable arm64 Colima profile ran Ubuntu 24.04.4, kernel
6.8.0-117, and systemd 255 from a detached clean checkout at committed main
@@ -121,11 +121,10 @@ session invalidation remain established by the focused API regressions rather
than by this in-process fixture. The receipt remains operator-produced,
unauthenticated, artifact-bound self-attestation rather than independent proof.
## Post-audit schema-v4 acceptance floor
## Current schema-v4 committed-main evidence
Schema v3 remains immutable historical evidence, but it is no longer accepted
by the current attester as qualification of a newer tree. A future run must use
schema v4. The committed
by the current attester as qualification of a newer tree. The committed
`scripts/release_control/secure_runtime_source_manifest_v4.json` expands the
production collector, helper, runner, host-agent provider, API admission,
configuration, update, and receipt roots, and the receipt must hash exactly
@@ -134,17 +133,40 @@ times, typed causal claims, and an exact reference to a retained secret-free
JSONL transcript event. The receipt also binds its intended repository path,
the transcript path and digest, the typed action receipt kind, report count and
report chronology. The attestation preserves those bindings alongside the
artifact build identities. No v4 live receipt or attestation is recorded here;
this is the acceptance contract for the next exact-commit or exact-RC run, not
a retroactive upgrade of the v3 evidence.
artifact build identities.
A newly created disposable arm64 Colima profile ran Ubuntu 24.04.4, kernel
6.8.0-117, and systemd 255 from a detached clean checkout at committed main
`defc24af837b91428fbee939d09cd31e9559fb4f`. All four exercised commands carry
that exact clean Go VCS revision. The guarded lab passed all twelve scenarios
in 107 seconds. Its 345-source manifest matched the qualified commit, and its
retained JSONL transcript contains 81 ordered events: twelve scenario events
and 69 raw command-output events.
The secret-free schema-v4 receipt is
`secure-agent-runtime-systemd-receipt-v4-2026-08-30.json` with SHA-256
`58da80f7d75d414c12cf6632bd895b821ce759625e7d00ae00c16d56204b1e76`. Its
bound transcript is
`secure-agent-runtime-systemd-transcript-v4-2026-08-30.jsonl` with SHA-256
`616681aee38202ed922880288b730cd85f746e081f8f9d45bb2d570e48b49f8c`. The
separate `secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json`
has SHA-256
`a48e855fdd2dcbc0cf91717dfaed22f942320c9661dd9b9e8f8f8e97f45d654b` and
verifies current-main identity and ancestry, exact source-manifest membership
and hashes, all artifact hashes and clean Go build identities, ordered typed
scenario claims, receipt/report chronology, and the receipt's intended record
path. This is new evidence for the exact qualified commit; it does not
retroactively upgrade schema v3.
## Proof classification and residuals
Focused regressions cover current code-level semantics. The schema-v3 guarded
systemd evidence covers only its historical qualified commit and the explicitly
exercised subset above. Neither is a substitute for exact release-candidate
reproduction, representative provider/appliance qualification, or external
review. The canonical support and residual matrix is published in
Focused regressions cover current code-level semantics. The schema-v4 guarded
systemd evidence covers only its exact qualified commit and explicitly
exercised fixture paths. It does not prove helper-backed update activation,
watchdog or interrupted-recovery behavior, nor the production Router over TLS
with durable credential persistence. It is not a substitute for exact
release-candidate reproduction, representative provider/appliance
qualification, or external review. The canonical support and residual matrix is published in
`docs/AGENT_SECURITY.md`; unqualified rows remain explicit blockers rather than
being inferred from the generic Linux result.
@@ -0,0 +1,664 @@
{
"schema_version": 4,
"record_path": "docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json",
"started_at": "2026-08-30T18:10:18.105761661Z",
"completed_at": "2026-08-30T18:12:04.297039052Z",
"source_manifest": {
"schema_version": 1,
"manifest_id": "secure-runtime-linux-v4",
"path": "scripts/release_control/secure_runtime_source_manifest_v4.json",
"sha256": "243e6c85640dec80082e3f1bdc5983912c613ad97ff9e9292b110a9f1411bb45",
"target_os": "linux",
"target_arch": "arm64"
},
"source_hashes": {
"cmd/pulse-agent-helper/main.go": "3da1978e6e70d29cc22f070c5ada1f6a5f516f6a6643a3b27f23a4adf9ade866",
"cmd/pulse-agent-helper/providers.go": "0a179a2327cca2660f5f24ab3102a7c55ba8c87d06bbfdfd8eff2b206b9b8f88",
"cmd/pulse-agent-runner/main.go": "33707517965ae81a8b42ba86cac98e665f376a4c176572e1f558862cec82c460",
"cmd/pulse-agent/main.go": "73527ea1c0513804fcbf64fa1b924fa7f29dc5441cd98ed2c0e2f53ddd621ca8",
"cmd/pulse-agent/runtime_health.go": "64de01be0472998b5f58b49a446e22d20591802f2679f342da7fb8f2628e0c49",
"cmd/pulse-agent/service_stub.go": "3674fde8d348a121fa6ac278d235ef1634d944dccd44184fecf70cbc5ca818f0",
"cmd/pulse-agent/service_windows.go": "59ac578a598113edc7263d47cfcee5bf3806e2d6310eb49fa8f8a30a8bff8a73",
"internal/actionrunner/runner.go": "2478a333b557c7a50c49e58d0e2872bc5f702bf984b90a94a51396e538e14ef8",
"internal/actionrunner/transport.go": "6e39ea82bc0b31300e9bdbcc3fed5c1fa2348166bbaf6ce0e95ce5adb44ee5d0",
"internal/actionrunner/types.go": "4d52786233ee15d5c832a03980dd9ac460cf76d147f2aba6a8336d06d2f9aa48",
"internal/agentexec/action_preflight.go": "6a2ce9fbbe514e5b70537f6b07ecd16796416a621a0712b7ee4185cf3a5ca7ab",
"internal/agentexec/approval_grant.go": "7a30d1d4699e4a92fcda5edbb972cbb821f3e627241158ce34b970bf2e47f650",
"internal/agentexec/apt_codec.go": "51525b97672d07cb520f1cdb7ce7749c1f0d38629552e3895133a23b6f2f73f2",
"internal/agentexec/docker_lifecycle_codec.go": "c6857d25272add6acfe800ff9dee06d2a812403ca930fd4f9beb0ed9ef5757d8",
"internal/agentexec/docker_observation_codec.go": "dba73ac04672cfd7359de9ecd9ac88a02d42896ca6ee6febe6b40b395bd10cbc",
"internal/agentexec/docker_update_codec.go": "84824476c1e4a250cfebab0b709e60876705141a243af1a2854570b2692f8e16",
"internal/agentexec/export_test_helpers.go": "516445912c3ed26ea71235888a77eca88f90f05dc9d78510f3faa0c97581be41",
"internal/agentexec/policy.go": "f84ec5bf77b33202a0a51907507be93893a4d6a52a291da83616f0936fc15f28",
"internal/agentexec/proxmox_guest_lifecycle_codec.go": "e29463d4f151a3f478c8b9123f5d7e47ecaa88c1b90fc41a2c15f3e9a06fc18e",
"internal/agentexec/server.go": "b252ed4b972afc648f713ea0ab7d1feaf617b7dd4fef3a2ef87e2fb657b90d5a",
"internal/agentexec/types.go": "428a06918af94c803c720d282d5123149e70c5bf2dbdfd06613495d54d8f9b0d",
"internal/agentexec/verifier_postconditions.go": "27f68d4f05e45803f65a1dd3c7e38d41ca39ab88d9f1a574dc4739911b8391cc",
"internal/agenthelper/client.go": "1192d45f3f93a59c07d7d6189767bdc53ea57f8660e0f6558e8dc97b06f420aa",
"internal/agenthelper/container_inventory.go": "ece7672977a3b9584273a942f7ee903b926af500bf80cc0e43784952cca62dfa",
"internal/agenthelper/file_security_other.go": "0bd44450f28b3fbf9eba13bd2ef13773faec850f91518b134770268176400051",
"internal/agenthelper/file_security_unix.go": "457094f8010691b17e08c95aa7191202dff5079e8054ae75619e6c1494c6307c",
"internal/agenthelper/peercred_linux.go": "31db3ba3b565ac9fac73ae7ce94c423cc3fd25791da81c5821b9db10ced94a4d",
"internal/agenthelper/peercred_other.go": "983a2c51fefe378d2605061e17b254825554f28f3b669bed58c36dd13f1ab204",
"internal/agenthelper/protocol.go": "d7a6548f2e7f91d6827b582d5a1becf24fed6ce4c57de0e4c16b3b4fd52bda0d",
"internal/agenthelper/providers.go": "f1ed8226b817b0fa7cea71ba052808be5e4a2e1cab8298029b3cfb1e932fe856",
"internal/agenthelper/registry.go": "0d9a0be8b33e86803daee782e4bffe4e691424c692df25603f4c8ed821d363e1",
"internal/agenthelper/server.go": "70ef4f2299cf5d3347520906e62e8d7307d67624f60232c9bcbafbc6035e3ebe",
"internal/agenthelper/update_activation.go": "cdaae1da9459d5cbbd9f84dce6e6e3234bc03ed4739e78292161d2faa98d2445",
"internal/agentupdate/pending_update_persistence_other.go": "cbfee489c1050744ec440df0627ee0d6cf349efaa57387fed31728504f71a297",
"internal/agentupdate/pending_update_persistence_windows.go": "d5475a26f8446f3c45c869a71cbde79e83731edb3b4e32fd952fb94d3c454211",
"internal/agentupdate/privileged_update.go": "1e27b3d94087e85139dfbfeb86b78e6444ee9b80bd97bdbf698d0d2dadd6c624",
"internal/agentupdate/privileged_update_owner_other.go": "460fcc9619f53d79bf598bc31c4fc34c5ce5bd8fed2300d31b1c6a64144e3a29",
"internal/agentupdate/privileged_update_owner_unix.go": "875f827dd9106ab4aee70b564d264505d76e993e019ec08c687a6b3e823df896",
"internal/agentupdate/restart_unix.go": "cff57a8ee74c0d41e374c40ea8808487095988df118727d95a888f0da1a6d205",
"internal/agentupdate/restart_windows.go": "5d515fb21beb45c82ce6197b2d3154a8f0d9d8ffae86125ac1516a7d0130f3d8",
"internal/agentupdate/update.go": "ad885a99ce679fc30c5155147961f1e970fec031e25f5b69ea9814795d2f335d",
"internal/api/access_admin_handlers.go": "b5ab4a4ace0c3290a49d370eecdedf8b2de8ff50979ce67e25ab4f5589440e6c",
"internal/api/access_admin_recovery.go": "304f63c863e2c5a8104e4da097d4bfbf7e6d400fb7a153bd3ddbe4a59682053a",
"internal/api/access_control_handlers.go": "5ed98baf5f5914f5a5cf9127426ec24b4710fd49dad456844c2502b87e3b5e26",
"internal/api/access_metrics_handlers.go": "9418de69783686f5051a66936d79059b68ba373de8b249d1591292919ea6a849",
"internal/api/access_tenant_provider.go": "1dcb5fdd875e2c41e257e20d41f77c3f6dd6e7cc7787468e0c36c9cb2330b7fe",
"internal/api/action_authority.go": "0a54504b9d8a4a3beb61b9a9329225e5d684ab9eeba70a06ecd22fb0dc8f2db5",
"internal/api/action_executor.go": "be19d610a0b5614b6cacc3239ef60baa88d3c092bf56f322a7e849ba85870e39",
"internal/api/action_runner_credentials.go": "14ff066b3ad8af52c63081f070d2f92c3fdf90bb5672c0a02314c91fdf59ac1f",
"internal/api/actions.go": "0ea3967610dcf5fe00e678a97a982949247b924f3bf1732019aaa2eec7cf276e",
"internal/api/activity_audit_handlers.go": "e314a619e7cdbccad71c5ca0aff2eccd864ed05977e2bc41ed3f043387e4422f",
"internal/api/admin_bypass_mode_dev.go": "05f390ebc02e1ab63661fc3530c174328c72e47ed616feb0f28e2d853c5961db",
"internal/api/admin_bypass_mode_release.go": "8deadaaffd001e014830eb30c46c226fc42700593e74c7e6f8f4fc3d06ecc40b",
"internal/api/agent_activity_telemetry.go": "cd837430d51120c2b1a97341234f4bce44653e2040552122ce2ea6e4ee6c0003",
"internal/api/agent_capabilities.go": "21d6b1925ca458781313d77928f277db2d6225bde1f55dcf1c06dc3e6b8cf5d7",
"internal/api/agent_command_authorization.go": "4e575a2c51d9456e97c531575c243045030d252d00a6c4711362e11e4c5c427c",
"internal/api/agent_command_redaction.go": "623788c5129289c7197e220e41326cba96eef6e919393d50df7ec1824b74c137",
"internal/api/agent_events.go": "0cee3893be3a01d8de0082eec541926544989ffca5c7b2dc8bc056a02c59da19",
"internal/api/agent_exec_token_binding.go": "ac230d99f65616e9134e8942cfe36ddce9e202b63c420c64f2ad0136aaa5e791",
"internal/api/agent_fleet_doctor.go": "425e391fc251ab756e12b6c8196f24c763e4f931ad50c3076d35d2c13d31c840",
"internal/api/agent_handlers_base.go": "c2c834d051715e070febf99b26420050bae08bf4f14c952d864ea25c26a46689",
"internal/api/agent_ingest.go": "79e7e1ee3c8f741fc4e0e17b7d1db3f99ceecb38019f1ebc9176ea8034dfdc97",
"internal/api/agent_install_command_shared.go": "e49ed243070e76d143c9dd96c6b517a08a12a777d99e8c470f0a96b630ff1204",
"internal/api/agent_profiles_tools.go": "31ac7cc3711ec77810d7d6ee530896a25652a350639e60f6ed26c35ab9e05d49",
"internal/api/agent_resource_context.go": "b80065c925cb4f9e95df6f771c1d4636fefd425f9e3d7a0e19b909a72b165501",
"internal/api/agent_version_shared.go": "40e268867f6a7272890e395bc0a97ac00504c41ac81257b60c8826a2d11d5330",
"internal/api/agentbinding/policy.go": "30ead686f253b70dfdca81de13fe329ffba1641141672b6ad8253c4bf88fcf20",
"internal/api/agenttokens/install.go": "fbbb178b7a214562dc88038e1dff0db47faf1664e48d3c2b64e884f52b533174",
"internal/api/ai_chat_transport.go": "b8cd204026714ae1d395cc07f64e0248322b5d24cbb9704fd3a3dea6dbff1eb7",
"internal/api/ai_handler.go": "a9e78b9788c362ffd8561105a36d8b6c0919f56396e7b88b4d8d5268a81bc2a9",
"internal/api/ai_handlers.go": "59d7cdb5af3060f451ad61bcc23e872b6de0575fdf9af12b98bc1a903b92d036",
"internal/api/ai_hosted_runtime.go": "a746418338ceaf577fc5068e34a30819904ae7f0ea5fb1002cb0c27cea0dd6c7",
"internal/api/ai_intelligence_handlers.go": "d9dc1cb7b1aa30ff406307486052f6d5a024d26e90ef6ea2625cab03f0529bf9",
"internal/api/ai_resource_types.go": "78e6276305c4b93bc8fd091c953e58f27417ba75e798a437061d35f6b78fe267",
"internal/api/alerting/alerts.go": "cfa499011224cac15b74c26004fdf6cf6718de380a797759a67d92a2b1f7c2d7",
"internal/api/alerting/external_probe_notifications.go": "3043d331aabf45350f9902acf69c315f4e594d06df7a62b38146bde4dfd8c8dd",
"internal/api/alerting/monitor_wrappers.go": "b1bd97d6a046b30687ad404403cb005be8d61110d605e459aca565fe3f80c43d",
"internal/api/alerting/notification_queue.go": "b1c61e450220f4c5f2b93e2f5907eeaff38e463d0f4fb2a9fdbd562bdd28f995",
"internal/api/alerting/notifications.go": "57fb6046a9f7f9b7a8e4c7a9e5437715ab0a4ad85e37268ad1e09d1c85ab6560",
"internal/api/alerting_compat.go": "7a86c8f7f9a243364159b17f8aa0319b4e4fc61335e2bebc567df4a6985514b6",
"internal/api/api_token_identity.go": "adffc3d27d0359cea29ad14811c9bb82078e30b54ac8ea0e4a445ad307991e50",
"internal/api/apicontext/context.go": "5069c811226ed6654fe3caa99e31fc43e001a0599f8d2275be8773d627d5cf5a",
"internal/api/apihttp/scope.go": "22a7a0af30c656ba0ec7b3ed33d6e5e5456f48b09cf06c440104b7e2a354a7b0",
"internal/api/assistant_typed_action_planner.go": "75f11f96af5eceafce0b80850543f3c976d70b54c193eb7a579cc384a0e6e7e1",
"internal/api/attention_actions.go": "9ff650484508ab4311e824a07dcedae29353543da52f095af78fa1662142a22b",
"internal/api/attention_evidence.go": "dc6b4f2a8a406cc436a33c8c6a1db84204fdbf8702639a1a82f9f7050a399348",
"internal/api/attention_handlers.go": "449ae73617a1bcd191b66909f8b928cd0f739b5c31753d0168183707fd021ea3",
"internal/api/attention_mutations.go": "ca86d76b97d2c72d3bbaf1d4a18d58559bf6f05b8992de62b2f56eac64625210",
"internal/api/attention_receipts.go": "bc177a9d2ea1b1e3feba114329a8f066fd12a564f9c8aeb3666b4bf80c63d08e",
"internal/api/auth.go": "8f6e771181541a252ae478d65d74e97645e86ba9b905f3f81b40c11db074bff4",
"internal/api/auth_denial_signal.go": "cb93d6742af2947dfd5310cdb4df7d035c7950a284cb34e5cbc96f1b889b8d06",
"internal/api/auth_env_path.go": "7938bdc69252a494a1965bbd0ff9d53fa943ae1d4f5160f0257518881d2c5d63",
"internal/api/auth_principal_identity.go": "2dcf138e9294e357ab0abe0d66b553a620752d77fe608ff478be64fd0f13bb2d",
"internal/api/authorization.go": "49349007b4868090373ba8ae4ddca7ef245c1820d2d2fc59db232b1d213b6612",
"internal/api/availability_handlers.go": "68ead5fc26bb34f85a8509e5431d17b1e1c96cef8a32b668759c432d641f4ce3",
"internal/api/availability_history_handlers.go": "dd87da2d197fd085794afbee160dd7706ed3a470dc25d3bcb63936726f7be381",
"internal/api/bootstrap_token.go": "30a338638b388f3b7f24c4f52541683d7807e36513210f6d12969cc63180434b",
"internal/api/chartapi/payload_cache.go": "0562f08e45a44c7a1b8648918f01103e494d0fc2c6e8b3a4a2cb059040ef8189",
"internal/api/chartapi/service.go": "1018fa106466fa4148f390c1a3f7f8f34ebcf52ed2667b524fb5f09f52659af0",
"internal/api/chartapi/types.go": "19204522a2d4303436e335e8b7fe339e2aabfe9601a1508d0be4928c55148643",
"internal/api/charts_compat.go": "e96389b7b9d5543452f9aed7d0f57eb539e6806bd16da9e1e9bcbb4da5819f9e",
"internal/api/chat_service_adapter.go": "ca729ba9bd98da4770343f5ca0095bae92478f7578c461ba5cfc05e111af608f",
"internal/api/cloud_agent_install_command.go": "295de654650ecf191ac4d3c57565f6fdd45f05c3f42c086b80efe7bcb04c6d07",
"internal/api/cloud_handoff.go": "6b6477b33a04588cdd46b5f5ca0d25e6c0b41e2e937da22253778eb44a385dab",
"internal/api/cloud_handoff_handlers.go": "1c3e12ac5465f81f60816f57e0bcaed5682edd07694d9a8b63b4750c127eeb29",
"internal/api/cloud_org_admin_auth.go": "3d4361802f80d58c298b0dd57f0daba7e69f7da4e533338f4e7cee12b9f09c8e",
"internal/api/cloud_org_admin_handlers.go": "11249b2d21394e2bed4869ee39d9bade37a1363b01bc087a5235e96f656936fa",
"internal/api/collector_authority.go": "09e390d33fb952a95dd202bec57aa8a599249dbf1091b915bb7546678a68213a",
"internal/api/config_handlers_compat.go": "7fc41dc53e5301cce10986b753cf846105d0edad595cb9555dfe9a58e41be22a",
"internal/api/config_profiles.go": "f469a466b496e246ec80595daed804b55dffa72742f6972b9070119092df7e8b",
"internal/api/config_transfer_authorization.go": "525d0c0538f11a4e18f01a08bf33f1539a4ef2e26db9cada8ff6eec432ebe33e",
"internal/api/configapi/config_discovery_handlers.go": "d499ff00be90ff9a20e6a213529835c066d298484602d470843db4f925894c80",
"internal/api/configapi/config_export_import_handlers.go": "6a264cad6a31d5485813e80270bb107f28d425dded7425d7f07503b28b74f981",
"internal/api/configapi/config_handlers.go": "2a6b8819a5c6f29ae7182bb63161e25618f9ca11c2cfc53a1e41a8e1d4bc285f",
"internal/api/configapi/config_node_handlers.go": "ab955443d378cf45f884cde701a073f1bd43365e93ad207290d64b70f9429dda",
"internal/api/configapi/config_setup_handlers.go": "0e42842f29647d33c8fe74b39b83163389a2eb0969f8eb1e4b2463c337fea3b9",
"internal/api/configapi/config_system_handlers.go": "795ea62862da3f6597ec5e2a1bffb91f188f1585a18e77af50ba3075dfd027ce",
"internal/api/configapi/dependencies.go": "4f2620778bccbfe58a6010f813aaf24af0123aa79a552e3d1ce0ac7f36dab190",
"internal/api/configapi/install_command.go": "7b819a63a5a755d9affc6229092be95e88c076282632b9ea6d039b696c2427c5",
"internal/api/configapi/setup_script_artifact.go": "aca4b1151d19df5fe6da3965375373127c7a91bb6ab2a3250e24fd15ce5b41be",
"internal/api/configapi/setup_script_render.go": "32759b1860b45c781607ca6b380c3d83e8568b77ab16567cc4236ca7da4eaba0",
"internal/api/connections_aggregator.go": "9c8156d544dd2d814a6a1b25c4239372abae126ec41d382a386619b1cc84f048",
"internal/api/connections_alerts.go": "71efc73848c99d3c799639cf2f48357db2b273175a670b3168b5047de80d936b",
"internal/api/connections_grouping.go": "44f50e6bfc73c2fb844bd1dd36d7045cde3364196053a7fa8898e4d3084cb6f1",
"internal/api/connections_handlers.go": "41975dc288f66888ad84febdb5fb66fe5c6970145b15743a41f5e1de32524dec",
"internal/api/connections_probe.go": "ab7bf1e2f0482328bdee4b134519fa1d5379fc2aaf2ec9e3b390f9e6f58c1f0a",
"internal/api/connections_types.go": "af57732666b1bebabf75d3f0de5bd421b2bdbf2311ddf2b709d5ddf6d4e681fa",
"internal/api/cors_policy.go": "71001daab7062943671f8a2efec59a6dd8d20b77b6b2b8af6f7f2ce8cae20a91",
"internal/api/csrf_store.go": "5768a98f50a61ed31ea83b20e4343c1366b673221eac0d4bce601c9b0a857522",
"internal/api/demo_middleware.go": "192f58c36bc0fc2e3b18cfb914e32f7bccef85d033ee2211473564cde383cd22",
"internal/api/demo_mode_commercial.go": "88e75e594472e0149c196b81b288b5b841d8e3309be2a1664d8135a4dd12fbb3",
"internal/api/demo_mode_operations.go": "48ba980abaca84da215c6f1cb0ad7d4032a1a554c7a6f78e2af3f01ea660f359",
"internal/api/deploy_handlers.go": "af72864e89f6720eaf0f6acce2ce6d5a90c06a6dba5d14ee9f12e49ded391076",
"internal/api/deprecation_metrics.go": "f09c919e23723bc09d324f478a698cb53c56fb9da342ef25b808844a8d2b40c4",
"internal/api/diagnostics.go": "344c7f1cddd1014c35550ac8b478d77619ba9f68030e2cde695c5ae59108e3e9",
"internal/api/discovery_handlers.go": "f5c3f3f5c9a2292dcb0f708e5bde18813d3155dbcec8c3109fb6dda70452769c",
"internal/api/docker_agents.go": "5eabed7a78cd6c0bb8df0a07dc51a0cf55886919e957abfb4f1b0ce2ce44ea85",
"internal/api/docker_container_action_executor.go": "c1aef8384d2cc8ab42a0d83db81fd61411101baceefa5c2539f10dfe2ff06d2a",
"internal/api/docker_container_action_result.go": "70d6c154038416377d533cc2fd0398c3e74c22398ee38d98d35bae9df1130632",
"internal/api/docker_metadata.go": "99598ad8b05638d14fac95e91f1fa93d1e301cba5e486a559c2a0d53c9198df6",
"internal/api/docs_links.go": "467eb1dede5e6d10336683141fa12230e6106f56d4279d7b7120a7416675a4fa",
"internal/api/enterprise_extension_ai_alert_analysis.go": "a00046c2898718359dae5bb178fbc33fdedb5a39871b4769351f251fe4d2caa0",
"internal/api/enterprise_extension_ai_autofix.go": "b632ba3becebbb4f66a05b656982e00c9aa86af90b0d88bb23fe45fcd168d4fe",
"internal/api/enterprise_extension_ai_investigation.go": "109f6cc1b0fe9aa7c1ffec4e6ae3e2ff9a795dbfae9bb23fc1e77f03273ca672",
"internal/api/enterprise_extension_audit_admin.go": "46cb98ef8eb5a80a0ac2c23a7558bedff6cddc6e220885ccf0a3ef863cc2bf12",
"internal/api/enterprise_extension_rbac_admin.go": "c15b58d124246a96104801178b2f621c48822f949b022d1958e07181be1b7be0",
"internal/api/enterprise_extension_reporting_admin.go": "5175036492611300eec523f84d8f33d61133d2ef2b5b17754fbf563d2950885c",
"internal/api/enterprise_extension_sso_admin.go": "9e70e1420e9da8aea788713f9545a9284fd92d6d7d044e91c1774e2d5e4f7a09",
"internal/api/flapping_postmortem.go": "fc6b6f14833000e53f94c61bb3a8749dbe1c2ff74e1cae827cd9c36dc2ed99b4",
"internal/api/frontend_embed.go": "abb2b942f5d59347ab7c6c9d2d3a35f4c094a42704ea3686cd4810c7282a068e",
"internal/api/guest_metadata.go": "d400c8e71cae811869b2abca65be2fba8e3e4cc3a4032ce5dea7be2fad84f0b9",
"internal/api/host_apt_action_result.go": "2c46e66942ccb3cebf4204fc695e297d59c32392afbe42049664fef12adf9ba3",
"internal/api/host_metadata.go": "68d61e98bb7acaf7d148b37e2eb416247c50a317560f9b5421f8f4f42f23b8ac",
"internal/api/host_storage_cleanup_action_executor.go": "4c5a0f21c07bb26b1c8206254e680c5880062f87b9e1eb8c5d3b41745eaa4723",
"internal/api/host_update_action_executor.go": "1b667b667c94a670a5685e4d204fd716ff40e6a5029bae0addf0202104f292cc",
"internal/api/hosted_entitlement_refresh.go": "bb4c8a49f97aedcb7c0b00628f390dc81072184df6f5335c160a04c34cfcc9cb",
"internal/api/http_metrics.go": "81fc091698cf7c1b011af70776dad53db3aa735367e51f4cda8a9bbf4b2b8527",
"internal/api/identity_sso_handlers.go": "fe125dd1e6e39c3dc674fa18ce57497791b93eb1951e3346765557595545717f",
"internal/api/kubernetes_agents.go": "7091a55df3fa214c08998d5528daf2792652bd32b02a51e3e4eed626f605601f",
"internal/api/licensing_bridge.go": "6afb5aefc414af81c44f6eb29e3464e1390972c50d52b9fcb84485bc658175a6",
"internal/api/licensing_handlers.go": "5f04e6a4543cd2bb2c4d782c782b9ab2b7486bda9ba7caa3f4b3b55b36d7a760",
"internal/api/licensing_legacy_retry.go": "23774844f2d42c94e15d9b3fe94aaa4fee00550e862d20a221590cff07d7e32e",
"internal/api/log_handlers.go": "c26cca429175d265f8003da91e57bc4b401d5ce236ed4e10e05023b69aea703e",
"internal/api/log_redact.go": "c02efc8b4d808aeee5c2181f29e6071b15488ec98df18439953f0427080e294c",
"internal/api/magic_link.go": "e89d72b4971d7526b66f67767b49b92c92a312e2cba81e1d6a7aaee12223def7",
"internal/api/magic_link_handlers.go": "ef9290751de30913b80085551893844a81e4e9bc79b6b5e053714e7509fc7dcf",
"internal/api/magic_link_store_sqlite.go": "41a4b043528888c019e06b65ea2bcb03461165dc9ad22bb69801f5b59b492061",
"internal/api/maintenance_verification.go": "6e4c78b090e442ff061e61e89e54271fa630d92a79d6ed34739fd6f1f46fa5e9",
"internal/api/maintenance_verification_wiring.go": "7dcc5bf18b98b9bfbc8303cf5a671629bfbdf76e220e6db4caebabf2c7ae74a5",
"internal/api/metadata_handlers_shared.go": "08407104bcd03fe18ef75f14a5cad82914a342bacd6eb066f61f93cb6f48f5c8",
"internal/api/metadata_helpers.go": "2ae9b6dae0e33bbadc84c9ab6f3241247f7e747111a0eb7d794eab61cae0dbce",
"internal/api/metadata_provider.go": "af146dc07fe00ee30ce49e897919736fdaa3f940cdd7d565e5dbaaf408fdd0ec",
"internal/api/metrics_reporting_handlers.go": "f6ee4261576045add6478798cd12d5eb3da8a91d9940f08e2deef7041b23d008",
"internal/api/middleware.go": "ed09180803ac654ac5e416b0e5b29042632c6a32f95accea591b17b35b3222b1",
"internal/api/middleware_license.go": "4dee04c182e7d2f6a75a32f03543a387068f172dbbd622fbdf5f16085027fb46",
"internal/api/middleware_tenant.go": "53a6304b105f1175962d7a7f621176d4c4e7ff8019cdafc630f6dd096d798d13",
"internal/api/monitored_system_ledger.go": "fd1647aba616bf9e426264dbb803284580ddf7dc8598d90c513774a834532450",
"internal/api/monitored_system_usage.go": "392a08e14642fa7f71d70663b3d4b3edacfc92bc13fc71410759952d9ed3509b",
"internal/api/oidc_handlers.go": "1f3982f69f2b4c8edb72e6e95440efad26c6a21377a566991b80671cdd57b605",
"internal/api/oidc_service.go": "82f21af7da5f05a86bf76561684bd8f356f473e6ed18429f960a81b261581546",
"internal/api/onboarding_handlers.go": "4a47265c65d46a6770c7caf94ccb55602f62e579bf0ed791af26c25602f33ee5",
"internal/api/org_handlers.go": "bb47a7b69ff24f05f8cab7e304fc281837970c1cb75a405a35e54c6d2d8e96ac",
"internal/api/org_lifecycle_handlers.go": "980b4c6e7e3010fdc22e52c5d2ee7a12b6a2b0ff63331feca7398841cecec4fe",
"internal/api/patrol_action_broker.go": "bbc5ebd742c5dc4c3b5cc5b79eab746b074af847ebccc190115605e3cd258f28",
"internal/api/patrol_action_reconciliation.go": "52e339d14ee9715b85d19a93fee21b656a55d8793e9a192fa71b86726c0d48e6",
"internal/api/patrol_finding_notifications.go": "c19e09c9118a67dd64be2e22f1d8f2efa46694a161f3011e2d513d9e66e44997",
"internal/api/patrol_objectives.go": "fc47707db8f337e692b0392fe46f33ade34ffe56ea99300defd246c0c4afdbcc",
"internal/api/payments_webhook_handlers.go": "ec1e1cf664520a9c15b3a8a947dce9186cf5c6bd76cb0b9ef3d1ab3ea598535b",
"internal/api/pbs_backups.go": "788600ff602866f7d5d70408fb7c612036cc6f9d7adde51d4a8ff84635597cc2",
"internal/api/platform_connection_shared.go": "d41aed940a10758167f68752c591225fc9c4a6034e49a0741cd673d417cfd4b8",
"internal/api/platform_mock_connections.go": "34a4a8176a9abedb42aba31b771252387b73ddb9d4c880d1a7d7328e5afa8136",
"internal/api/pmg.go": "efb9ad0037c196cbcf084dab03d3c31c6ade1ca4fa1904d0dd72a5f0493ef5af",
"internal/api/profile_suggestions.go": "b1fcf4548fc28303e9266faa3eecf2e632d1510d3b5cdbf3cddc66836f1ad8e3",
"internal/api/proxmox_guest_action_executor.go": "ddb70d949e8841202618d3ac3fd3dc350b03271701c93ac3a83c139c130e587a",
"internal/api/proxmox_guest_action_observer.go": "11b0146be21c9303315864d4ac0fe7ccf46ed3b1b380ea96e8933586a6e1db8a",
"internal/api/proxmox_guest_action_result.go": "b28f45e197f55dbb7072d229dc24ce70d73ed67dd3f511407f26fd7b091e9e93",
"internal/api/public_signup_handlers.go": "0e180ee90cbc7b65df2eb7075d76fb51c3f308331d2420c8e5a9cb3cce1393d3",
"internal/api/purchase_return_redemptions.go": "e1a0a573773ebb308f6406ad6bdb932f43d48519c1ec6dfccdf0c7cbbd899ca5",
"internal/api/pve_backups.go": "3117c78dbf940bb350aabc10ea999c05942749ed82c549969aacf829536fd012",
"internal/api/rate_limit_config.go": "503bdd861cdb50c917e3d613b56298ca7b83d6b3e14da7a5c774dcf2ab4b0e95",
"internal/api/ratelimit.go": "122c8ac5378e6affdf7b75e609489688bfbee6b019c1592c61a46c68baf9f6a8",
"internal/api/ratelimit_tenant.go": "2a8bd7b5ddbc757c5ac5606c220647b2447e56efd61b1f9f378b576f251c77de",
"internal/api/recovery_handlers.go": "553698c6c21e057adcb888a2fa15c7f488c3db217f3e9136b6bed2e61142b6ef",
"internal/api/recovery_tokens.go": "c05626028329fa15024190782af89eab37592ad080d37b9ddaf630504972e6b9",
"internal/api/relay_hosted_runtime.go": "f4ed4fcf2b2d152c8cbf76e90248ad2d1bd3767761f0f92b18c345307d3a5f53",
"internal/api/relay_mobile_capability.go": "04c7566f9beb22b39e47c5d2591079573ee8244ea554c680576017eb130883d9",
"internal/api/relay_mobile_capability_generated.go": "b62a514754ceb0b6e03251d4873f7755a44bb5dc81787d4f7c8eca4fcfd6dd26",
"internal/api/release_demo_fixtures_dev.go": "f4502a13aa453a50ea967a92959cc6c9013259bdfe596e9e0b9c50da544442d5",
"internal/api/release_demo_fixtures_release.go": "a3d98bfc68d10981676406d1916c13996636c5d5996cf360db26c5d1c14f9026",
"internal/api/replication.go": "9faf8ea8879dd79b33e516acd68f567559c50f7ad5c88e7c34317af9d8b01775",
"internal/api/report_schedules.go": "bc48321b39c6c529b0fc5fa8b0add899831c8574ea0f9ff8eb24c6c7c9fcd834",
"internal/api/reporting_availability.go": "1fb0c3161a742060848da9367f90d68d8c1192ad95111c0caa5c4bd1b40afde1",
"internal/api/reporting_catalog_handlers.go": "6f4bdc73f653c47e397cb6dd9b459523c094a3bbbcf2e9c5950f7fd4a1c1d05f",
"internal/api/reporting_inventory_handlers.go": "8651612acd744975b5b1f4b469a9949ec6017266ead3a29b5b1f6578189eeb85",
"internal/api/reporting_runtime_snapshot.go": "9398bd23e031941c9a6b8ef5cf7debd6a4d8c8e1030bb00ff4e9c3d9650aceb7",
"internal/api/resourceapi/k8s_namespaces.go": "78dda0edba00d8f4d951c0b45e2e7b438c408391dd42143d43bdab3eb107ea0e",
"internal/api/resourceapi/resources.go": "58664371f69e1728963fedab9681521beef12bfbb7d6f994ea0541004346d5b1",
"internal/api/resources_compat.go": "ff90db21381ea3b27ba2199d58f963efae7885e88416b2d6f540d86c2d57fecc",
"internal/api/resources_operator_state.go": "949e74e2698fd90dd8c0f47cd5809b37e95db40b48d3d37e4d4b53489dec0c1e",
"internal/api/router.go": "f1483edbff4d267088af6b6646e58106ca0dae3c6f750727e3c74a4b14fafcd6",
"internal/api/router_helpers.go": "a61f76b9dd9e7883778253bc908d6b6dff55bdb07ca335716a952da57ae89b94",
"internal/api/router_logging.go": "80251a5c997d1a46b21ad6b4291a2aea099ab29553d69553df95efa08a7852d7",
"internal/api/router_routes_ai_relay.go": "5dc12639ef3ff8a6ce2d8b1c0be3d9e83007929c413463d0bea14f141aaa0d94",
"internal/api/router_routes_auth_security.go": "24b6371975952cf6bcc83b2fbb16994104ccee1009bc3693a71c1d9ff9e137c5",
"internal/api/router_routes_cloud.go": "7a47facf452e9f08958036cae38664e116003f2df46e0614b7e84b1cc175db91",
"internal/api/router_routes_debug.go": "92b6bd7d50b829f99f3a1613b87f83727dc099cfe9d75ed2d3d80c82984f9821",
"internal/api/router_routes_licensing.go": "ab6853ef7ad69f1c80fd57022bc8db50964c4854131d9876f25d4da0b1bb8821",
"internal/api/router_routes_monitoring.go": "ed5d592961030cebc1e3851c3ceb94d0760d8ad3c427735132d8551724352f03",
"internal/api/router_routes_registration.go": "5dd74018d9f27552a8e619816825e66cfd66d5848618efd283b4cc15f3055ae7",
"internal/api/runtime_branding.go": "c7fd8070b0fc5e679aad88955c041f423a22127ea971522eb2e2655d245c505d",
"internal/api/runtime_display.go": "974c2c0ad1b4e2d07eec99fcd850de8e0edb29eb5c1e25afb29f487d4a8e57ad",
"internal/api/runtime_inventory_sources.go": "10140e2fc660c4631641152a48fbcb1ca3da68a97a5c205051647342b07ff12a",
"internal/api/saml_handlers.go": "a7f0f4a2822f04ba467597c8c6be71bae52e1727953aa45e96c2c037966f6b0a",
"internal/api/saml_service.go": "598d2e31c2280983984eceffa587feaf1dd54c10477c5205587a1fd0e5182592",
"internal/api/security.go": "4c1e22e52749ad6fac5173f11b51644c500d9195c2b0e2ae0ede7260022b006a",
"internal/api/security_first_run_reset.go": "6b3e04f3e6094a7b0a8a19e0e21a7adba16146cbaf5c266a9997d86f84bf126c",
"internal/api/security_setup_fix.go": "26a9bb880f47caedf850f93a8660f489658b4cf5ddf54202b8f3cd06c153116c",
"internal/api/security_status_capabilities.go": "a384aca3ea0ba7809b94abf7eb5dc6448e5c1f253341b1936d0d12ec5be818eb",
"internal/api/security_tokens.go": "6448fcd31ebd447ca2e01e79dffe614adcfa313a256db8710529cba5c2eb84fb",
"internal/api/session_store.go": "fd56ebc4131d60d7de022ad16ea6240016e35796aa7386b5b4e9a89798e2312c",
"internal/api/slo.go": "c9306f43058eaa2e29768a9e8cdcac06f7bbd6f10e1f9b76dadf4bec48f6ff09",
"internal/api/sso_outbound.go": "9920a49fed5a9415e099f6e5aa01dfdc5bff97212004fa269a71f35b549e724f",
"internal/api/state_provider.go": "56ad65a422d4229079ecc1701c3170bce90e9893f2bdffcd69045967c3c4256b",
"internal/api/state_summary.go": "0da03832e2844b2b4b3d4e659a48aa540664f7ad7671251a617e46fe28ca1a77",
"internal/api/subscription_entitlements.go": "0314f3b64ea57ad3315317cedef28518f10fa54e0c7621097ef8bd5f8cb5bdf8",
"internal/api/subscription_state_handlers.go": "c7b8f94368d62a582e9e2a506c1bfbee2b220cba4a54c129b5056955949cc498",
"internal/api/subscription_state_reconciler.go": "0b66098ee91e87681273f2a9ad6d4ea027a20a99e09e42baf89df0099f94b3ff",
"internal/api/system_settings.go": "c71814a15c49c5da3af9d541d1fea492cfac9131d1a082023cb5eb9e4e0f22f4",
"internal/api/telemetry_audit_reads.go": "7cc72c7428e5bd4fed58c6c0a07a0033d07b324741e9e626fb8a7b2565c6fe98",
"internal/api/telemetry_licensed_features.go": "b11e211705a305d70aaa6977c603fe91aefa9628bd7828c05c2052ffd5f37f2e",
"internal/api/telemetry_pulse_intelligence.go": "0d2dff2276a1d8cbcb07cac9b064343b4896cbb01bc4a53f6eaf5c31e094e3ce",
"internal/api/telemetry_workload_history.go": "62ced9db02d0e04e6723df6142cd6decec9e43c991f5b44a61579e0e73987dd5",
"internal/api/truenas_app_action_provider.go": "ff6b2709ced8ea51887edfa2b1fc4770dfc76b8a5b45b7479e012945fdc5cfd3",
"internal/api/truenas_app_config_provider.go": "b34c12a919c3b9d4ddc8f660ddfa99a06450c8a6ee6269fd93db71ba03b9c3f3",
"internal/api/truenas_app_read_provider.go": "cfb4875315002fd3133b463e27ea09fca5d6dd608ef7954aa8a65ae28aad25bd",
"internal/api/truenas_handlers.go": "bf58c69707ada9d6692861f34d71c1eb2ff32cec0a150d1f331daf2edda3edd2",
"internal/api/types.go": "a5dcb11c6618bd8eaad2eec59cb46d754ddd160e5463987e7cbfa88846cc2ac0",
"internal/api/unified_agent.go": "3ee6bce5cf07652ce1072958d7f4e26183cb62bd8c2cafed3b1903181894bb00",
"internal/api/update_detection.go": "cf8567ff9f6cf3e1902d4a594c48b3fb58bdf6a53c1273e4fc6b386ba615a88f",
"internal/api/update_readiness.go": "f308b143c5c4ffe9344c9c4bbac7a84eb080a33d7a3b55229843e945f3b0c756",
"internal/api/updates.go": "a933c93ed496a401e7fcda3f527443a39e9628dbf64dcc36decfeb8b8d0d25be",
"internal/api/user_limit_enforcement.go": "a4065221e976cfae80182d88346bb9a369777fa5e9fe89d76fb3f310b04cb3a6",
"internal/api/vmware_handlers.go": "a0606e09b10bab5fc899bb42cb57a1089b5a6b1248a52bf46c2c50ce9b613751",
"internal/config/ai.go": "e773d1d1b4bede3aae9a5e1ec640f82c0992826b2bea964724f5de61c01e9ed7",
"internal/config/ai_providers.go": "994c8430b6084616b69fe702bfa4a1602d83e5c37dc60039ac1879e076714eef",
"internal/config/api_tokens.go": "f333752b6da24a85c4342332a8c656cf86d83c8cab45d49d36af9f182fb8af0b",
"internal/config/audit_read_activity.go": "b8fc44fa443112fa94e92c2a2516bd149b9aec12ac7f4b48f87752f9b4f4817a",
"internal/config/availability.go": "72cd69d132a39810940f19c6df10712a0754e6187e2c0bf6b247eb2777217900",
"internal/config/billing_state.go": "b244ad2167d87a20b63189665288008cdbdba3dc97d783add0b9e390ee690a63",
"internal/config/client_helpers.go": "8dd2444ad85af9347f5481bc9c80aa4d91e8eef64f6c966e01a53d3676834757",
"internal/config/config.go": "038725360ef71c31a22d1d79f6b370af07bd25112432b5d8b389ef57a6715818",
"internal/config/detect_root.go": "b1e09c43ae7a8b23edf0639b7c178bbfe8d6db307ce1a0d6864314673c9e4371",
"internal/config/docker_metadata.go": "f6a45c123ffeadbe3481ce5fb744c96afe6a2b2cf2f8f6f400b3913aec78c98e",
"internal/config/entitlement_billing_state.go": "aeb581849ec36021de82d3f3a74eb34bc8051464c5002cc978813a212f465034",
"internal/config/export.go": "8bd4cddcb24ff552185c1e8c7fcfd8ef445e048cb794ad45295f5616945782b7",
"internal/config/file_read_limits.go": "74b877ff7dbd5a7df01edf79fa4033e316facd6acdaf2af01116d4367d48478c",
"internal/config/guest_metadata.go": "63b71837469c85b90e8c7f1f797323b53981dc5e2c6bf414030b960d8910cd09",
"internal/config/host_continuity.go": "cb8408fa70784883a4a62ffd3d7818e16281795d580ce6b9830826a440a14921",
"internal/config/host_metadata.go": "2b3a6f22f9ebec79b69d1327f7b64468e923a1a7fe41e04e88272cd92d7548fa",
"internal/config/import_transaction.go": "c1d8b15b66bd8ec3ca44972d2ebfc45055060ddb37ca9de01f8ee0c0b517740d",
"internal/config/metadata_helpers.go": "73849782962c0d2dec8b8750b4a8ab8c094371536069758eca641a450961743f",
"internal/config/migration.go": "0d48bed7a34c505e413881ebf5cc731aae2ed8d580d0d4ac4bd39422b8817138",
"internal/config/multi_tenant.go": "1873996b514af326a15fc9205f9dee714e3d556ee66db2c8dcb028100c546b6d",
"internal/config/node_test_tally.go": "67ff9908c0c9c5689c23d872d7ed07753f3a117e54aa69de06834346316cb75f",
"internal/config/oidc.go": "11bf532dea4a9ea0f65bef5397dad28629cf79d7b2976d156e2b06589b84e49f",
"internal/config/patrol_autopilot_persistence.go": "31a02f3070cbb4730380efe8e3a4193bcc637c06409c58fc2c09e0f2128ebbb8",
"internal/config/persistence.go": "7271dab3607bfa15312c08e15d8088cfd9278297af10499be4790c56abf55e14",
"internal/config/persistence_alert_intent.go": "187f0e264add73555bfb5c42593b7dcfd841eccdf35c9ecf6eada1f6bac98b43",
"internal/config/persistence_installation_scope.go": "a146e20278fe009166015bc608d34ad411ccfa3ac2884bdc610e96c13807a75c",
"internal/config/persistence_metadata_accessors.go": "51822e30287c314cac91bf822246a3a82d978335697459938b481f7516216b98",
"internal/config/persistence_relay.go": "5874a46e7900b27934fd402533e1a6d7a7b54a45cff25b50f067926579d95c21",
"internal/config/pve_instances.go": "b740964482aaca40d2de5f7f772b79ae093f3e90e4d5fc4aed50c05cf7df20a3",
"internal/config/pve_node_identity.go": "8971e149c1e0c668c2fc8c25abc9b7e86eaf62f0fc19ec0642f4336c9ae8f1d4",
"internal/config/report_branding.go": "bf774484179ab2eadb833013d4b467c10e0af4363a1f220af0e0b2a606d9984c",
"internal/config/report_schedules.go": "1be7c9b681d21a68227d712eaee590d546c5a16bec09dbe68cab3755bb114a8b",
"internal/config/sso.go": "281fa3c5b27aa9dc2ca54c575c800f4fac7397213621540dfa394e4c825e7d30",
"internal/config/truenas.go": "5ab9f0203f8910ffc495ca4249fb36a758dfb3147ce934c514ef3dd01b41d498",
"internal/config/vmware.go": "a29600f8e229ef83577224ba943da9630db0e88203c8e1569385c33e5d485744",
"internal/config/watcher.go": "8efbdc2dcbf9fba9a04ee298bc2118a6ec20c1c4bcf07c5b8a9d2158a2a03467",
"internal/config/workload_history_activity_tally.go": "a2b246c6c1218d6b754cd1bc62ac820ccd6eddb072f14ffed8c5ed1cf9c194e0",
"internal/hostagent/action_runner_client.go": "1a6231c7fdef1c4595b2f0e6660d077374769fa45c0d429d0ea84440a9de3d57",
"internal/hostagent/action_runner_health_persistence_unix.go": "dbc8eb02bcf7129d36a7a6ca91f7abfb102cb6dfbe3ac66b52b74303a06b6887",
"internal/hostagent/action_runner_health_persistence_windows.go": "f16fa2e9f9a2f8aa675777f36582087ead3051e04cdc805ffe7e9200191e9184",
"internal/hostagent/agent.go": "500b7bdd10a2a93b598201e1716e5ad84f98a5a344c9247a5ecab71ef67323d2",
"internal/hostagent/availability.go": "eea45d12922b6859492f562dcfab4dbe248b32a92bc5abd002b5ac51422fdccf",
"internal/hostagent/ceph.go": "fee9561bc972b7bff11a9e87ad879efeac0914fb24b63eae0319f495aceb68f6",
"internal/hostagent/cluster_sensors.go": "6d6104dd2046dc6f9626d2f08f6990923bfad9b37f8028e555b590e368316e26",
"internal/hostagent/command_authority.go": "212ba17cef8beda1cd6250067513ac4ab68faa808844aacd7e5a03691f2dc9a3",
"internal/hostagent/commands.go": "03e1da3a0874645cc8dda0fd03ca307ba754ce61ecbab731e74513822b11b4f0",
"internal/hostagent/commands_deploy.go": "73ac6378c23ba4665dd98459fb941691b114be9ffd2307dbeb8c7ffb1bfd9571",
"internal/hostagent/commands_procgroup_unix.go": "1303d4227ded53ac3668b7a15092d50ff92cb3ffc581d594f9de2ee633fcd884",
"internal/hostagent/commands_procgroup_windows.go": "a2137b47610613beb3748b19eec798091081a800cf162b6f6bf1de9ebf6f40c4",
"internal/hostagent/custom_sensor_security_unix.go": "fa4175df3610c35432a60fdb5c0935800b995b6f89556b3ff00a480999eaf896",
"internal/hostagent/custom_sensor_security_windows.go": "e8ce8bec788b28c75d1734ec7746ec0f467919e05da10d5c382d31fca71877ba",
"internal/hostagent/custom_sensors.go": "301f134d27f8766bb671e4a6576d09f4894916547880585c312c227d3cc68166",
"internal/hostagent/docker_lifecycle.go": "3c6f4ebbbd3ebbe48b29deae6fdec4648e7c9617e5cde0aca432a210997df6c4",
"internal/hostagent/docker_update.go": "03324b0ca29b63609d6078bb5900cc501ab40bed9ff1c46c50992b1d07e0f539",
"internal/hostagent/enroll.go": "5d72a553cdaad74aa77942404c7f1da7537dde0920dcabba0bccc927bd8d36b9",
"internal/hostagent/libvirt.go": "0c4ee6346169e06bc26d2e006ff85cc7749da435c2f59db17adb8c4ad334d7e5",
"internal/hostagent/mdadm.go": "f2714ec89953361aec92cb09dfaaf89b25af97eb24360c5b464ba723f3261cf4",
"internal/hostagent/nvidia_smi.go": "9a4c4657604f1cf0d365b64a6ac4b289b21fc7cb7b7ef1b85888bb4381473beb",
"internal/hostagent/os_identity.go": "0ab3306f5219ec8534cd4862962297169df055e1d62012ac999c01137b374bdf",
"internal/hostagent/package_manager_lease.go": "e8879c39780a1712596cc8dd4ce25d45f28eef6c698878bb20a9cd1fd4aecbe2",
"internal/hostagent/package_updates.go": "64e0f3042ad176a874c724c91e05d7012b4c5f3b08d4df15d00ae29ea327423a",
"internal/hostagent/privilege.go": "9973b39fce82be4989ae64515d43bbfd4e3195330d64a388573bf7ebe69454dd",
"internal/hostagent/privilege_helper_client.go": "90313c33de1006895fbe1cfa001943b5ed79a02f5a7f296d529d9862de2b6cf1",
"internal/hostagent/proxmox_guest_lifecycle.go": "14d0a882859a44b3f3ff300c6f547db77e966881b742003fcb3e52db04431a89",
"internal/hostagent/proxmox_lxc_filesystems.go": "101007cd8ff35cb2f7d80140aaab0df162092ddd27d7c30bcb9972f28763d0ad",
"internal/hostagent/proxmox_lxc_filesystems_linux.go": "05424af10374cff45163a25eb8149e1bc2d3604b336b5f699a3fbaa480a2615d",
"internal/hostagent/proxmox_setup.go": "6101db7876fa63f305d27276ea8193e35435cf485f628a196048b5a9b9636391",
"internal/hostagent/smartctl.go": "83d75343e1a7496d987f128f4084f290de81db2a6cc63b463528207696dfb1d0",
"internal/hostagent/storage_cleanup.go": "6bf8a9457ae63fb4cdf375660cb85a15302aa29fdc303e1ed9a2cfc71abf3c0f",
"internal/hostagent/sysinfo.go": "768558142a26526f99edc0e55e8408e165e6f272b8bdb63d871d1659a3f08b44",
"internal/hostagent/unraid.go": "e317ae5ba0432e1cfedf853ee69288473631e5cd0300910a9c0f54f54ce32e6f",
"internal/hostagent/version.go": "fd06f8a2f9360b1e82a0687f76fe13f6b16786a2e2dca3fbc5d668717ec6b04b",
"internal/hostagent/windows_librehardwaremonitor.go": "aa9f67de011c2f23ba7ac1ffd66d566c12bfc920446b1151b8d08abe02349c9c",
"internal/hostagent/windows_storage_sensors.go": "c0b43fd797a79887c7b24f18f36185b35885d1328b207549ab7f3eae05a00789",
"internal/hostagent/xcpng.go": "24334380d87e6e0ea0559e03ffdcb5ce754f1f23340038ecf482758d6e51d28c",
"internal/hostagent/zfs.go": "75fe80d6fb8c2ecd7495589bf006800065f0c51caa3c454c3ccf828e2d905437",
"internal/operationreceipt/store.go": "6f40b4422fde09e81fc989b9b5f35066ebb3276e20bb0903a554414b69e6f6fe",
"internal/operationreceipt/types.go": "08b86678dfe55b5ec29c94ef96de15e9e3f416a9db656481f8ae833b38538dfa",
"scripts/install.sh": "63d1609fd1a3c02d07ee9034b7f177b4f00e523c97ea91b74bce2946407c5c9a",
"scripts/installtests/secure_runtime_systemd_lab_test.go": "5f6929162d8067c454b6c676481c6fd739053565c910419da65ee85e263c454a",
"scripts/release_control/secure_runtime_attestation.py": "f83c545a95dd6f9c46b4c676e1c28a2ae9b7a8a42ebef11b0af914d580ccecf1",
"scripts/release_control/secure_runtime_source_manifest_v4.json": "243e6c85640dec80082e3f1bdc5983912c613ad97ff9e9292b110a9f1411bb45"
},
"artifact_hashes": {
"collector_v1": "6ebdbc3b54c9cfdfa69419024d676d239309c8b100e614bbb1c5d7d58ff244a4",
"collector_v2": "d11bc3387cfe4cd775df00ab4ec869aa53c2b9a41ff82186d67347b7a1d24b7c",
"helper": "717faf13d6931b048ecc545f2064919bde61ca891c7e53fe36989a91085d88d9",
"runner": "baf14412a7c8b74ad5ab70c3eab15a106d46ec6e6e742df38a11fc2671156a46"
},
"artifact_versions": {
"collector_v1": "v6.4.1-secure-v4.1",
"collector_v2": "v6.4.1-secure-v4.2"
},
"disposable_vm_guard_sha256": "8e5627d75bbd86ab54f63cf4af8a63bdb5c134450e1cf75b0bf13095349fa68d",
"os_release": "PRETTY_NAME=\"Ubuntu 24.04.4 LTS\"\nNAME=\"Ubuntu\"\nVERSION_ID=\"24.04\"\nVERSION=\"24.04.4 LTS (Noble Numbat)\"\nVERSION_CODENAME=noble\nID=ubuntu\nID_LIKE=debian\nHOME_URL=\"https://www.ubuntu.com/\"\nSUPPORT_URL=\"https://help.ubuntu.com/\"\nBUG_REPORT_URL=\"https://bugs.launchpad.net/ubuntu/\"\nPRIVACY_POLICY_URL=\"https://www.ubuntu.com/legal/terms-and-policies/privacy-policy\"\nUBUNTU_CODENAME=noble\nLOGO=ubuntu-logo",
"kernel": "Linux 6.8.0-117-generic #117-Ubuntu SMP PREEMPT_DYNAMIC Thu May 7 17:26:37 UTC 2026 aarch64 GNU/Linux",
"systemd_version": "systemd 255 (255.4-1ubuntu8.15)",
"architecture": "arm64",
"collector_service_user": "pulse-agent",
"collector_process_uid": 996,
"collector_authority": "monitoring-only",
"ambient_capabilities_none": true,
"helper_protocol_healthy": true,
"state_identity_preserved": true,
"docker_degraded": true,
"action_runner_qualified": true,
"action_mutation_verified": true,
"collector_authority_reduction_request_observed": true,
"action_receipt_kind": "pulse.host_storage_cleanup_result",
"credential_rotated": true,
"self_revoke_observed": true,
"collector_continuity": true,
"report_count": 47,
"first_report_at": "2026-08-30T18:10:19.845040724Z",
"last_report_at": "2026-08-30T18:12:04.284245654Z",
"transcript": {
"format": "jsonl-v1",
"record_path": "docs/release-control/v6/internal/records/secure-agent-runtime-systemd-transcript-v4-2026-08-30.jsonl",
"sha256": "616681aee38202ed922880288b730cd85f746e081f8f9d45bb2d570e48b49f8c",
"event_count": 81
},
"scenarios": [
{
"sequence": 1,
"name": "legacy_root_command_capable_install",
"passed": true,
"started_at": "2026-08-30T18:10:18.105761661Z",
"completed_at": "2026-08-30T18:10:20.7594628Z",
"evidence": {
"kind": "runtime-observation-v1",
"summary": "root collector installed; docker_enabled=true",
"claims": [
"legacy_root_command_authority_observed"
],
"observations": {
"collector_process_uid": 0,
"commands_enabled": true
},
"transcript_event_ids": [
"event-0007"
]
}
},
{
"sequence": 2,
"name": "read_only_inspect",
"passed": true,
"started_at": "2026-08-30T18:10:20.7594628Z",
"completed_at": "2026-08-30T18:10:20.852343562Z",
"evidence": {
"kind": "runtime-observation-v1",
"summary": "stable installer-owned files unchanged",
"claims": [
"inspection_left_stable_files_unchanged"
],
"observations": {
"stable_files_unchanged": true
},
"transcript_event_ids": [
"event-0009"
]
}
},
{
"sequence": 3,
"name": "drop_in_fail_closed_rehearsal",
"passed": true,
"started_at": "2026-08-30T18:10:20.852343562Z",
"completed_at": "2026-08-30T18:10:21.145118405Z",
"evidence": {
"kind": "runtime-observation-v1",
"summary": "migration rejected before stable installer-owned files changed",
"claims": [
"drop_in_rejected_before_mutation"
],
"observations": {
"rejected_before_mutation": true
},
"transcript_event_ids": [
"event-0013"
]
}
},
{
"sequence": 4,
"name": "safe_profile_apply",
"passed": true,
"started_at": "2026-08-30T18:10:21.145118405Z",
"completed_at": "2026-08-30T18:10:28.52640484Z",
"evidence": {
"kind": "runtime-observation-v1",
"summary": "fresh server lastSeen, least-privilege identity, typed helper health",
"claims": [
"collector_non_root",
"collector_monitoring_only",
"helper_protocol_healthy",
"collector_authority_reduction_observed"
],
"observations": {
"collector_authority": "monitoring-only",
"collector_service_user": "pulse-agent",
"helper_status": "ok"
},
"transcript_event_ids": [
"event-0024"
]
}
},
{
"sequence": 5,
"name": "explicit_safe_profile_rollback",
"passed": true,
"started_at": "2026-08-30T18:10:28.52640484Z",
"completed_at": "2026-08-30T18:10:30.084995619Z",
"evidence": {
"kind": "runtime-observation-v1",
"summary": "legacy binary and service identity restored without resurrecting collector command authority",
"claims": [
"explicit_rollback_preserved_reduced_authority"
],
"observations": {
"commands_enabled": false,
"restored_profile": "root-monitoring"
},
"transcript_event_ids": [
"event-0029"
]
}
},
{
"sequence": 6,
"name": "automatic_failure_rollback",
"passed": true,
"started_at": "2026-08-30T18:10:30.084995619Z",
"completed_at": "2026-08-30T18:11:03.696237146Z",
"evidence": {
"kind": "runtime-observation-v1",
"summary": "frozen lastSeen prevented commit and restored binary/state identity without command authority",
"claims": [
"failed_activation_restored_prior_runtime"
],
"observations": {
"activation_committed": false,
"restored_profile": "root-monitoring"
},
"transcript_event_ids": [
"event-0034"
]
}
},
{
"sequence": 7,
"name": "ordinary_update_non_migration",
"passed": true,
"started_at": "2026-08-30T18:11:03.696237146Z",
"completed_at": "2026-08-30T18:11:09.208098298Z",
"evidence": {
"kind": "runtime-observation-v1",
"summary": "binary updated while the downgraded root monitoring profile remained unchanged",
"claims": [
"ordinary_update_preserved_selected_profile"
],
"observations": {
"collector_v2_installed": true,
"selected_profile": "root-monitoring"
},
"transcript_event_ids": [
"event-0039"
]
}
},
{
"sequence": 8,
"name": "final_safe_profile_apply",
"passed": true,
"started_at": "2026-08-30T18:11:09.208098298Z",
"completed_at": "2026-08-30T18:11:17.15862403Z",
"evidence": {
"kind": "runtime-observation-v1",
"summary": "collector continued reporting after committed migration",
"claims": [
"collector_reporting_continued_after_migration"
],
"observations": {
"collector_service_user": "pulse-agent",
"continuity_report_observed": true
},
"transcript_event_ids": [
"event-0050"
]
}
},
{
"sequence": 9,
"name": "separate_action_runner_install",
"passed": true,
"started_at": "2026-08-30T18:11:17.15862403Z",
"completed_at": "2026-08-30T18:11:40.279395293Z",
"evidence": {
"kind": "runtime-observation-v1",
"summary": "root action runner registered and activated independently while the collector remained non-root and reporting",
"claims": [
"action_runner_registered_separately"
],
"observations": {
"collector_service_user": "pulse-agent",
"fixture_activation_requests": 1,
"runner_service_user": "root"
},
"transcript_event_ids": [
"event-0063"
]
}
},
{
"sequence": 10,
"name": "typed_action_receipt",
"passed": true,
"started_at": "2026-08-30T18:11:40.279395293Z",
"completed_at": "2026-08-30T18:11:40.533544715Z",
"evidence": {
"kind": "runtime-observation-v1",
"summary": "verified apt cache mutation and durable terminal receipt; stale fingerprint refused before mutation; generic command dispatch denied",
"claims": [
"typed_mutation_verified",
"terminal_receipt_replayed",
"stale_precondition_refused",
"generic_command_denied"
],
"observations": {
"action_receipt_kind": "pulse.host_storage_cleanup_result",
"generic_command_denied": true,
"mutation_started": true,
"stale_precondition_mutation_started": false,
"verification": "verified"
},
"transcript_event_ids": [
"event-0064"
]
}
},
{
"sequence": 11,
"name": "action_runner_credential_rotation",
"passed": true,
"started_at": "2026-08-30T18:11:40.533544715Z",
"completed_at": "2026-08-30T18:12:03.915338343Z",
"evidence": {
"kind": "runtime-observation-v1",
"summary": "mismatched invalidation was rejected, exact superseded session closed, replacement credential registered and activated",
"claims": [
"fixture_credential_replacement_observed"
],
"observations": {
"fixture_activation_requests": 2,
"proof_scope": "in-memory-fixture",
"replacement_registered": true,
"superseded_session_invalidated": true
},
"transcript_event_ids": [
"event-0066"
]
}
},
{
"sequence": 12,
"name": "action_runner_self_revoke",
"passed": true,
"started_at": "2026-08-30T18:12:03.915338343Z",
"completed_at": "2026-08-30T18:12:04.285982642Z",
"evidence": {
"kind": "runtime-observation-v1",
"summary": "uninstall revoked the exact host binding and removed only runner state; collector/helper continuity remained healthy",
"claims": [
"exact_runner_binding_revoked"
],
"observations": {
"collector_continuity": true,
"revocation_count": 1
},
"transcript_event_ids": [
"event-0078"
]
}
}
]
}
@@ -0,0 +1,81 @@
{"sequence":1,"event_id":"event-0001","observed_at":"2026-08-30T18:10:18.362321296Z","kind":"command_output","operation":"uname","output":"Linux 6.8.0-117-generic #117-Ubuntu SMP PREEMPT_DYNAMIC Thu May 7 17:26:37 UTC 2026 aarch64 GNU/Linux\n","output_sha256":"e811a5e87379ce7ecb7a58b34bea7986bd3fdf5fdfbc816a10ed0207284c5e1a"}
{"sequence":2,"event_id":"event-0002","observed_at":"2026-08-30T18:10:18.363429665Z","kind":"command_output","operation":"systemctl","output":"systemd 255 (255.4-1ubuntu8.15)\n+PAM +AUDIT +SELINUX +APPARMOR +IMA +SMACK +SECCOMP +GCRYPT -GNUTLS +OPENSSL +ACL +BLKID +CURL +ELFUTILS +FIDO2 +IDN2 -IDN +IPTC +KMOD +LIBCRYPTSETUP +LIBFDISK +PCRE2 -PWQUALITY +P11KIT +QRENCODE +TPM2 +BZIP2 +LZ4 +XZ +ZLIB +ZSTD -BPF_FRAMEWORK -XKBCOMMON +UTMP +SYSVINIT default-hierarchy=unified\n","output_sha256":"e17b32215432ff3a0180f661c415aadce050a16ff595a2d691e7e1c8afa5a715"}
{"sequence":3,"event_id":"event-0003","observed_at":"2026-08-30T18:10:20.738316511Z","kind":"command_output","operation":"installer --enable-commands --command-authority command-capable --enable-docker","output":"[INFO] Detecting available platforms...\n[INFO] Monitoring configuration:\n[INFO] Agent metrics: true\n[INFO] Docker/Podman: true\n[INFO] Kubernetes: false\n[INFO] Proxmox: false\n[INFO] Pulse command execution: true\n[INFO] Accepts Pulse-scoped command requests on this agent.\n[INFO] On Proxmox nodes this is required for opted-in LXC Docker inventory via pct exec.\n[INFO] The Pulse server must also be started with PULSE_ENABLE_PROXMOX_GUEST_DOCKER_INVENTORY=true.\n[INFO] Pulse server version: v6.4.1-secure-v4.1\n[INFO] Downloading agent from http://127.0.0.1:35287/download/pulse-agent?arch=linux-arm64\u0026serverVersion=v6.4.1-secure-v4.1...\n[INFO] Binary checksum verified\n[INFO] Installing binary to /usr/local/bin/pulse-agent...\n[INFO] Configuring Systemd service at /etc/systemd/system/pulse-agent.service...\n[INFO] Token stored securely at /var/lib/pulse-agent/token (mode 600)\n[INFO] Verifying agent started successfully...\n[INFO] Agent is running, healthy, and registered with Pulse.\n[INFO] Installation complete! Agent is running.\n[INFO] To uninstall later: sudo bash /var/lib/pulse-agent/install.sh --uninstall\n[INFO] Token file: /var/lib/pulse-agent/token (mode 600, root only)\n","output_sha256":"b731d1da60b0403f9523f5cf0a5636c2fb281077a5b59aa6530df4be0d5ac41e"}
{"sequence":4,"event_id":"event-0004","observed_at":"2026-08-30T18:10:20.745966242Z","kind":"command_output","operation":"systemctl","output":"root\n","output_sha256":"53175bcc0524f37b47062fafdda28e3f8eb91d519ca0a184ca71bbebe72f969a"}
{"sequence":5,"event_id":"event-0005","observed_at":"2026-08-30T18:10:20.752702313Z","kind":"command_output","operation":"systemctl","output":"2051\n","output_sha256":"dba4ed9a9905ad118e34ffb5d5dedcdba00cfe293551f569872da45cb51c4e29"}
{"sequence":6,"event_id":"event-0006","observed_at":"2026-08-30T18:10:20.755228517Z","kind":"command_output","operation":"systemctl","output":"active\n","output_sha256":"45df5ad5e0ecfa54d3226343e0e6857337494ba6e32f189d1174070665d8c659"}
{"sequence":7,"event_id":"event-0007","observed_at":"2026-08-30T18:10:20.7594628Z","kind":"scenario_result","scenario":"legacy_root_command_capable_install","claims":["legacy_root_command_authority_observed"],"observations":{"collector_process_uid":0,"commands_enabled":true},"summary":"root collector installed; docker_enabled=true","output":""}
{"sequence":8,"event_id":"event-0008","observed_at":"2026-08-30T18:10:20.824220298Z","kind":"command_output","operation":"installer --safe-profile-inspect","output":"Pulse safe-profile migration inspection (read-only)\nplatform_supported=true\ncurrent_profile=legacy-root-command-capable\nunit_fragment_path=/etc/systemd/system/pulse-agent.service\nunit_drop_in_paths=none\nunit_unoverridden=true\nunit_user=root\nunit_groups=root\nambient_capabilities=none\ncollector_binary_owner=root:root\ncollector_binary_mode=755\nprovider_host=true\nprovider_docker=true\nprovider_kubernetes=false\nprovider_proxmox=false\ntyped_helper=false\ncollector_commands=true\naction_runner_independent=false\ntarget_profile=typed-helper-monitoring-only\ntarget_unit_user=pulse-agent\ntarget_groups=no-rootful-docker-group\ntarget_ambient_capabilities=none\ntarget_binary_owner=root:root\ntarget_commands=false\ntarget_smart=typed-helper\ntarget_proxmox_filesystems=typed-helper\ntarget_action_runner=unchanged\ndegraded_docker=rootful daemon access is removed unless an independently usable rootless socket is configured\ndegraded_actions=collector command authority is removed; remediation requires the separately enrolled action runner\n","output_sha256":"376efea67abd4ca23aacf07523723860239c7f449d6e9f8fe99d2313602bf250"}
{"sequence":9,"event_id":"event-0009","observed_at":"2026-08-30T18:10:20.852343562Z","kind":"scenario_result","scenario":"read_only_inspect","claims":["inspection_left_stable_files_unchanged"],"observations":{"stable_files_unchanged":true},"summary":"stable installer-owned files unchanged","output":""}
{"sequence":10,"event_id":"event-0010","observed_at":"2026-08-30T18:10:20.945822872Z","kind":"command_output","operation":"systemctl","output":"","output_sha256":"e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"}
{"sequence":11,"event_id":"event-0011","observed_at":"2026-08-30T18:10:21.03806768Z","kind":"command_output","operation":"installer --safe-profile-apply","output":"[INFO] Recovering connection details from /var/lib/pulse-agent/connection.env...\n[INFO] Recovered connection details from the running Pulse Agent process.\n[INFO] Detecting available platforms...\n[INFO] Monitoring configuration:\n[INFO] Agent metrics: true\n[INFO] Docker/Podman: true\n[INFO] Kubernetes: false\n[INFO] Proxmox: false\n[INFO] Pulse command execution: false\n[INFO] Command execution is off; enable only when Patrol actions or Proxmox LXC Docker inventory are needed.\n[WARN] Safe-profile migration disabled rootful Docker monitoring: the collector has no usable collector-owned rootless runtime. Container monitoring is an explicit migration degradation, not helper parity.\n[ERROR] Refusing safe-profile migration while the collector has a different effective FragmentPath or any systemd drop-in override; consolidate the effective unit first\n","output_sha256":"8e7d2f524d16df3fcaf4c659c3a731340e9dc47c8e0fa144c511cf740048e671"}
{"sequence":12,"event_id":"event-0012","observed_at":"2026-08-30T18:10:21.145112938Z","kind":"command_output","operation":"systemctl","output":"","output_sha256":"e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"}
{"sequence":13,"event_id":"event-0013","observed_at":"2026-08-30T18:10:21.145118405Z","kind":"scenario_result","scenario":"drop_in_fail_closed_rehearsal","claims":["drop_in_rejected_before_mutation"],"observations":{"rejected_before_mutation":true},"summary":"migration rejected before stable installer-owned files changed","output":""}
{"sequence":14,"event_id":"event-0014","observed_at":"2026-08-30T18:10:28.385102455Z","kind":"command_output","operation":"installer --safe-profile-apply","output":"[INFO] Recovering connection details from /var/lib/pulse-agent/connection.env...\n[INFO] Recovered connection details from the running Pulse Agent process.\n[INFO] Detecting available platforms...\n[INFO] Monitoring configuration:\n[INFO] Agent metrics: true\n[INFO] Docker/Podman: true\n[INFO] Kubernetes: false\n[INFO] Proxmox: false\n[INFO] Pulse command execution: false\n[INFO] Command execution is off; enable only when Patrol actions or Proxmox LXC Docker inventory are needed.\n[WARN] Safe-profile migration disabled rootful Docker monitoring: the collector has no usable collector-owned rootless runtime. Container monitoring is an explicit migration degradation, not helper parity.\n[INFO] Snapshotted legacy-root-command-capable collector/helper profile before migration.\n[INFO] Durably removed execution and cross-host management scopes from the collector credential before migration.\n[INFO] Pulse server version: v6.4.1-secure-v4.1\n[INFO] Downloading agent from http://127.0.0.1:35287/download/pulse-agent?arch=linux-arm64\u0026serverVersion=v6.4.1-secure-v4.1...\n[INFO] Binary checksum verified\n[INFO] Downloading typed privileged helper from http://127.0.0.1:35287/download/pulse-agent-helper?arch=linux-arm64\u0026serverVersion=v6.4.1-secure-v4.1...\n[INFO] Typed privileged helper binary verified\n[WARN] Downloaded agent version (v6.4.1-secure-v4.2) does not match Pulse server version (v6.4.1-secure-v4.1). Check that Pulse is upgraded and that any reverse proxy is not serving a stale cached binary.\n[INFO] Existing installation detected: v6.4.1-secure-v4.1\n[INFO] Upgrading to: v6.4.1-secure-v4.2\n[INFO] Stopping existing pulse-agent service...\n[INFO] Installing binary to /usr/local/bin/pulse-agent...\n[INFO] Binary upgraded successfully. Updating service configuration...\n[INFO] Configuring Systemd service at /etc/systemd/system/pulse-agent.service...\n[INFO] Token stored securely at /etc/pulse-agent/token (mode 600)\n[INFO] Created system user pulse-agent\nCreated symlink /etc/systemd/system/sockets.target.wants/pulse-agent-helper.socket → /etc/systemd/system/pulse-agent-helper.socket.\n[INFO] Typed privileged helper socket active at /run/pulse-agent/helper.sock (root:pulse-agent 0660)\n[INFO] Typed-helper collector profile: service runs as pulse-agent; binaries and credential files remain root-owned while mutable state remains pulse-agent-owned.\n[INFO] Committed typed-helper monitoring-only profile; rollback snapshot retained at /var/lib/pulse-agent-profile/transaction-20260830T181021Z-2332.\n[INFO] Verifying agent started successfully...\n[INFO] Agent is running, healthy, and registered with Pulse.\n[INFO] Upgrade complete! Agent restarted with new configuration.\n[INFO] To uninstall later: sudo bash /var/lib/pulse-agent/install.sh --uninstall\n","output_sha256":"adb83b61744c1698374d8f20fb255ba84736bdb261528ef67a3248bf9cdd588f"}
{"sequence":15,"event_id":"event-0015","observed_at":"2026-08-30T18:10:28.390060514Z","kind":"command_output","operation":"systemctl","output":"pulse-agent\n","output_sha256":"34d6cc22cb99bd7b3aca0e87e15484537e7d6d1c915333fee99537265fd04271"}
{"sequence":16,"event_id":"event-0016","observed_at":"2026-08-30T18:10:28.394295139Z","kind":"command_output","operation":"systemctl","output":"\n","output_sha256":"01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b"}
{"sequence":17,"event_id":"event-0017","observed_at":"2026-08-30T18:10:28.400601885Z","kind":"command_output","operation":"systemctl","output":"PULSE_AGENT_HELPER_SOCKET=/run/pulse-agent/helper.sock\n","output_sha256":"b9e3421218efb6f874e831eca30c501ea84b75cc4f06e2146bf642aabbdc2e8c"}
{"sequence":18,"event_id":"event-0018","observed_at":"2026-08-30T18:10:28.401049542Z","kind":"command_output","operation":"id","output":"996\n","output_sha256":"009cbb4830299d01fc84a6a56d4f07707d7d073673f6cde576027bafbac75168"}
{"sequence":19,"event_id":"event-0019","observed_at":"2026-08-30T18:10:28.403462797Z","kind":"command_output","operation":"systemctl","output":"2775\n","output_sha256":"a8d9dbab58c95589525422a9b79cde314bf2a37c2b53b516c4e60f1ea5554b1a"}
{"sequence":20,"event_id":"event-0020","observed_at":"2026-08-30T18:10:28.403933478Z","kind":"command_output","operation":"id","output":"pulse-agent\n","output_sha256":"34d6cc22cb99bd7b3aca0e87e15484537e7d6d1c915333fee99537265fd04271"}
{"sequence":21,"event_id":"event-0021","observed_at":"2026-08-30T18:10:28.405883977Z","kind":"command_output","operation":"systemctl","output":"active\n","output_sha256":"45df5ad5e0ecfa54d3226343e0e6857337494ba6e32f189d1174070665d8c659"}
{"sequence":22,"event_id":"event-0022","observed_at":"2026-08-30T18:10:28.408182784Z","kind":"command_output","operation":"systemctl","output":"active\n","output_sha256":"45df5ad5e0ecfa54d3226343e0e6857337494ba6e32f189d1174070665d8c659"}
{"sequence":23,"event_id":"event-0023","observed_at":"2026-08-30T18:10:28.521114906Z","kind":"command_output","operation":"systemctl","output":"active\n","output_sha256":"45df5ad5e0ecfa54d3226343e0e6857337494ba6e32f189d1174070665d8c659"}
{"sequence":24,"event_id":"event-0024","observed_at":"2026-08-30T18:10:28.52640484Z","kind":"scenario_result","scenario":"safe_profile_apply","claims":["collector_non_root","collector_monitoring_only","helper_protocol_healthy","collector_authority_reduction_observed"],"observations":{"collector_authority":"monitoring-only","collector_service_user":"pulse-agent","helper_status":"ok"},"summary":"fresh server lastSeen, least-privilege identity, typed helper health","output":""}
{"sequence":25,"event_id":"event-0025","observed_at":"2026-08-30T18:10:28.825084783Z","kind":"command_output","operation":"installer --safe-profile-rollback","output":"[INFO] Preserving existing typed privileged-helper profile\n[INFO] Restored collector/helper profile legacy-root-command-capable; the action runner was left unchanged.\n","output_sha256":"d1b813088b5a7baefd91f310ba6fb207d605172500a6e6d84b0c6a98e9554d7d"}
{"sequence":26,"event_id":"event-0026","observed_at":"2026-08-30T18:10:30.051445232Z","kind":"command_output","operation":"systemctl","output":"root\n","output_sha256":"53175bcc0524f37b47062fafdda28e3f8eb91d519ca0a184ca71bbebe72f969a"}
{"sequence":27,"event_id":"event-0027","observed_at":"2026-08-30T18:10:30.056823643Z","kind":"command_output","operation":"systemctl","output":"3135\n","output_sha256":"8d2b36f7deec8da7564cf857265ed021d9262467645fdb18b6be0f341d6a5988"}
{"sequence":28,"event_id":"event-0028","observed_at":"2026-08-30T18:10:30.058444781Z","kind":"command_output","operation":"systemctl","output":"active\n","output_sha256":"45df5ad5e0ecfa54d3226343e0e6857337494ba6e32f189d1174070665d8c659"}
{"sequence":29,"event_id":"event-0029","observed_at":"2026-08-30T18:10:30.084995619Z","kind":"scenario_result","scenario":"explicit_safe_profile_rollback","claims":["explicit_rollback_preserved_reduced_authority"],"observations":{"commands_enabled":false,"restored_profile":"root-monitoring"},"summary":"legacy binary and service identity restored without resurrecting collector command authority","output":""}
{"sequence":30,"event_id":"event-0030","observed_at":"2026-08-30T18:11:02.581415872Z","kind":"command_output","operation":"installer --safe-profile-apply","output":"[INFO] Recovering connection details from /var/lib/pulse-agent/connection.env...\n[INFO] Recovered connection details from the running Pulse Agent process.\n[INFO] Detecting available platforms...\n[INFO] Monitoring configuration:\n[INFO] Agent metrics: true\n[INFO] Docker/Podman: true\n[INFO] Kubernetes: false\n[INFO] Proxmox: false\n[INFO] Pulse command execution: false\n[INFO] Command execution is off; enable only when Patrol actions or Proxmox LXC Docker inventory are needed.\n[WARN] Safe-profile migration disabled rootful Docker monitoring: the collector has no usable collector-owned rootless runtime. Container monitoring is an explicit migration degradation, not helper parity.\n[INFO] Snapshotted legacy-root-monitoring collector/helper profile before migration.\n[INFO] Durably removed execution and cross-host management scopes from the collector credential before migration.\n[INFO] Pulse server version: v6.4.1-secure-v4.1\n[INFO] Downloading agent from http://127.0.0.1:35287/download/pulse-agent?arch=linux-arm64\u0026serverVersion=v6.4.1-secure-v4.1...\n[INFO] Binary checksum verified\n[INFO] Downloading typed privileged helper from http://127.0.0.1:35287/download/pulse-agent-helper?arch=linux-arm64\u0026serverVersion=v6.4.1-secure-v4.1...\n[INFO] Typed privileged helper binary verified\n[WARN] Downloaded agent version (v6.4.1-secure-v4.2) does not match Pulse server version (v6.4.1-secure-v4.1). Check that Pulse is upgraded and that any reverse proxy is not serving a stale cached binary.\n[INFO] Existing installation detected: v6.4.1-secure-v4.1\n[INFO] Upgrading to: v6.4.1-secure-v4.2\n[INFO] Stopping existing pulse-agent service...\n[INFO] Installing binary to /usr/local/bin/pulse-agent...\n[INFO] Binary upgraded successfully. Updating service configuration...\n[INFO] Configuring Systemd service at /etc/systemd/system/pulse-agent.service...\n[INFO] Token stored securely at /etc/pulse-agent/token (mode 600)\n[INFO] Typed privileged helper socket active at /run/pulse-agent/helper.sock (root:pulse-agent 0660)\n[INFO] Typed-helper collector profile: service runs as pulse-agent; binaries and credential files remain root-owned while mutable state remains pulse-agent-owned.\n[ERROR] Safe-profile collector did not satisfy local readiness, helper availability, and server registration; restoring the previous profile\n[ERROR] Safe-profile migration did not commit; restoring the previous collector/helper profile.\n[INFO] Restored collector/helper profile legacy-root-monitoring; the action runner was left unchanged.\n","output_sha256":"0de7285656c69ca973636202bcdb919a6e3f7bee4adc1dbf68489077c30ee171"}
{"sequence":31,"event_id":"event-0031","observed_at":"2026-08-30T18:11:03.688233182Z","kind":"command_output","operation":"systemctl","output":"root\n","output_sha256":"53175bcc0524f37b47062fafdda28e3f8eb91d519ca0a184ca71bbebe72f969a"}
{"sequence":32,"event_id":"event-0032","observed_at":"2026-08-30T18:11:03.694235395Z","kind":"command_output","operation":"systemctl","output":"4041\n","output_sha256":"678fde4a9e0d6f6c48b754f0b7958a822e49b5a1e067211619c62c20523f6dd6"}
{"sequence":33,"event_id":"event-0033","observed_at":"2026-08-30T18:11:03.696233521Z","kind":"command_output","operation":"systemctl","output":"active\n","output_sha256":"45df5ad5e0ecfa54d3226343e0e6857337494ba6e32f189d1174070665d8c659"}
{"sequence":34,"event_id":"event-0034","observed_at":"2026-08-30T18:11:03.696237146Z","kind":"scenario_result","scenario":"automatic_failure_rollback","claims":["failed_activation_restored_prior_runtime"],"observations":{"activation_committed":false,"restored_profile":"root-monitoring"},"summary":"frozen lastSeen prevented commit and restored binary/state identity without command authority","output":""}
{"sequence":35,"event_id":"event-0035","observed_at":"2026-08-30T18:11:09.162063893Z","kind":"command_output","operation":"installer --update","output":"[INFO] Recovering connection details from /var/lib/pulse-agent/connection.env...\n[INFO] Recovered connection details from the running Pulse Agent process.\n[INFO] Detecting available platforms...\n[INFO] Monitoring configuration:\n[INFO] Agent metrics: true\n[INFO] Docker/Podman: true\n[INFO] Kubernetes: false\n[INFO] Proxmox: false\n[INFO] Pulse command execution: false\n[INFO] Command execution is off; enable only when Patrol actions or Proxmox LXC Docker inventory are needed.\n[INFO] Pulse server version: v6.4.1-secure-v4.1\n[INFO] Downloading agent from http://127.0.0.1:35287/download/pulse-agent?arch=linux-arm64\u0026serverVersion=v6.4.1-secure-v4.1...\n[INFO] Binary checksum verified\n[WARN] Downloaded agent version (v6.4.1-secure-v4.2) does not match Pulse server version (v6.4.1-secure-v4.1). Check that Pulse is upgraded and that any reverse proxy is not serving a stale cached binary.\n[INFO] Existing installation detected: v6.4.1-secure-v4.1\n[INFO] Upgrading to: v6.4.1-secure-v4.2\n[INFO] Stopping existing pulse-agent service...\n[INFO] Installing binary to /usr/local/bin/pulse-agent...\n[INFO] Binary upgraded successfully. Updating service configuration...\n[INFO] Configuring Systemd service at /etc/systemd/system/pulse-agent.service...\n[INFO] Token stored securely at /var/lib/pulse-agent/token (mode 600)\n[INFO] Verifying agent started successfully...\n[INFO] Agent is running, healthy, and registered with Pulse.\n[INFO] Upgrade complete! Agent restarted with new configuration.\n[INFO] To uninstall later: sudo bash /var/lib/pulse-agent/install.sh --uninstall\n","output_sha256":"ae63fcc6a44550e3fb3fd67c91d6e51429f571fc95672978ee0cb5b33f27c3e0"}
{"sequence":36,"event_id":"event-0036","observed_at":"2026-08-30T18:11:09.16587804Z","kind":"command_output","operation":"systemctl","output":"root\n","output_sha256":"53175bcc0524f37b47062fafdda28e3f8eb91d519ca0a184ca71bbebe72f969a"}
{"sequence":37,"event_id":"event-0037","observed_at":"2026-08-30T18:11:09.171831589Z","kind":"command_output","operation":"systemctl","output":"4337\n","output_sha256":"561c94f2d5cea37acc020b2bbadf8e3870ed3ec6f96be25303506e9ea87fed47"}
{"sequence":38,"event_id":"event-0038","observed_at":"2026-08-30T18:11:09.175195329Z","kind":"command_output","operation":"systemctl","output":"active\n","output_sha256":"45df5ad5e0ecfa54d3226343e0e6857337494ba6e32f189d1174070665d8c659"}
{"sequence":39,"event_id":"event-0039","observed_at":"2026-08-30T18:11:09.208098298Z","kind":"scenario_result","scenario":"ordinary_update_non_migration","claims":["ordinary_update_preserved_selected_profile"],"observations":{"collector_v2_installed":true,"selected_profile":"root-monitoring"},"summary":"binary updated while the downgraded root monitoring profile remained unchanged","output":""}
{"sequence":40,"event_id":"event-0040","observed_at":"2026-08-30T18:11:16.207403241Z","kind":"command_output","operation":"installer --safe-profile-apply","output":"[INFO] Recovering connection details from /var/lib/pulse-agent/connection.env...\n[INFO] Recovered connection details from the running Pulse Agent process.\n[INFO] Detecting available platforms...\n[INFO] Monitoring configuration:\n[INFO] Agent metrics: true\n[INFO] Docker/Podman: true\n[INFO] Kubernetes: false\n[INFO] Proxmox: false\n[INFO] Pulse command execution: false\n[INFO] Command execution is off; enable only when Patrol actions or Proxmox LXC Docker inventory are needed.\n[WARN] Safe-profile migration disabled rootful Docker monitoring: the collector has no usable collector-owned rootless runtime. Container monitoring is an explicit migration degradation, not helper parity.\n[INFO] Snapshotted legacy-root-monitoring collector/helper profile before migration.\n[INFO] Durably removed execution and cross-host management scopes from the collector credential before migration.\n[INFO] Pulse server version: v6.4.1-secure-v4.2\n[INFO] Downloading agent from http://127.0.0.1:35287/download/pulse-agent?arch=linux-arm64\u0026serverVersion=v6.4.1-secure-v4.2...\n[INFO] Binary checksum verified\n[INFO] Downloading typed privileged helper from http://127.0.0.1:35287/download/pulse-agent-helper?arch=linux-arm64\u0026serverVersion=v6.4.1-secure-v4.2...\n[INFO] Typed privileged helper binary verified\n[INFO] Existing installation detected: v6.4.1-secure-v4.2\n[INFO] Upgrading to: v6.4.1-secure-v4.2\n[INFO] Stopping existing pulse-agent service...\n[INFO] Installing binary to /usr/local/bin/pulse-agent...\n[INFO] Binary upgraded successfully. Updating service configuration...\n[INFO] Configuring Systemd service at /etc/systemd/system/pulse-agent.service...\n[INFO] Token stored securely at /etc/pulse-agent/token (mode 600)\n[INFO] Typed privileged helper socket active at /run/pulse-agent/helper.sock (root:pulse-agent 0660)\n[INFO] Typed-helper collector profile: service runs as pulse-agent; binaries and credential files remain root-owned while mutable state remains pulse-agent-owned.\n[INFO] Committed typed-helper monitoring-only profile; rollback snapshot retained at /var/lib/pulse-agent-profile/transaction-20260830T181109Z-4405.\n[INFO] Verifying agent started successfully...\n[INFO] Agent is running, healthy, and registered with Pulse.\n[INFO] Upgrade complete! Agent restarted with new configuration.\n[INFO] To uninstall later: sudo bash /var/lib/pulse-agent/install.sh --uninstall\n","output_sha256":"67bf6d2ac87ddfe499f67ad3b0ed7eed17a798ad5d0a71fe2568d281ee5051a1"}
{"sequence":41,"event_id":"event-0041","observed_at":"2026-08-30T18:11:16.211301263Z","kind":"command_output","operation":"systemctl","output":"pulse-agent\n","output_sha256":"34d6cc22cb99bd7b3aca0e87e15484537e7d6d1c915333fee99537265fd04271"}
{"sequence":42,"event_id":"event-0042","observed_at":"2026-08-30T18:11:16.21490958Z","kind":"command_output","operation":"systemctl","output":"\n","output_sha256":"01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b"}
{"sequence":43,"event_id":"event-0043","observed_at":"2026-08-30T18:11:16.221707825Z","kind":"command_output","operation":"systemctl","output":"PULSE_AGENT_HELPER_SOCKET=/run/pulse-agent/helper.sock\n","output_sha256":"b9e3421218efb6f874e831eca30c501ea84b75cc4f06e2146bf642aabbdc2e8c"}
{"sequence":44,"event_id":"event-0044","observed_at":"2026-08-30T18:11:16.222220727Z","kind":"command_output","operation":"id","output":"996\n","output_sha256":"009cbb4830299d01fc84a6a56d4f07707d7d073673f6cde576027bafbac75168"}
{"sequence":45,"event_id":"event-0045","observed_at":"2026-08-30T18:11:16.224861164Z","kind":"command_output","operation":"systemctl","output":"4839\n","output_sha256":"9c1eb9ff2bd806a5e9867911bac4c47cd10c6a30b60e9fe5e5219a54327ed523"}
{"sequence":46,"event_id":"event-0046","observed_at":"2026-08-30T18:11:16.225404821Z","kind":"command_output","operation":"id","output":"pulse-agent\n","output_sha256":"34d6cc22cb99bd7b3aca0e87e15484537e7d6d1c915333fee99537265fd04271"}
{"sequence":47,"event_id":"event-0047","observed_at":"2026-08-30T18:11:16.227948287Z","kind":"command_output","operation":"systemctl","output":"active\n","output_sha256":"45df5ad5e0ecfa54d3226343e0e6857337494ba6e32f189d1174070665d8c659"}
{"sequence":48,"event_id":"event-0048","observed_at":"2026-08-30T18:11:16.229939345Z","kind":"command_output","operation":"systemctl","output":"active\n","output_sha256":"45df5ad5e0ecfa54d3226343e0e6857337494ba6e32f189d1174070665d8c659"}
{"sequence":49,"event_id":"event-0049","observed_at":"2026-08-30T18:11:16.351868983Z","kind":"command_output","operation":"systemctl","output":"active\n","output_sha256":"45df5ad5e0ecfa54d3226343e0e6857337494ba6e32f189d1174070665d8c659"}
{"sequence":50,"event_id":"event-0050","observed_at":"2026-08-30T18:11:17.15862403Z","kind":"scenario_result","scenario":"final_safe_profile_apply","claims":["collector_reporting_continued_after_migration"],"observations":{"collector_service_user":"pulse-agent","continuity_report_observed":true},"summary":"collector continued reporting after committed migration","output":""}
{"sequence":51,"event_id":"event-0051","observed_at":"2026-08-30T18:11:40.250324493Z","kind":"command_output","operation":"installer --least-privilege --enable-privileged-helper --enable-action-runner","output":"[INFO] Detecting available platforms...\n[INFO] Docker/Podman detected - enabling container monitoring\n[INFO] (use --disable-docker to skip)\n[INFO] Monitoring configuration:\n[INFO] Agent metrics: true\n[INFO] Docker/Podman: true\n[INFO] Kubernetes: false\n[INFO] Proxmox: false\n[INFO] Pulse command execution: false\n[INFO] Command execution is off; enable only when Patrol actions or Proxmox LXC Docker inventory are needed.\n[INFO] Pulse server version: v6.4.1-secure-v4.2\n[INFO] Downloading agent from http://127.0.0.1:35287/download/pulse-agent?arch=linux-arm64\u0026serverVersion=v6.4.1-secure-v4.2...\n[INFO] Binary checksum verified\n[INFO] Downloading typed privileged helper from http://127.0.0.1:35287/download/pulse-agent-helper?arch=linux-arm64\u0026serverVersion=v6.4.1-secure-v4.2...\n[INFO] Typed privileged helper binary verified\n[INFO] Downloading typed action runner from http://127.0.0.1:35287/download/pulse-agent-runner?arch=linux-arm64\u0026serverVersion=v6.4.1-secure-v4.2...\n[INFO] Typed action runner binary verified\n[INFO] Existing installation detected: v6.4.1-secure-v4.2\n[INFO] Upgrading to: v6.4.1-secure-v4.2\n[INFO] Stopping existing pulse-agent service...\n[INFO] Installing binary to /usr/local/bin/pulse-agent...\n[INFO] Binary upgraded successfully. Updating service configuration...\n[INFO] Configuring Systemd service at /etc/systemd/system/pulse-agent.service...\n[INFO] Token stored securely at /etc/pulse-agent/token (mode 600)\n[INFO] Typed privileged helper socket active at /run/pulse-agent/helper.sock (root:pulse-agent 0660)\n[INFO] Typed-helper collector profile: service runs as pulse-agent; binaries and credential files remain root-owned while mutable state remains pulse-agent-owned.\nCreated symlink /etc/systemd/system/multi-user.target.wants/pulse-agent-runner.service → /etc/systemd/system/pulse-agent-runner.service.\n[INFO] Typed action runner enabled as a separate root service with its own credential; collector monitoring remains independently active.\n[INFO] Verifying agent started successfully...\n[WARN] Agent process is running but did not become ready within ~18s.\n[WARN] It may still be initializing. Check logs: tail -f /var/log/pulse-agent.log\n[WARN] Upgrade complete, but the agent may not be running correctly.\n[INFO] To uninstall later: sudo bash /var/lib/pulse-agent/install.sh --uninstall\n","output_sha256":"b0d8d70d332b15fe826244ca9f92141c6b29beaa7ba591587d584c36473879bb"}
{"sequence":52,"event_id":"event-0052","observed_at":"2026-08-30T18:11:40.253514384Z","kind":"command_output","operation":"systemctl","output":"active\n","output_sha256":"45df5ad5e0ecfa54d3226343e0e6857337494ba6e32f189d1174070665d8c659"}
{"sequence":53,"event_id":"event-0053","observed_at":"2026-08-30T18:11:40.257591464Z","kind":"command_output","operation":"systemctl","output":"root\n","output_sha256":"53175bcc0524f37b47062fafdda28e3f8eb91d519ca0a184ca71bbebe72f969a"}
{"sequence":54,"event_id":"event-0054","observed_at":"2026-08-30T18:11:40.260239275Z","kind":"command_output","operation":"systemctl","output":"\n","output_sha256":"01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b"}
{"sequence":55,"event_id":"event-0055","observed_at":"2026-08-30T18:11:40.262872878Z","kind":"command_output","operation":"systemctl","output":"pulse-agent\n","output_sha256":"34d6cc22cb99bd7b3aca0e87e15484537e7d6d1c915333fee99537265fd04271"}
{"sequence":56,"event_id":"event-0056","observed_at":"2026-08-30T18:11:40.265266171Z","kind":"command_output","operation":"systemctl","output":"\n","output_sha256":"01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b"}
{"sequence":57,"event_id":"event-0057","observed_at":"2026-08-30T18:11:40.272183659Z","kind":"command_output","operation":"systemctl","output":"PULSE_AGENT_HELPER_SOCKET=/run/pulse-agent/helper.sock\n","output_sha256":"b9e3421218efb6f874e831eca30c501ea84b75cc4f06e2146bf642aabbdc2e8c"}
{"sequence":58,"event_id":"event-0058","observed_at":"2026-08-30T18:11:40.272633649Z","kind":"command_output","operation":"id","output":"996\n","output_sha256":"009cbb4830299d01fc84a6a56d4f07707d7d073673f6cde576027bafbac75168"}
{"sequence":59,"event_id":"event-0059","observed_at":"2026-08-30T18:11:40.274950938Z","kind":"command_output","operation":"systemctl","output":"5371\n","output_sha256":"99a39a35c441842e9cda35b8fffcf669f5da52a897266d56e90884fdbe142f8c"}
{"sequence":60,"event_id":"event-0060","observed_at":"2026-08-30T18:11:40.275348132Z","kind":"command_output","operation":"id","output":"pulse-agent\n","output_sha256":"34d6cc22cb99bd7b3aca0e87e15484537e7d6d1c915333fee99537265fd04271"}
{"sequence":61,"event_id":"event-0061","observed_at":"2026-08-30T18:11:40.276960621Z","kind":"command_output","operation":"systemctl","output":"active\n","output_sha256":"45df5ad5e0ecfa54d3226343e0e6857337494ba6e32f189d1174070665d8c659"}
{"sequence":62,"event_id":"event-0062","observed_at":"2026-08-30T18:11:40.279389417Z","kind":"command_output","operation":"systemctl","output":"active\n","output_sha256":"45df5ad5e0ecfa54d3226343e0e6857337494ba6e32f189d1174070665d8c659"}
{"sequence":63,"event_id":"event-0063","observed_at":"2026-08-30T18:11:40.279395293Z","kind":"scenario_result","scenario":"separate_action_runner_install","claims":["action_runner_registered_separately"],"observations":{"collector_service_user":"pulse-agent","fixture_activation_requests":1,"runner_service_user":"root"},"summary":"root action runner registered and activated independently while the collector remained non-root and reporting","output":""}
{"sequence":64,"event_id":"event-0064","observed_at":"2026-08-30T18:11:40.533544715Z","kind":"scenario_result","scenario":"typed_action_receipt","claims":["typed_mutation_verified","terminal_receipt_replayed","stale_precondition_refused","generic_command_denied"],"observations":{"action_receipt_kind":"pulse.host_storage_cleanup_result","generic_command_denied":true,"mutation_started":true,"stale_precondition_mutation_started":false,"verification":"verified"},"summary":"verified apt cache mutation and durable terminal receipt; stale fingerprint refused before mutation; generic command dispatch denied","output":""}
{"sequence":65,"event_id":"event-0065","observed_at":"2026-08-30T18:12:03.915316425Z","kind":"command_output","operation":"installer --least-privilege --enable-privileged-helper --enable-action-runner","output":"[INFO] Detecting available platforms...\n[INFO] Docker/Podman detected - enabling container monitoring\n[INFO] (use --disable-docker to skip)\n[INFO] Monitoring configuration:\n[INFO] Agent metrics: true\n[INFO] Docker/Podman: true\n[INFO] Kubernetes: false\n[INFO] Proxmox: false\n[INFO] Pulse command execution: false\n[INFO] Command execution is off; enable only when Patrol actions or Proxmox LXC Docker inventory are needed.\n[INFO] Pulse server version: v6.4.1-secure-v4.2\n[INFO] Downloading agent from http://127.0.0.1:35287/download/pulse-agent?arch=linux-arm64\u0026serverVersion=v6.4.1-secure-v4.2...\n[INFO] Binary checksum verified\n[INFO] Downloading typed privileged helper from http://127.0.0.1:35287/download/pulse-agent-helper?arch=linux-arm64\u0026serverVersion=v6.4.1-secure-v4.2...\n[INFO] Typed privileged helper binary verified\n[INFO] Downloading typed action runner from http://127.0.0.1:35287/download/pulse-agent-runner?arch=linux-arm64\u0026serverVersion=v6.4.1-secure-v4.2...\n[INFO] Typed action runner binary verified\n[INFO] Existing installation detected: v6.4.1-secure-v4.2\n[INFO] Upgrading to: v6.4.1-secure-v4.2\n[INFO] Stopping existing pulse-agent service...\n[INFO] Installing binary to /usr/local/bin/pulse-agent...\n[INFO] Binary upgraded successfully. Updating service configuration...\n[INFO] Configuring Systemd service at /etc/systemd/system/pulse-agent.service...\n[INFO] Token stored securely at /etc/pulse-agent/token (mode 600)\n[INFO] Typed privileged helper socket active at /run/pulse-agent/helper.sock (root:pulse-agent 0660)\n[INFO] Typed-helper collector profile: service runs as pulse-agent; binaries and credential files remain root-owned while mutable state remains pulse-agent-owned.\n[INFO] Typed action runner enabled as a separate root service with its own credential; collector monitoring remains independently active.\n[INFO] Verifying agent started successfully...\n[WARN] Agent process is running but did not become ready within ~18s.\n[WARN] It may still be initializing. Check logs: tail -f /var/log/pulse-agent.log\n[WARN] Upgrade complete, but the agent may not be running correctly.\n[INFO] To uninstall later: sudo bash /var/lib/pulse-agent/install.sh --uninstall\n","output_sha256":"ef02c81e2651ec1bb67438246da7660a2f91fce59661eeb3012739a82753a694"}
{"sequence":66,"event_id":"event-0066","observed_at":"2026-08-30T18:12:03.915338343Z","kind":"scenario_result","scenario":"action_runner_credential_rotation","claims":["fixture_credential_replacement_observed"],"observations":{"fixture_activation_requests":2,"proof_scope":"in-memory-fixture","replacement_registered":true,"superseded_session_invalidated":true},"summary":"mismatched invalidation was rejected, exact superseded session closed, replacement credential registered and activated","output":""}
{"sequence":67,"event_id":"event-0067","observed_at":"2026-08-30T18:12:04.157126044Z","kind":"command_output","operation":"standalone installer --uninstall-action-runner","output":"[INFO] Preserving existing typed privileged-helper profile\n[INFO] Revoked the action-runner credential before removing local runner state.\n[INFO] Pulse action runner removed. Collector monitoring was left installed and running.\n","output_sha256":"909539d49081a87ab0bf02af5743dcef8ab3564f602723a21f0bb565b566b70f"}
{"sequence":68,"event_id":"event-0068","observed_at":"2026-08-30T18:12:04.160278256Z","kind":"command_output","operation":"systemctl","output":"not-found\n","output_sha256":"391bc413c3044926b4afa41806bf4a5c4fad68a3165b8563fe1bffec0792fc76"}
{"sequence":69,"event_id":"event-0069","observed_at":"2026-08-30T18:12:04.162746065Z","kind":"command_output","operation":"systemctl","output":"pulse-agent\n","output_sha256":"34d6cc22cb99bd7b3aca0e87e15484537e7d6d1c915333fee99537265fd04271"}
{"sequence":70,"event_id":"event-0070","observed_at":"2026-08-30T18:12:04.164660352Z","kind":"command_output","operation":"systemctl","output":"\n","output_sha256":"01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b"}
{"sequence":71,"event_id":"event-0071","observed_at":"2026-08-30T18:12:04.168965652Z","kind":"command_output","operation":"systemctl","output":"PULSE_AGENT_HELPER_SOCKET=/run/pulse-agent/helper.sock\n","output_sha256":"b9e3421218efb6f874e831eca30c501ea84b75cc4f06e2146bf642aabbdc2e8c"}
{"sequence":72,"event_id":"event-0072","observed_at":"2026-08-30T18:12:04.169274165Z","kind":"command_output","operation":"id","output":"996\n","output_sha256":"009cbb4830299d01fc84a6a56d4f07707d7d073673f6cde576027bafbac75168"}
{"sequence":73,"event_id":"event-0073","observed_at":"2026-08-30T18:12:04.171324791Z","kind":"command_output","operation":"systemctl","output":"5955\n","output_sha256":"08b943ce091ddaaeb86d43519d1dc5294fc37aa857345270f44bfda34b7abcdc"}
{"sequence":74,"event_id":"event-0074","observed_at":"2026-08-30T18:12:04.171717973Z","kind":"command_output","operation":"id","output":"pulse-agent\n","output_sha256":"34d6cc22cb99bd7b3aca0e87e15484537e7d6d1c915333fee99537265fd04271"}
{"sequence":75,"event_id":"event-0075","observed_at":"2026-08-30T18:12:04.173147282Z","kind":"command_output","operation":"systemctl","output":"active\n","output_sha256":"45df5ad5e0ecfa54d3226343e0e6857337494ba6e32f189d1174070665d8c659"}
{"sequence":76,"event_id":"event-0076","observed_at":"2026-08-30T18:12:04.175360664Z","kind":"command_output","operation":"systemctl","output":"active\n","output_sha256":"45df5ad5e0ecfa54d3226343e0e6857337494ba6e32f189d1174070665d8c659"}
{"sequence":77,"event_id":"event-0077","observed_at":"2026-08-30T18:12:04.285974475Z","kind":"command_output","operation":"systemctl","output":"active\n","output_sha256":"45df5ad5e0ecfa54d3226343e0e6857337494ba6e32f189d1174070665d8c659"}
{"sequence":78,"event_id":"event-0078","observed_at":"2026-08-30T18:12:04.285982642Z","kind":"scenario_result","scenario":"action_runner_self_revoke","claims":["exact_runner_binding_revoked"],"observations":{"collector_continuity":true,"revocation_count":1},"summary":"uninstall revoked the exact host binding and removed only runner state; collector/helper continuity remained healthy","output":""}
{"sequence":79,"event_id":"event-0079","observed_at":"2026-08-30T18:12:04.289275485Z","kind":"command_output","operation":"systemctl","output":"pulse-agent\n","output_sha256":"34d6cc22cb99bd7b3aca0e87e15484537e7d6d1c915333fee99537265fd04271"}
{"sequence":80,"event_id":"event-0080","observed_at":"2026-08-30T18:12:04.293590328Z","kind":"command_output","operation":"systemctl","output":"5955\n","output_sha256":"08b943ce091ddaaeb86d43519d1dc5294fc37aa857345270f44bfda34b7abcdc"}
{"sequence":81,"event_id":"event-0081","observed_at":"2026-08-30T18:12:04.297029843Z","kind":"command_output","operation":"systemctl","output":"\n","output_sha256":"01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b"}
+15 -10
View File
@@ -196,25 +196,30 @@ or generic command path.
| Platform or capability | Preferred boundary | Safe-profile behavior | Qualification and default implication | Residual owner and removal condition |
|---|---|---|---|---|
| Proxmox VE/PBS/PMG inventory, status, storage, and ordinary metrics | API-only connection with a narrowly scoped token; no host agent | No collector, helper, or runner authority is required for this data | Supported independently of the safe host-agent profile; it does not prove host-local SMART, LXC filesystem, or action parity | `agent-lifecycle`: keep API permissions and returned telemetry covered by provider tests |
| Standard Linux systemd host telemetry and collector update | Unprivileged `pulse-agent` plus the root-owned typed helper | Core `/proc`, filesystem, network, RAID, and hwmon telemetry stays in the collector; helper-backed signed update activation is implemented but its live activation/recovery transaction is not qualified | **Qualified on disposable Ubuntu 24.04.4 arm64 at committed main** for install, migration, explicit/automatic profile rollback, helper health, reporting continuity, and process/credential separation. The receipt's ordinary update ran under the downgraded root monitoring profile and does not prove `agent_update.activate.v1`, executable-digest commit, watchdog rollback, interrupted recovery, or last-known-good restoration. Remains opt-in pending those live scenarios, exact-RC reproduction, and external review | `deployment-installability` and `security-privacy`: qualify helper activation/failure/recovery from the designated release candidate and accept the external boundary review |
| Standard Linux systemd host telemetry and collector update | Unprivileged `pulse-agent` plus the root-owned typed helper | Core `/proc`, filesystem, network, RAID, and hwmon telemetry stays in the collector; helper-backed signed update activation is implemented but its live activation/recovery transaction is not qualified | **Qualified on disposable Ubuntu 24.04.4 arm64 at committed main `defc24af837b91428fbee939d09cd31e9559fb4f`** for install, migration, explicit/automatic profile rollback, helper health, reporting continuity, and process/credential separation. The schema-v4 receipt's ordinary update ran under the downgraded root monitoring profile and does not prove `agent_update.activate.v1`, executable-digest commit, watchdog rollback, interrupted recovery, or last-known-good restoration. Remains opt-in pending those live scenarios, exact-RC reproduction, and external review | `deployment-installability` and `security-privacy`: qualify helper activation/failure/recovery from the designated release candidate and accept the external boundary review |
| Linux SMART telemetry | `smart.snapshot` through the no-network helper; no caller-selected device or arguments | Implemented, unqualified on representative physical disks. Helper failure omits/degrades SMART only; the collector does not retry as root | Does not yet justify SMART parity or a default change | `agent-lifecycle`: record live SATA, SAS/controller, USB bridge, and NVMe evidence, including standby, permission failure, timeout, and partial-data cases |
| Proxmox node-local LXC filesystem telemetry | `proxmox.lxc_filesystems` through the no-network helper using fixed bounded `pct` operations | Implemented, unqualified on a representative PVE node. Helper failure omits/degrades this snapshot only | Does not yet justify Proxmox host-agent parity or a default change | `agent-lifecycle`: record live running/stopped LXC, mount, timeout, output-bound, and helper-loss behavior on supported PVE versions |
| Rootful Docker or Podman inventory | No direct collector access to a root-equivalent daemon socket | **Unavailable in the safe profile.** Migration disables the provider visibly. A closed helper `container.inventory` operation exists, but collector integration and live parity are not qualified | Rootful container parity is an explicit default blocker; the legacy/root profile is not safe-profile evidence | `agent-lifecycle`: either integrate and qualify bounded helper inventory or retain the explicit degradation permanently |
| Collector-owned rootless Docker or Podman | Direct access only to one usable runtime socket owned by the `pulse-agent` UID | Implemented, unqualified live. Ambiguous, root-owned, unreadable, unwritable, or unavailable sockets disable container monitoring | Does not yet justify container-runtime parity or a default change | `deployment-installability`: record fresh install, migration, restart, socket-loss, ambiguity, and telemetry parity on both rootless Docker and rootless Podman |
| Separate runner package update and package-cache cleanup | Root-owned `pulse-agent-runner`, host-bound action credential, typed request, postcondition, and durable receipt | A real verified apt-cache mutation, stale-fingerprint refusal, replay, and self-revocation are present in the committed-main systemd receipt. Two-phase credential activation and nonce-bound readiness are implemented but need fresh production-path qualification | Qualified only for the exercised apt-cache mutation; the receipt does not prove the current Router/TLS/durable-persistence credential lifecycle, every runner operation, or an exact release candidate | `agent-lifecycle` and `api-contracts`: reproduce through the production Router over HTTPS from the RC, including failed activation/rollback and representative package-update success/failure/cancellation evidence |
| Separate runner package update and package-cache cleanup | Root-owned `pulse-agent-runner`, host-bound action credential, typed request, postcondition, and durable receipt | The schema-v4 committed-main systemd receipt records a real verified apt-cache mutation, stale-fingerprint refusal, replay, nonce-bound readiness, exact credential rotation, and self-revocation | Qualified only for those exercised fixture paths; the receipt does not prove the production Router/TLS/durable-persistence credential lifecycle, failed activation rollback, every runner operation, or an exact release candidate | `agent-lifecycle` and `api-contracts`: reproduce through the production Router over HTTPS from the RC, including failed activation/rollback and representative package-update success/failure/cancellation evidence |
| Separate runner Proxmox guest and container lifecycle/update actions | Root-owned runner with closed typed protocols; never the monitoring collector | Implemented, unqualified on representative PVE and container-runtime targets | No live-provider action-parity claim and no default change | `agent-lifecycle`: record target-bound success, stale-state refusal, cancellation, reconnect/replay, and independent postconditions on disposable real targets |
| Appliance, non-systemd, Windows, and macOS host-agent profiles | Platform API where sufficient; otherwise an explicitly named legacy/full-trust profile | **Unavailable for safe-profile apply.** The installer fails closed instead of silently installing a root-equivalent profile | Excluded from the Linux safe-profile claim | `deployment-installability`: land a platform-specific service, filesystem, update, helper, migration, rollback, and live-proof contract before marking that platform supported |
The committed-main Linux evidence is recorded in
`docs/release-control/v6/internal/records/secure-agent-runtime-qualification-foundation-2026-08-30.md`.
That receipt is artifact-bound operator self-attestation, not an independently
authenticated external assessment. The safe profile therefore remains opt-in.
The current attester requires a fresh schema-v4 run: it expands a committed
production-source manifest, requires exact source membership, binds ordered
scenario claims to a retained secret-free JSONL transcript, validates typed
receipt/report chronology, and hashes the intended repository record path
inside the receipt. The existing v3 record remains historical and is not
silently promoted to this stronger evidence class.
The current schema-v4 receipt qualifies exact committed main
`defc24af837b91428fbee939d09cd31e9559fb4f`. Its attestation verifies a
345-source production manifest, clean exact-commit identities for all four
artifacts, twelve ordered scenario claims, and a retained secret-free JSONL
transcript containing 81 events. The receipt, transcript, and attestation have
SHA-256 digests
`58da80f7d75d414c12cf6632bd895b821ce759625e7d00ae00c16d56204b1e76`,
`616681aee38202ed922880288b730cd85f746e081f8f9d45bb2d570e48b49f8c`, and
`a48e855fdd2dcbc0cf91717dfaed22f942320c9661dd9b9e8f8f8e97f45d654b`.
This remains artifact-bound operator self-attestation, not an independently
authenticated external assessment or production Router/TLS/durable-store
exercise. The existing v3 record remains historical. The safe profile
therefore remains opt-in.
Monitoring never implies remediation. On the supported Linux systemd profile,
an operator may separately enroll the typed action runner: