diff --git a/.gitleaksignore b/.gitleaksignore index 1dca834ff..f6a157761 100644 --- a/.gitleaksignore +++ b/.gitleaksignore @@ -4,6 +4,44 @@ frontend-modern/browser-verification.json:generic-api-key:11 frontend-modern/browser-verification.json:generic-api-key:12 +# Schema-v4 secure-runtime evidence stores SHA-256 source digests beside source +# paths whose names contain auth/token terminology. Suppress only those exact +# generated path/rule/line fingerprints; the transcript remains fully scanned. +docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:80 +docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:81 +docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:82 +docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:83 +docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:84 +docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:87 +docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:97 +docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:119 +docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:128 +docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:129 +docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:130 +docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:135 +docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:144 +docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:242 +docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:262 +docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:277 +docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json:generic-api-key:304 +docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:56 +docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:57 +docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:58 +docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:59 +docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:60 +docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:63 +docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:73 +docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:95 +docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:104 +docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:105 +docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:106 +docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:111 +docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:120 +docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:218 +docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:238 +docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:253 +docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json:generic-api-key:280 + # Historical findings proven to be deterministic examples, placeholders, or # public-key/path false positives. Keep these commit-, path-, rule-, and # line-specific so provider credentials and expired tokens remain visible. diff --git a/docs/AGENT_SECURITY.md b/docs/AGENT_SECURITY.md index d51c67e2b..f07a36007 100644 --- a/docs/AGENT_SECURITY.md +++ b/docs/AGENT_SECURITY.md @@ -196,25 +196,30 @@ or generic command path. | Platform or capability | Preferred boundary | Safe-profile behavior | Qualification and default implication | Residual owner and removal condition | |---|---|---|---|---| | Proxmox VE/PBS/PMG inventory, status, storage, and ordinary metrics | API-only connection with a narrowly scoped token; no host agent | No collector, helper, or runner authority is required for this data | Supported independently of the safe host-agent profile; it does not prove host-local SMART, LXC filesystem, or action parity | `agent-lifecycle`: keep API permissions and returned telemetry covered by provider tests | -| Standard Linux systemd host telemetry and collector update | Unprivileged `pulse-agent` plus the root-owned typed helper | Core `/proc`, filesystem, network, RAID, and hwmon telemetry stays in the collector; helper-backed signed update activation is implemented but its live activation/recovery transaction is not qualified | **Qualified on disposable Ubuntu 24.04.4 arm64 at committed main** for install, migration, explicit/automatic profile rollback, helper health, reporting continuity, and process/credential separation. The receipt's ordinary update ran under the downgraded root monitoring profile and does not prove `agent_update.activate.v1`, executable-digest commit, watchdog rollback, interrupted recovery, or last-known-good restoration. Remains opt-in pending those live scenarios, exact-RC reproduction, and external review | `deployment-installability` and `security-privacy`: qualify helper activation/failure/recovery from the designated release candidate and accept the external boundary review | +| Standard Linux systemd host telemetry and collector update | Unprivileged `pulse-agent` plus the root-owned typed helper | Core `/proc`, filesystem, network, RAID, and hwmon telemetry stays in the collector; helper-backed signed update activation is implemented but its live activation/recovery transaction is not qualified | **Qualified on disposable Ubuntu 24.04.4 arm64 at committed main `defc24af837b91428fbee939d09cd31e9559fb4f`** for install, migration, explicit/automatic profile rollback, helper health, reporting continuity, and process/credential separation. The schema-v4 receipt's ordinary update ran under the downgraded root monitoring profile and does not prove `agent_update.activate.v1`, executable-digest commit, watchdog rollback, interrupted recovery, or last-known-good restoration. Remains opt-in pending those live scenarios, exact-RC reproduction, and external review | `deployment-installability` and `security-privacy`: qualify helper activation/failure/recovery from the designated release candidate and accept the external boundary review | | Linux SMART telemetry | `smart.snapshot` through the no-network helper; no caller-selected device or arguments | Implemented, unqualified on representative physical disks. Helper failure omits/degrades SMART only; the collector does not retry as root | Does not yet justify SMART parity or a default change | `agent-lifecycle`: record live SATA, SAS/controller, USB bridge, and NVMe evidence, including standby, permission failure, timeout, and partial-data cases | | Proxmox node-local LXC filesystem telemetry | `proxmox.lxc_filesystems` through the no-network helper using fixed bounded `pct` operations | Implemented, unqualified on a representative PVE node. Helper failure omits/degrades this snapshot only | Does not yet justify Proxmox host-agent parity or a default change | `agent-lifecycle`: record live running/stopped LXC, mount, timeout, output-bound, and helper-loss behavior on supported PVE versions | | Rootful Docker or Podman inventory | No direct collector access to a root-equivalent daemon socket | **Unavailable in the safe profile.** Migration disables the provider visibly. A closed helper `container.inventory` operation exists, but collector integration and live parity are not qualified | Rootful container parity is an explicit default blocker; the legacy/root profile is not safe-profile evidence | `agent-lifecycle`: either integrate and qualify bounded helper inventory or retain the explicit degradation permanently | | Collector-owned rootless Docker or Podman | Direct access only to one usable runtime socket owned by the `pulse-agent` UID | Implemented, unqualified live. Ambiguous, root-owned, unreadable, unwritable, or unavailable sockets disable container monitoring | Does not yet justify container-runtime parity or a default change | `deployment-installability`: record fresh install, migration, restart, socket-loss, ambiguity, and telemetry parity on both rootless Docker and rootless Podman | -| Separate runner package update and package-cache cleanup | Root-owned `pulse-agent-runner`, host-bound action credential, typed request, postcondition, and durable receipt | A real verified apt-cache mutation, stale-fingerprint refusal, replay, and self-revocation are present in the committed-main systemd receipt. Two-phase credential activation and nonce-bound readiness are implemented but need fresh production-path qualification | Qualified only for the exercised apt-cache mutation; the receipt does not prove the current Router/TLS/durable-persistence credential lifecycle, every runner operation, or an exact release candidate | `agent-lifecycle` and `api-contracts`: reproduce through the production Router over HTTPS from the RC, including failed activation/rollback and representative package-update success/failure/cancellation evidence | +| Separate runner package update and package-cache cleanup | Root-owned `pulse-agent-runner`, host-bound action credential, typed request, postcondition, and durable receipt | The schema-v4 committed-main systemd receipt records a real verified apt-cache mutation, stale-fingerprint refusal, replay, nonce-bound readiness, exact credential rotation, and self-revocation | Qualified only for those exercised fixture paths; the receipt does not prove the production Router/TLS/durable-persistence credential lifecycle, failed activation rollback, every runner operation, or an exact release candidate | `agent-lifecycle` and `api-contracts`: reproduce through the production Router over HTTPS from the RC, including failed activation/rollback and representative package-update success/failure/cancellation evidence | | Separate runner Proxmox guest and container lifecycle/update actions | Root-owned runner with closed typed protocols; never the monitoring collector | Implemented, unqualified on representative PVE and container-runtime targets | No live-provider action-parity claim and no default change | `agent-lifecycle`: record target-bound success, stale-state refusal, cancellation, reconnect/replay, and independent postconditions on disposable real targets | | Appliance, non-systemd, Windows, and macOS host-agent profiles | Platform API where sufficient; otherwise an explicitly named legacy/full-trust profile | **Unavailable for safe-profile apply.** The installer fails closed instead of silently installing a root-equivalent profile | Excluded from the Linux safe-profile claim | `deployment-installability`: land a platform-specific service, filesystem, update, helper, migration, rollback, and live-proof contract before marking that platform supported | The committed-main Linux evidence is recorded in `docs/release-control/v6/internal/records/secure-agent-runtime-qualification-foundation-2026-08-30.md`. -That receipt is artifact-bound operator self-attestation, not an independently -authenticated external assessment. The safe profile therefore remains opt-in. -The current attester requires a fresh schema-v4 run: it expands a committed -production-source manifest, requires exact source membership, binds ordered -scenario claims to a retained secret-free JSONL transcript, validates typed -receipt/report chronology, and hashes the intended repository record path -inside the receipt. The existing v3 record remains historical and is not -silently promoted to this stronger evidence class. +The current schema-v4 receipt qualifies exact committed main +`defc24af837b91428fbee939d09cd31e9559fb4f`. Its attestation verifies a +345-source production manifest, clean exact-commit identities for all four +artifacts, twelve ordered scenario claims, and a retained secret-free JSONL +transcript containing 81 events. The receipt, transcript, and attestation have +SHA-256 digests +`58da80f7d75d414c12cf6632bd895b821ce759625e7d00ae00c16d56204b1e76`, +`616681aee38202ed922880288b730cd85f746e081f8f9d45bb2d570e48b49f8c`, and +`a48e855fdd2dcbc0cf91717dfaed22f942320c9661dd9b9e8f8f8e97f45d654b`. +This remains artifact-bound operator self-attestation, not an independently +authenticated external assessment or production Router/TLS/durable-store +exercise. The existing v3 record remains historical. The safe profile +therefore remains opt-in. Monitoring never implies remediation. On the supported Linux systemd profile, an operator may separately enroll the typed action runner: diff --git a/docs/release-control/v6/internal/AGENT_PRIVILEGE_BOUNDARY_PLAN.md b/docs/release-control/v6/internal/AGENT_PRIVILEGE_BOUNDARY_PLAN.md index d3453f181..88e3a232d 100644 --- a/docs/release-control/v6/internal/AGENT_PRIVILEGE_BOUNDARY_PLAN.md +++ b/docs/release-control/v6/internal/AGENT_PRIVILEGE_BOUNDARY_PLAN.md @@ -131,10 +131,22 @@ receipt roots; requires the receipt hashes to match that exact set; validates ordered timestamps and scenario-specific causal claims; binds every scenario to a retained secret-free JSONL transcript event; validates typed receipt kind and report chronology; and requires the intended repository record path to be -inside the hashed receipt. No schema-v4 live receipt exists yet. Accepted v4 -evidence will remain artifact-bound, self-attested systemd evidence rather than -an independently authenticated assessment. The repository still needs a fresh -exact committed release-candidate run, +inside the hashed receipt. + +A fresh Ubuntu 24.04.4/systemd 255 arm64 run at committed main +`defc24af837b91428fbee939d09cd31e9559fb4f` passed all twelve schema-v4 +scenarios in 107 seconds. The 345-source manifest matched the commit, all four +artifacts carried its clean Go VCS identity, and the receipt bound 81 retained +transcript events, including 69 raw command-output events. The receipt, +transcript, and attestation are recorded as +`internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json`, +`internal/records/secure-agent-runtime-systemd-transcript-v4-2026-08-30.jsonl`, +and +`internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json`. +This remains artifact-bound, secret-free, self-attested systemd fixture +evidence rather than an independently authenticated assessment or proof of the +production Router/TLS/durable-store credential lifecycle. The repository still +needs a fresh exact committed release-candidate run, representative Proxmox, SMART, Docker and rootless Podman telemetry/action parity, appliance profiles, and the external security review. Until those proofs are recorded, the safe profile remains opt-in and provider degradation diff --git a/docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json b/docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json new file mode 100644 index 000000000..d2b20170c --- /dev/null +++ b/docs/release-control/v6/internal/records/secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json @@ -0,0 +1,429 @@ +{ + "schema_version": 4, + "attestation_tool": "scripts/release_control/secure_runtime_attestation.py", + "attestation_tool_sha256": "f83c545a95dd6f9c46b4c676e1c28a2ae9b7a8a42ebef11b0af914d580ccecf1", + "proof_classification": "committed-main-artifact-bound-self-attested-systemd", + "qualified_commit": "defc24af837b91428fbee939d09cd31e9559fb4f", + "qualified_ref_at_run": "defc24af837b91428fbee939d09cd31e9559fb4f", + "main_ref_verified": "origin/main", + "main_ref_commit_at_attestation": "defc24af837b91428fbee939d09cd31e9559fb4f", + "qualified_commit_reachable_from_main": true, + "build_checkout": "detached-worktree", + "build_checkout_clean_except_lab_artifacts": true, + "disposable_vm_guard_receipt_claim_validated": true, + "execution_receipt_authentication": "none-secret-free-self-attestation", + "receipt": { + "record_path": "docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json", + "sha256": "58da80f7d75d414c12cf6632bd895b821ce759625e7d00ae00c16d56204b1e76", + "path_bound_inside_receipt": true + }, + "transcript": { + "record_path": "docs/release-control/v6/internal/records/secure-agent-runtime-systemd-transcript-v4-2026-08-30.jsonl", + "sha256": "616681aee38202ed922880288b730cd85f746e081f8f9d45bb2d570e48b49f8c", + "event_count": 81, + "scenario_event_count": 12, + "command_output_event_count": 69, + "format": "jsonl-v1" + }, + "source_manifest": { + "schema_version": 1, + "manifest_id": "secure-runtime-linux-v4", + "path": "scripts/release_control/secure_runtime_source_manifest_v4.json", + "sha256": "243e6c85640dec80082e3f1bdc5983912c613ad97ff9e9292b110a9f1411bb45", + "target_os": "linux", + "target_arch": "arm64", + "source_count": 345 + }, + "source_hashes_match_commit": true, + "source_hashes": { + "cmd/pulse-agent-helper/main.go": "3da1978e6e70d29cc22f070c5ada1f6a5f516f6a6643a3b27f23a4adf9ade866", + "cmd/pulse-agent-helper/providers.go": "0a179a2327cca2660f5f24ab3102a7c55ba8c87d06bbfdfd8eff2b206b9b8f88", + "cmd/pulse-agent-runner/main.go": "33707517965ae81a8b42ba86cac98e665f376a4c176572e1f558862cec82c460", + "cmd/pulse-agent/main.go": "73527ea1c0513804fcbf64fa1b924fa7f29dc5441cd98ed2c0e2f53ddd621ca8", + "cmd/pulse-agent/runtime_health.go": "64de01be0472998b5f58b49a446e22d20591802f2679f342da7fb8f2628e0c49", + "cmd/pulse-agent/service_stub.go": "3674fde8d348a121fa6ac278d235ef1634d944dccd44184fecf70cbc5ca818f0", + "cmd/pulse-agent/service_windows.go": "59ac578a598113edc7263d47cfcee5bf3806e2d6310eb49fa8f8a30a8bff8a73", + "internal/actionrunner/runner.go": "2478a333b557c7a50c49e58d0e2872bc5f702bf984b90a94a51396e538e14ef8", + "internal/actionrunner/transport.go": "6e39ea82bc0b31300e9bdbcc3fed5c1fa2348166bbaf6ce0e95ce5adb44ee5d0", + "internal/actionrunner/types.go": "4d52786233ee15d5c832a03980dd9ac460cf76d147f2aba6a8336d06d2f9aa48", + "internal/agentexec/action_preflight.go": "6a2ce9fbbe514e5b70537f6b07ecd16796416a621a0712b7ee4185cf3a5ca7ab", + "internal/agentexec/approval_grant.go": "7a30d1d4699e4a92fcda5edbb972cbb821f3e627241158ce34b970bf2e47f650", + "internal/agentexec/apt_codec.go": "51525b97672d07cb520f1cdb7ce7749c1f0d38629552e3895133a23b6f2f73f2", + "internal/agentexec/docker_lifecycle_codec.go": "c6857d25272add6acfe800ff9dee06d2a812403ca930fd4f9beb0ed9ef5757d8", + "internal/agentexec/docker_observation_codec.go": "dba73ac04672cfd7359de9ecd9ac88a02d42896ca6ee6febe6b40b395bd10cbc", + "internal/agentexec/docker_update_codec.go": "84824476c1e4a250cfebab0b709e60876705141a243af1a2854570b2692f8e16", + "internal/agentexec/export_test_helpers.go": "516445912c3ed26ea71235888a77eca88f90f05dc9d78510f3faa0c97581be41", + "internal/agentexec/policy.go": "f84ec5bf77b33202a0a51907507be93893a4d6a52a291da83616f0936fc15f28", + "internal/agentexec/proxmox_guest_lifecycle_codec.go": "e29463d4f151a3f478c8b9123f5d7e47ecaa88c1b90fc41a2c15f3e9a06fc18e", + "internal/agentexec/server.go": "b252ed4b972afc648f713ea0ab7d1feaf617b7dd4fef3a2ef87e2fb657b90d5a", + "internal/agentexec/types.go": "428a06918af94c803c720d282d5123149e70c5bf2dbdfd06613495d54d8f9b0d", + "internal/agentexec/verifier_postconditions.go": "27f68d4f05e45803f65a1dd3c7e38d41ca39ab88d9f1a574dc4739911b8391cc", + "internal/agenthelper/client.go": "1192d45f3f93a59c07d7d6189767bdc53ea57f8660e0f6558e8dc97b06f420aa", + "internal/agenthelper/container_inventory.go": "ece7672977a3b9584273a942f7ee903b926af500bf80cc0e43784952cca62dfa", + "internal/agenthelper/file_security_other.go": "0bd44450f28b3fbf9eba13bd2ef13773faec850f91518b134770268176400051", + "internal/agenthelper/file_security_unix.go": "457094f8010691b17e08c95aa7191202dff5079e8054ae75619e6c1494c6307c", + "internal/agenthelper/peercred_linux.go": "31db3ba3b565ac9fac73ae7ce94c423cc3fd25791da81c5821b9db10ced94a4d", + "internal/agenthelper/peercred_other.go": "983a2c51fefe378d2605061e17b254825554f28f3b669bed58c36dd13f1ab204", + "internal/agenthelper/protocol.go": "d7a6548f2e7f91d6827b582d5a1becf24fed6ce4c57de0e4c16b3b4fd52bda0d", + "internal/agenthelper/providers.go": "f1ed8226b817b0fa7cea71ba052808be5e4a2e1cab8298029b3cfb1e932fe856", + "internal/agenthelper/registry.go": "0d9a0be8b33e86803daee782e4bffe4e691424c692df25603f4c8ed821d363e1", + "internal/agenthelper/server.go": "70ef4f2299cf5d3347520906e62e8d7307d67624f60232c9bcbafbc6035e3ebe", + "internal/agenthelper/update_activation.go": "cdaae1da9459d5cbbd9f84dce6e6e3234bc03ed4739e78292161d2faa98d2445", + "internal/agentupdate/pending_update_persistence_other.go": "cbfee489c1050744ec440df0627ee0d6cf349efaa57387fed31728504f71a297", + "internal/agentupdate/pending_update_persistence_windows.go": "d5475a26f8446f3c45c869a71cbde79e83731edb3b4e32fd952fb94d3c454211", + "internal/agentupdate/privileged_update.go": "1e27b3d94087e85139dfbfeb86b78e6444ee9b80bd97bdbf698d0d2dadd6c624", + "internal/agentupdate/privileged_update_owner_other.go": "460fcc9619f53d79bf598bc31c4fc34c5ce5bd8fed2300d31b1c6a64144e3a29", + "internal/agentupdate/privileged_update_owner_unix.go": "875f827dd9106ab4aee70b564d264505d76e993e019ec08c687a6b3e823df896", + "internal/agentupdate/restart_unix.go": "cff57a8ee74c0d41e374c40ea8808487095988df118727d95a888f0da1a6d205", + "internal/agentupdate/restart_windows.go": "5d515fb21beb45c82ce6197b2d3154a8f0d9d8ffae86125ac1516a7d0130f3d8", + "internal/agentupdate/update.go": "ad885a99ce679fc30c5155147961f1e970fec031e25f5b69ea9814795d2f335d", + "internal/api/access_admin_handlers.go": "b5ab4a4ace0c3290a49d370eecdedf8b2de8ff50979ce67e25ab4f5589440e6c", + "internal/api/access_admin_recovery.go": "304f63c863e2c5a8104e4da097d4bfbf7e6d400fb7a153bd3ddbe4a59682053a", + "internal/api/access_control_handlers.go": "5ed98baf5f5914f5a5cf9127426ec24b4710fd49dad456844c2502b87e3b5e26", + "internal/api/access_metrics_handlers.go": "9418de69783686f5051a66936d79059b68ba373de8b249d1591292919ea6a849", + "internal/api/access_tenant_provider.go": "1dcb5fdd875e2c41e257e20d41f77c3f6dd6e7cc7787468e0c36c9cb2330b7fe", + "internal/api/action_authority.go": "0a54504b9d8a4a3beb61b9a9329225e5d684ab9eeba70a06ecd22fb0dc8f2db5", + "internal/api/action_executor.go": "be19d610a0b5614b6cacc3239ef60baa88d3c092bf56f322a7e849ba85870e39", + "internal/api/action_runner_credentials.go": "14ff066b3ad8af52c63081f070d2f92c3fdf90bb5672c0a02314c91fdf59ac1f", + "internal/api/actions.go": "0ea3967610dcf5fe00e678a97a982949247b924f3bf1732019aaa2eec7cf276e", + "internal/api/activity_audit_handlers.go": "e314a619e7cdbccad71c5ca0aff2eccd864ed05977e2bc41ed3f043387e4422f", + "internal/api/admin_bypass_mode_dev.go": "05f390ebc02e1ab63661fc3530c174328c72e47ed616feb0f28e2d853c5961db", + "internal/api/admin_bypass_mode_release.go": "8deadaaffd001e014830eb30c46c226fc42700593e74c7e6f8f4fc3d06ecc40b", + "internal/api/agent_activity_telemetry.go": "cd837430d51120c2b1a97341234f4bce44653e2040552122ce2ea6e4ee6c0003", + "internal/api/agent_capabilities.go": "21d6b1925ca458781313d77928f277db2d6225bde1f55dcf1c06dc3e6b8cf5d7", + "internal/api/agent_command_authorization.go": "4e575a2c51d9456e97c531575c243045030d252d00a6c4711362e11e4c5c427c", + "internal/api/agent_command_redaction.go": "623788c5129289c7197e220e41326cba96eef6e919393d50df7ec1824b74c137", + "internal/api/agent_events.go": "0cee3893be3a01d8de0082eec541926544989ffca5c7b2dc8bc056a02c59da19", + "internal/api/agent_exec_token_binding.go": "ac230d99f65616e9134e8942cfe36ddce9e202b63c420c64f2ad0136aaa5e791", + "internal/api/agent_fleet_doctor.go": "425e391fc251ab756e12b6c8196f24c763e4f931ad50c3076d35d2c13d31c840", + "internal/api/agent_handlers_base.go": "c2c834d051715e070febf99b26420050bae08bf4f14c952d864ea25c26a46689", + "internal/api/agent_ingest.go": "79e7e1ee3c8f741fc4e0e17b7d1db3f99ceecb38019f1ebc9176ea8034dfdc97", + "internal/api/agent_install_command_shared.go": "e49ed243070e76d143c9dd96c6b517a08a12a777d99e8c470f0a96b630ff1204", + "internal/api/agent_profiles_tools.go": "31ac7cc3711ec77810d7d6ee530896a25652a350639e60f6ed26c35ab9e05d49", + "internal/api/agent_resource_context.go": "b80065c925cb4f9e95df6f771c1d4636fefd425f9e3d7a0e19b909a72b165501", + "internal/api/agent_version_shared.go": "40e268867f6a7272890e395bc0a97ac00504c41ac81257b60c8826a2d11d5330", + "internal/api/agentbinding/policy.go": "30ead686f253b70dfdca81de13fe329ffba1641141672b6ad8253c4bf88fcf20", + "internal/api/agenttokens/install.go": "fbbb178b7a214562dc88038e1dff0db47faf1664e48d3c2b64e884f52b533174", + "internal/api/ai_chat_transport.go": "b8cd204026714ae1d395cc07f64e0248322b5d24cbb9704fd3a3dea6dbff1eb7", + "internal/api/ai_handler.go": "a9e78b9788c362ffd8561105a36d8b6c0919f56396e7b88b4d8d5268a81bc2a9", + "internal/api/ai_handlers.go": "59d7cdb5af3060f451ad61bcc23e872b6de0575fdf9af12b98bc1a903b92d036", + "internal/api/ai_hosted_runtime.go": "a746418338ceaf577fc5068e34a30819904ae7f0ea5fb1002cb0c27cea0dd6c7", + "internal/api/ai_intelligence_handlers.go": "d9dc1cb7b1aa30ff406307486052f6d5a024d26e90ef6ea2625cab03f0529bf9", + "internal/api/ai_resource_types.go": "78e6276305c4b93bc8fd091c953e58f27417ba75e798a437061d35f6b78fe267", + "internal/api/alerting/alerts.go": "cfa499011224cac15b74c26004fdf6cf6718de380a797759a67d92a2b1f7c2d7", + "internal/api/alerting/external_probe_notifications.go": "3043d331aabf45350f9902acf69c315f4e594d06df7a62b38146bde4dfd8c8dd", + "internal/api/alerting/monitor_wrappers.go": "b1bd97d6a046b30687ad404403cb005be8d61110d605e459aca565fe3f80c43d", + "internal/api/alerting/notification_queue.go": "b1c61e450220f4c5f2b93e2f5907eeaff38e463d0f4fb2a9fdbd562bdd28f995", + "internal/api/alerting/notifications.go": "57fb6046a9f7f9b7a8e4c7a9e5437715ab0a4ad85e37268ad1e09d1c85ab6560", + "internal/api/alerting_compat.go": "7a86c8f7f9a243364159b17f8aa0319b4e4fc61335e2bebc567df4a6985514b6", + "internal/api/api_token_identity.go": "adffc3d27d0359cea29ad14811c9bb82078e30b54ac8ea0e4a445ad307991e50", + "internal/api/apicontext/context.go": "5069c811226ed6654fe3caa99e31fc43e001a0599f8d2275be8773d627d5cf5a", + "internal/api/apihttp/scope.go": "22a7a0af30c656ba0ec7b3ed33d6e5e5456f48b09cf06c440104b7e2a354a7b0", + "internal/api/assistant_typed_action_planner.go": "75f11f96af5eceafce0b80850543f3c976d70b54c193eb7a579cc384a0e6e7e1", + "internal/api/attention_actions.go": "9ff650484508ab4311e824a07dcedae29353543da52f095af78fa1662142a22b", + "internal/api/attention_evidence.go": "dc6b4f2a8a406cc436a33c8c6a1db84204fdbf8702639a1a82f9f7050a399348", + "internal/api/attention_handlers.go": "449ae73617a1bcd191b66909f8b928cd0f739b5c31753d0168183707fd021ea3", + "internal/api/attention_mutations.go": "ca86d76b97d2c72d3bbaf1d4a18d58559bf6f05b8992de62b2f56eac64625210", + "internal/api/attention_receipts.go": "bc177a9d2ea1b1e3feba114329a8f066fd12a564f9c8aeb3666b4bf80c63d08e", + "internal/api/auth.go": "8f6e771181541a252ae478d65d74e97645e86ba9b905f3f81b40c11db074bff4", + "internal/api/auth_denial_signal.go": "cb93d6742af2947dfd5310cdb4df7d035c7950a284cb34e5cbc96f1b889b8d06", + "internal/api/auth_env_path.go": "7938bdc69252a494a1965bbd0ff9d53fa943ae1d4f5160f0257518881d2c5d63", + "internal/api/auth_principal_identity.go": "2dcf138e9294e357ab0abe0d66b553a620752d77fe608ff478be64fd0f13bb2d", + "internal/api/authorization.go": "49349007b4868090373ba8ae4ddca7ef245c1820d2d2fc59db232b1d213b6612", + "internal/api/availability_handlers.go": "68ead5fc26bb34f85a8509e5431d17b1e1c96cef8a32b668759c432d641f4ce3", + "internal/api/availability_history_handlers.go": "dd87da2d197fd085794afbee160dd7706ed3a470dc25d3bcb63936726f7be381", + "internal/api/bootstrap_token.go": "30a338638b388f3b7f24c4f52541683d7807e36513210f6d12969cc63180434b", + "internal/api/chartapi/payload_cache.go": "0562f08e45a44c7a1b8648918f01103e494d0fc2c6e8b3a4a2cb059040ef8189", + "internal/api/chartapi/service.go": "1018fa106466fa4148f390c1a3f7f8f34ebcf52ed2667b524fb5f09f52659af0", + "internal/api/chartapi/types.go": "19204522a2d4303436e335e8b7fe339e2aabfe9601a1508d0be4928c55148643", + "internal/api/charts_compat.go": "e96389b7b9d5543452f9aed7d0f57eb539e6806bd16da9e1e9bcbb4da5819f9e", + "internal/api/chat_service_adapter.go": "ca729ba9bd98da4770343f5ca0095bae92478f7578c461ba5cfc05e111af608f", + "internal/api/cloud_agent_install_command.go": "295de654650ecf191ac4d3c57565f6fdd45f05c3f42c086b80efe7bcb04c6d07", + "internal/api/cloud_handoff.go": "6b6477b33a04588cdd46b5f5ca0d25e6c0b41e2e937da22253778eb44a385dab", + "internal/api/cloud_handoff_handlers.go": "1c3e12ac5465f81f60816f57e0bcaed5682edd07694d9a8b63b4750c127eeb29", + "internal/api/cloud_org_admin_auth.go": "3d4361802f80d58c298b0dd57f0daba7e69f7da4e533338f4e7cee12b9f09c8e", + "internal/api/cloud_org_admin_handlers.go": "11249b2d21394e2bed4869ee39d9bade37a1363b01bc087a5235e96f656936fa", + "internal/api/collector_authority.go": "09e390d33fb952a95dd202bec57aa8a599249dbf1091b915bb7546678a68213a", + "internal/api/config_handlers_compat.go": "7fc41dc53e5301cce10986b753cf846105d0edad595cb9555dfe9a58e41be22a", + "internal/api/config_profiles.go": "f469a466b496e246ec80595daed804b55dffa72742f6972b9070119092df7e8b", + "internal/api/config_transfer_authorization.go": "525d0c0538f11a4e18f01a08bf33f1539a4ef2e26db9cada8ff6eec432ebe33e", + "internal/api/configapi/config_discovery_handlers.go": "d499ff00be90ff9a20e6a213529835c066d298484602d470843db4f925894c80", + "internal/api/configapi/config_export_import_handlers.go": "6a264cad6a31d5485813e80270bb107f28d425dded7425d7f07503b28b74f981", + "internal/api/configapi/config_handlers.go": "2a6b8819a5c6f29ae7182bb63161e25618f9ca11c2cfc53a1e41a8e1d4bc285f", + "internal/api/configapi/config_node_handlers.go": "ab955443d378cf45f884cde701a073f1bd43365e93ad207290d64b70f9429dda", + "internal/api/configapi/config_setup_handlers.go": "0e42842f29647d33c8fe74b39b83163389a2eb0969f8eb1e4b2463c337fea3b9", + "internal/api/configapi/config_system_handlers.go": "795ea62862da3f6597ec5e2a1bffb91f188f1585a18e77af50ba3075dfd027ce", + "internal/api/configapi/dependencies.go": "4f2620778bccbfe58a6010f813aaf24af0123aa79a552e3d1ce0ac7f36dab190", + "internal/api/configapi/install_command.go": "7b819a63a5a755d9affc6229092be95e88c076282632b9ea6d039b696c2427c5", + "internal/api/configapi/setup_script_artifact.go": "aca4b1151d19df5fe6da3965375373127c7a91bb6ab2a3250e24fd15ce5b41be", + "internal/api/configapi/setup_script_render.go": "32759b1860b45c781607ca6b380c3d83e8568b77ab16567cc4236ca7da4eaba0", + "internal/api/connections_aggregator.go": "9c8156d544dd2d814a6a1b25c4239372abae126ec41d382a386619b1cc84f048", + "internal/api/connections_alerts.go": "71efc73848c99d3c799639cf2f48357db2b273175a670b3168b5047de80d936b", + "internal/api/connections_grouping.go": "44f50e6bfc73c2fb844bd1dd36d7045cde3364196053a7fa8898e4d3084cb6f1", + "internal/api/connections_handlers.go": "41975dc288f66888ad84febdb5fb66fe5c6970145b15743a41f5e1de32524dec", + "internal/api/connections_probe.go": "ab7bf1e2f0482328bdee4b134519fa1d5379fc2aaf2ec9e3b390f9e6f58c1f0a", + "internal/api/connections_types.go": "af57732666b1bebabf75d3f0de5bd421b2bdbf2311ddf2b709d5ddf6d4e681fa", + "internal/api/cors_policy.go": "71001daab7062943671f8a2efec59a6dd8d20b77b6b2b8af6f7f2ce8cae20a91", + "internal/api/csrf_store.go": "5768a98f50a61ed31ea83b20e4343c1366b673221eac0d4bce601c9b0a857522", + "internal/api/demo_middleware.go": "192f58c36bc0fc2e3b18cfb914e32f7bccef85d033ee2211473564cde383cd22", + "internal/api/demo_mode_commercial.go": "88e75e594472e0149c196b81b288b5b841d8e3309be2a1664d8135a4dd12fbb3", + "internal/api/demo_mode_operations.go": "48ba980abaca84da215c6f1cb0ad7d4032a1a554c7a6f78e2af3f01ea660f359", + "internal/api/deploy_handlers.go": "af72864e89f6720eaf0f6acce2ce6d5a90c06a6dba5d14ee9f12e49ded391076", + "internal/api/deprecation_metrics.go": "f09c919e23723bc09d324f478a698cb53c56fb9da342ef25b808844a8d2b40c4", + "internal/api/diagnostics.go": "344c7f1cddd1014c35550ac8b478d77619ba9f68030e2cde695c5ae59108e3e9", + "internal/api/discovery_handlers.go": "f5c3f3f5c9a2292dcb0f708e5bde18813d3155dbcec8c3109fb6dda70452769c", + "internal/api/docker_agents.go": "5eabed7a78cd6c0bb8df0a07dc51a0cf55886919e957abfb4f1b0ce2ce44ea85", + "internal/api/docker_container_action_executor.go": "c1aef8384d2cc8ab42a0d83db81fd61411101baceefa5c2539f10dfe2ff06d2a", + "internal/api/docker_container_action_result.go": "70d6c154038416377d533cc2fd0398c3e74c22398ee38d98d35bae9df1130632", + "internal/api/docker_metadata.go": "99598ad8b05638d14fac95e91f1fa93d1e301cba5e486a559c2a0d53c9198df6", + "internal/api/docs_links.go": "467eb1dede5e6d10336683141fa12230e6106f56d4279d7b7120a7416675a4fa", + "internal/api/enterprise_extension_ai_alert_analysis.go": "a00046c2898718359dae5bb178fbc33fdedb5a39871b4769351f251fe4d2caa0", + "internal/api/enterprise_extension_ai_autofix.go": "b632ba3becebbb4f66a05b656982e00c9aa86af90b0d88bb23fe45fcd168d4fe", + "internal/api/enterprise_extension_ai_investigation.go": "109f6cc1b0fe9aa7c1ffec4e6ae3e2ff9a795dbfae9bb23fc1e77f03273ca672", + "internal/api/enterprise_extension_audit_admin.go": "46cb98ef8eb5a80a0ac2c23a7558bedff6cddc6e220885ccf0a3ef863cc2bf12", + "internal/api/enterprise_extension_rbac_admin.go": "c15b58d124246a96104801178b2f621c48822f949b022d1958e07181be1b7be0", + "internal/api/enterprise_extension_reporting_admin.go": "5175036492611300eec523f84d8f33d61133d2ef2b5b17754fbf563d2950885c", + "internal/api/enterprise_extension_sso_admin.go": "9e70e1420e9da8aea788713f9545a9284fd92d6d7d044e91c1774e2d5e4f7a09", + "internal/api/flapping_postmortem.go": "fc6b6f14833000e53f94c61bb3a8749dbe1c2ff74e1cae827cd9c36dc2ed99b4", + "internal/api/frontend_embed.go": "abb2b942f5d59347ab7c6c9d2d3a35f4c094a42704ea3686cd4810c7282a068e", + "internal/api/guest_metadata.go": "d400c8e71cae811869b2abca65be2fba8e3e4cc3a4032ce5dea7be2fad84f0b9", + "internal/api/host_apt_action_result.go": "2c46e66942ccb3cebf4204fc695e297d59c32392afbe42049664fef12adf9ba3", + "internal/api/host_metadata.go": "68d61e98bb7acaf7d148b37e2eb416247c50a317560f9b5421f8f4f42f23b8ac", + "internal/api/host_storage_cleanup_action_executor.go": "4c5a0f21c07bb26b1c8206254e680c5880062f87b9e1eb8c5d3b41745eaa4723", + "internal/api/host_update_action_executor.go": "1b667b667c94a670a5685e4d204fd716ff40e6a5029bae0addf0202104f292cc", + "internal/api/hosted_entitlement_refresh.go": "bb4c8a49f97aedcb7c0b00628f390dc81072184df6f5335c160a04c34cfcc9cb", + "internal/api/http_metrics.go": "81fc091698cf7c1b011af70776dad53db3aa735367e51f4cda8a9bbf4b2b8527", + "internal/api/identity_sso_handlers.go": "fe125dd1e6e39c3dc674fa18ce57497791b93eb1951e3346765557595545717f", + "internal/api/kubernetes_agents.go": "7091a55df3fa214c08998d5528daf2792652bd32b02a51e3e4eed626f605601f", + "internal/api/licensing_bridge.go": "6afb5aefc414af81c44f6eb29e3464e1390972c50d52b9fcb84485bc658175a6", + "internal/api/licensing_handlers.go": "5f04e6a4543cd2bb2c4d782c782b9ab2b7486bda9ba7caa3f4b3b55b36d7a760", + "internal/api/licensing_legacy_retry.go": "23774844f2d42c94e15d9b3fe94aaa4fee00550e862d20a221590cff07d7e32e", + "internal/api/log_handlers.go": "c26cca429175d265f8003da91e57bc4b401d5ce236ed4e10e05023b69aea703e", + "internal/api/log_redact.go": "c02efc8b4d808aeee5c2181f29e6071b15488ec98df18439953f0427080e294c", + "internal/api/magic_link.go": "e89d72b4971d7526b66f67767b49b92c92a312e2cba81e1d6a7aaee12223def7", + "internal/api/magic_link_handlers.go": "ef9290751de30913b80085551893844a81e4e9bc79b6b5e053714e7509fc7dcf", + "internal/api/magic_link_store_sqlite.go": "41a4b043528888c019e06b65ea2bcb03461165dc9ad22bb69801f5b59b492061", + "internal/api/maintenance_verification.go": "6e4c78b090e442ff061e61e89e54271fa630d92a79d6ed34739fd6f1f46fa5e9", + "internal/api/maintenance_verification_wiring.go": "7dcc5bf18b98b9bfbc8303cf5a671629bfbdf76e220e6db4caebabf2c7ae74a5", + "internal/api/metadata_handlers_shared.go": "08407104bcd03fe18ef75f14a5cad82914a342bacd6eb066f61f93cb6f48f5c8", + "internal/api/metadata_helpers.go": "2ae9b6dae0e33bbadc84c9ab6f3241247f7e747111a0eb7d794eab61cae0dbce", + "internal/api/metadata_provider.go": "af146dc07fe00ee30ce49e897919736fdaa3f940cdd7d565e5dbaaf408fdd0ec", + "internal/api/metrics_reporting_handlers.go": "f6ee4261576045add6478798cd12d5eb3da8a91d9940f08e2deef7041b23d008", + "internal/api/middleware.go": "ed09180803ac654ac5e416b0e5b29042632c6a32f95accea591b17b35b3222b1", + "internal/api/middleware_license.go": "4dee04c182e7d2f6a75a32f03543a387068f172dbbd622fbdf5f16085027fb46", + "internal/api/middleware_tenant.go": "53a6304b105f1175962d7a7f621176d4c4e7ff8019cdafc630f6dd096d798d13", + "internal/api/monitored_system_ledger.go": "fd1647aba616bf9e426264dbb803284580ddf7dc8598d90c513774a834532450", + "internal/api/monitored_system_usage.go": "392a08e14642fa7f71d70663b3d4b3edacfc92bc13fc71410759952d9ed3509b", + "internal/api/oidc_handlers.go": "1f3982f69f2b4c8edb72e6e95440efad26c6a21377a566991b80671cdd57b605", + "internal/api/oidc_service.go": "82f21af7da5f05a86bf76561684bd8f356f473e6ed18429f960a81b261581546", + "internal/api/onboarding_handlers.go": "4a47265c65d46a6770c7caf94ccb55602f62e579bf0ed791af26c25602f33ee5", + "internal/api/org_handlers.go": "bb47a7b69ff24f05f8cab7e304fc281837970c1cb75a405a35e54c6d2d8e96ac", + "internal/api/org_lifecycle_handlers.go": "980b4c6e7e3010fdc22e52c5d2ee7a12b6a2b0ff63331feca7398841cecec4fe", + "internal/api/patrol_action_broker.go": "bbc5ebd742c5dc4c3b5cc5b79eab746b074af847ebccc190115605e3cd258f28", + "internal/api/patrol_action_reconciliation.go": "52e339d14ee9715b85d19a93fee21b656a55d8793e9a192fa71b86726c0d48e6", + "internal/api/patrol_finding_notifications.go": "c19e09c9118a67dd64be2e22f1d8f2efa46694a161f3011e2d513d9e66e44997", + "internal/api/patrol_objectives.go": "fc47707db8f337e692b0392fe46f33ade34ffe56ea99300defd246c0c4afdbcc", + "internal/api/payments_webhook_handlers.go": "ec1e1cf664520a9c15b3a8a947dce9186cf5c6bd76cb0b9ef3d1ab3ea598535b", + "internal/api/pbs_backups.go": "788600ff602866f7d5d70408fb7c612036cc6f9d7adde51d4a8ff84635597cc2", + "internal/api/platform_connection_shared.go": "d41aed940a10758167f68752c591225fc9c4a6034e49a0741cd673d417cfd4b8", + "internal/api/platform_mock_connections.go": "34a4a8176a9abedb42aba31b771252387b73ddb9d4c880d1a7d7328e5afa8136", + "internal/api/pmg.go": "efb9ad0037c196cbcf084dab03d3c31c6ade1ca4fa1904d0dd72a5f0493ef5af", + "internal/api/profile_suggestions.go": "b1fcf4548fc28303e9266faa3eecf2e632d1510d3b5cdbf3cddc66836f1ad8e3", + "internal/api/proxmox_guest_action_executor.go": "ddb70d949e8841202618d3ac3fd3dc350b03271701c93ac3a83c139c130e587a", + "internal/api/proxmox_guest_action_observer.go": "11b0146be21c9303315864d4ac0fe7ccf46ed3b1b380ea96e8933586a6e1db8a", + "internal/api/proxmox_guest_action_result.go": "b28f45e197f55dbb7072d229dc24ce70d73ed67dd3f511407f26fd7b091e9e93", + "internal/api/public_signup_handlers.go": "0e180ee90cbc7b65df2eb7075d76fb51c3f308331d2420c8e5a9cb3cce1393d3", + "internal/api/purchase_return_redemptions.go": "e1a0a573773ebb308f6406ad6bdb932f43d48519c1ec6dfccdf0c7cbbd899ca5", + "internal/api/pve_backups.go": "3117c78dbf940bb350aabc10ea999c05942749ed82c549969aacf829536fd012", + "internal/api/rate_limit_config.go": "503bdd861cdb50c917e3d613b56298ca7b83d6b3e14da7a5c774dcf2ab4b0e95", + "internal/api/ratelimit.go": "122c8ac5378e6affdf7b75e609489688bfbee6b019c1592c61a46c68baf9f6a8", + "internal/api/ratelimit_tenant.go": "2a8bd7b5ddbc757c5ac5606c220647b2447e56efd61b1f9f378b576f251c77de", + "internal/api/recovery_handlers.go": "553698c6c21e057adcb888a2fa15c7f488c3db217f3e9136b6bed2e61142b6ef", + "internal/api/recovery_tokens.go": "c05626028329fa15024190782af89eab37592ad080d37b9ddaf630504972e6b9", + "internal/api/relay_hosted_runtime.go": "f4ed4fcf2b2d152c8cbf76e90248ad2d1bd3767761f0f92b18c345307d3a5f53", + "internal/api/relay_mobile_capability.go": "04c7566f9beb22b39e47c5d2591079573ee8244ea554c680576017eb130883d9", + "internal/api/relay_mobile_capability_generated.go": "b62a514754ceb0b6e03251d4873f7755a44bb5dc81787d4f7c8eca4fcfd6dd26", + "internal/api/release_demo_fixtures_dev.go": "f4502a13aa453a50ea967a92959cc6c9013259bdfe596e9e0b9c50da544442d5", + "internal/api/release_demo_fixtures_release.go": "a3d98bfc68d10981676406d1916c13996636c5d5996cf360db26c5d1c14f9026", + "internal/api/replication.go": "9faf8ea8879dd79b33e516acd68f567559c50f7ad5c88e7c34317af9d8b01775", + "internal/api/report_schedules.go": "bc48321b39c6c529b0fc5fa8b0add899831c8574ea0f9ff8eb24c6c7c9fcd834", + "internal/api/reporting_availability.go": "1fb0c3161a742060848da9367f90d68d8c1192ad95111c0caa5c4bd1b40afde1", + "internal/api/reporting_catalog_handlers.go": "6f4bdc73f653c47e397cb6dd9b459523c094a3bbbcf2e9c5950f7fd4a1c1d05f", + "internal/api/reporting_inventory_handlers.go": "8651612acd744975b5b1f4b469a9949ec6017266ead3a29b5b1f6578189eeb85", + "internal/api/reporting_runtime_snapshot.go": "9398bd23e031941c9a6b8ef5cf7debd6a4d8c8e1030bb00ff4e9c3d9650aceb7", + "internal/api/resourceapi/k8s_namespaces.go": "78dda0edba00d8f4d951c0b45e2e7b438c408391dd42143d43bdab3eb107ea0e", + "internal/api/resourceapi/resources.go": "58664371f69e1728963fedab9681521beef12bfbb7d6f994ea0541004346d5b1", + "internal/api/resources_compat.go": "ff90db21381ea3b27ba2199d58f963efae7885e88416b2d6f540d86c2d57fecc", + "internal/api/resources_operator_state.go": "949e74e2698fd90dd8c0f47cd5809b37e95db40b48d3d37e4d4b53489dec0c1e", + "internal/api/router.go": "f1483edbff4d267088af6b6646e58106ca0dae3c6f750727e3c74a4b14fafcd6", + "internal/api/router_helpers.go": "a61f76b9dd9e7883778253bc908d6b6dff55bdb07ca335716a952da57ae89b94", + "internal/api/router_logging.go": "80251a5c997d1a46b21ad6b4291a2aea099ab29553d69553df95efa08a7852d7", + "internal/api/router_routes_ai_relay.go": "5dc12639ef3ff8a6ce2d8b1c0be3d9e83007929c413463d0bea14f141aaa0d94", + "internal/api/router_routes_auth_security.go": "24b6371975952cf6bcc83b2fbb16994104ccee1009bc3693a71c1d9ff9e137c5", + "internal/api/router_routes_cloud.go": "7a47facf452e9f08958036cae38664e116003f2df46e0614b7e84b1cc175db91", + "internal/api/router_routes_debug.go": "92b6bd7d50b829f99f3a1613b87f83727dc099cfe9d75ed2d3d80c82984f9821", + "internal/api/router_routes_licensing.go": "ab6853ef7ad69f1c80fd57022bc8db50964c4854131d9876f25d4da0b1bb8821", + "internal/api/router_routes_monitoring.go": "ed5d592961030cebc1e3851c3ceb94d0760d8ad3c427735132d8551724352f03", + "internal/api/router_routes_registration.go": "5dd74018d9f27552a8e619816825e66cfd66d5848618efd283b4cc15f3055ae7", + "internal/api/runtime_branding.go": "c7fd8070b0fc5e679aad88955c041f423a22127ea971522eb2e2655d245c505d", + "internal/api/runtime_display.go": "974c2c0ad1b4e2d07eec99fcd850de8e0edb29eb5c1e25afb29f487d4a8e57ad", + "internal/api/runtime_inventory_sources.go": "10140e2fc660c4631641152a48fbcb1ca3da68a97a5c205051647342b07ff12a", + "internal/api/saml_handlers.go": "a7f0f4a2822f04ba467597c8c6be71bae52e1727953aa45e96c2c037966f6b0a", + "internal/api/saml_service.go": "598d2e31c2280983984eceffa587feaf1dd54c10477c5205587a1fd0e5182592", + "internal/api/security.go": "4c1e22e52749ad6fac5173f11b51644c500d9195c2b0e2ae0ede7260022b006a", + "internal/api/security_first_run_reset.go": "6b3e04f3e6094a7b0a8a19e0e21a7adba16146cbaf5c266a9997d86f84bf126c", + "internal/api/security_setup_fix.go": "26a9bb880f47caedf850f93a8660f489658b4cf5ddf54202b8f3cd06c153116c", + "internal/api/security_status_capabilities.go": "a384aca3ea0ba7809b94abf7eb5dc6448e5c1f253341b1936d0d12ec5be818eb", + "internal/api/security_tokens.go": "6448fcd31ebd447ca2e01e79dffe614adcfa313a256db8710529cba5c2eb84fb", + "internal/api/session_store.go": "fd56ebc4131d60d7de022ad16ea6240016e35796aa7386b5b4e9a89798e2312c", + "internal/api/slo.go": "c9306f43058eaa2e29768a9e8cdcac06f7bbd6f10e1f9b76dadf4bec48f6ff09", + "internal/api/sso_outbound.go": "9920a49fed5a9415e099f6e5aa01dfdc5bff97212004fa269a71f35b549e724f", + "internal/api/state_provider.go": "56ad65a422d4229079ecc1701c3170bce90e9893f2bdffcd69045967c3c4256b", + "internal/api/state_summary.go": "0da03832e2844b2b4b3d4e659a48aa540664f7ad7671251a617e46fe28ca1a77", + "internal/api/subscription_entitlements.go": "0314f3b64ea57ad3315317cedef28518f10fa54e0c7621097ef8bd5f8cb5bdf8", + "internal/api/subscription_state_handlers.go": "c7b8f94368d62a582e9e2a506c1bfbee2b220cba4a54c129b5056955949cc498", + "internal/api/subscription_state_reconciler.go": "0b66098ee91e87681273f2a9ad6d4ea027a20a99e09e42baf89df0099f94b3ff", + "internal/api/system_settings.go": "c71814a15c49c5da3af9d541d1fea492cfac9131d1a082023cb5eb9e4e0f22f4", + "internal/api/telemetry_audit_reads.go": "7cc72c7428e5bd4fed58c6c0a07a0033d07b324741e9e626fb8a7b2565c6fe98", + "internal/api/telemetry_licensed_features.go": "b11e211705a305d70aaa6977c603fe91aefa9628bd7828c05c2052ffd5f37f2e", + "internal/api/telemetry_pulse_intelligence.go": "0d2dff2276a1d8cbcb07cac9b064343b4896cbb01bc4a53f6eaf5c31e094e3ce", + "internal/api/telemetry_workload_history.go": "62ced9db02d0e04e6723df6142cd6decec9e43c991f5b44a61579e0e73987dd5", + "internal/api/truenas_app_action_provider.go": "ff6b2709ced8ea51887edfa2b1fc4770dfc76b8a5b45b7479e012945fdc5cfd3", + "internal/api/truenas_app_config_provider.go": "b34c12a919c3b9d4ddc8f660ddfa99a06450c8a6ee6269fd93db71ba03b9c3f3", + "internal/api/truenas_app_read_provider.go": "cfb4875315002fd3133b463e27ea09fca5d6dd608ef7954aa8a65ae28aad25bd", + "internal/api/truenas_handlers.go": "bf58c69707ada9d6692861f34d71c1eb2ff32cec0a150d1f331daf2edda3edd2", + "internal/api/types.go": "a5dcb11c6618bd8eaad2eec59cb46d754ddd160e5463987e7cbfa88846cc2ac0", + "internal/api/unified_agent.go": "3ee6bce5cf07652ce1072958d7f4e26183cb62bd8c2cafed3b1903181894bb00", + "internal/api/update_detection.go": "cf8567ff9f6cf3e1902d4a594c48b3fb58bdf6a53c1273e4fc6b386ba615a88f", + "internal/api/update_readiness.go": "f308b143c5c4ffe9344c9c4bbac7a84eb080a33d7a3b55229843e945f3b0c756", + "internal/api/updates.go": "a933c93ed496a401e7fcda3f527443a39e9628dbf64dcc36decfeb8b8d0d25be", + "internal/api/user_limit_enforcement.go": "a4065221e976cfae80182d88346bb9a369777fa5e9fe89d76fb3f310b04cb3a6", + "internal/api/vmware_handlers.go": "a0606e09b10bab5fc899bb42cb57a1089b5a6b1248a52bf46c2c50ce9b613751", + "internal/config/ai.go": "e773d1d1b4bede3aae9a5e1ec640f82c0992826b2bea964724f5de61c01e9ed7", + "internal/config/ai_providers.go": "994c8430b6084616b69fe702bfa4a1602d83e5c37dc60039ac1879e076714eef", + "internal/config/api_tokens.go": "f333752b6da24a85c4342332a8c656cf86d83c8cab45d49d36af9f182fb8af0b", + "internal/config/audit_read_activity.go": "b8fc44fa443112fa94e92c2a2516bd149b9aec12ac7f4b48f87752f9b4f4817a", + "internal/config/availability.go": "72cd69d132a39810940f19c6df10712a0754e6187e2c0bf6b247eb2777217900", + "internal/config/billing_state.go": "b244ad2167d87a20b63189665288008cdbdba3dc97d783add0b9e390ee690a63", + "internal/config/client_helpers.go": "8dd2444ad85af9347f5481bc9c80aa4d91e8eef64f6c966e01a53d3676834757", + "internal/config/config.go": "038725360ef71c31a22d1d79f6b370af07bd25112432b5d8b389ef57a6715818", + "internal/config/detect_root.go": "b1e09c43ae7a8b23edf0639b7c178bbfe8d6db307ce1a0d6864314673c9e4371", + "internal/config/docker_metadata.go": "f6a45c123ffeadbe3481ce5fb744c96afe6a2b2cf2f8f6f400b3913aec78c98e", + "internal/config/entitlement_billing_state.go": "aeb581849ec36021de82d3f3a74eb34bc8051464c5002cc978813a212f465034", + "internal/config/export.go": "8bd4cddcb24ff552185c1e8c7fcfd8ef445e048cb794ad45295f5616945782b7", + "internal/config/file_read_limits.go": "74b877ff7dbd5a7df01edf79fa4033e316facd6acdaf2af01116d4367d48478c", + "internal/config/guest_metadata.go": "63b71837469c85b90e8c7f1f797323b53981dc5e2c6bf414030b960d8910cd09", + "internal/config/host_continuity.go": "cb8408fa70784883a4a62ffd3d7818e16281795d580ce6b9830826a440a14921", + "internal/config/host_metadata.go": "2b3a6f22f9ebec79b69d1327f7b64468e923a1a7fe41e04e88272cd92d7548fa", + "internal/config/import_transaction.go": "c1d8b15b66bd8ec3ca44972d2ebfc45055060ddb37ca9de01f8ee0c0b517740d", + "internal/config/metadata_helpers.go": "73849782962c0d2dec8b8750b4a8ab8c094371536069758eca641a450961743f", + "internal/config/migration.go": "0d48bed7a34c505e413881ebf5cc731aae2ed8d580d0d4ac4bd39422b8817138", + "internal/config/multi_tenant.go": "1873996b514af326a15fc9205f9dee714e3d556ee66db2c8dcb028100c546b6d", + "internal/config/node_test_tally.go": "67ff9908c0c9c5689c23d872d7ed07753f3a117e54aa69de06834346316cb75f", + "internal/config/oidc.go": "11bf532dea4a9ea0f65bef5397dad28629cf79d7b2976d156e2b06589b84e49f", + "internal/config/patrol_autopilot_persistence.go": "31a02f3070cbb4730380efe8e3a4193bcc637c06409c58fc2c09e0f2128ebbb8", + "internal/config/persistence.go": "7271dab3607bfa15312c08e15d8088cfd9278297af10499be4790c56abf55e14", + "internal/config/persistence_alert_intent.go": "187f0e264add73555bfb5c42593b7dcfd841eccdf35c9ecf6eada1f6bac98b43", + "internal/config/persistence_installation_scope.go": "a146e20278fe009166015bc608d34ad411ccfa3ac2884bdc610e96c13807a75c", + "internal/config/persistence_metadata_accessors.go": "51822e30287c314cac91bf822246a3a82d978335697459938b481f7516216b98", + "internal/config/persistence_relay.go": "5874a46e7900b27934fd402533e1a6d7a7b54a45cff25b50f067926579d95c21", + "internal/config/pve_instances.go": "b740964482aaca40d2de5f7f772b79ae093f3e90e4d5fc4aed50c05cf7df20a3", + "internal/config/pve_node_identity.go": "8971e149c1e0c668c2fc8c25abc9b7e86eaf62f0fc19ec0642f4336c9ae8f1d4", + "internal/config/report_branding.go": "bf774484179ab2eadb833013d4b467c10e0af4363a1f220af0e0b2a606d9984c", + "internal/config/report_schedules.go": "1be7c9b681d21a68227d712eaee590d546c5a16bec09dbe68cab3755bb114a8b", + "internal/config/sso.go": "281fa3c5b27aa9dc2ca54c575c800f4fac7397213621540dfa394e4c825e7d30", + "internal/config/truenas.go": "5ab9f0203f8910ffc495ca4249fb36a758dfb3147ce934c514ef3dd01b41d498", + "internal/config/vmware.go": "a29600f8e229ef83577224ba943da9630db0e88203c8e1569385c33e5d485744", + "internal/config/watcher.go": "8efbdc2dcbf9fba9a04ee298bc2118a6ec20c1c4bcf07c5b8a9d2158a2a03467", + "internal/config/workload_history_activity_tally.go": "a2b246c6c1218d6b754cd1bc62ac820ccd6eddb072f14ffed8c5ed1cf9c194e0", + "internal/hostagent/action_runner_client.go": "1a6231c7fdef1c4595b2f0e6660d077374769fa45c0d429d0ea84440a9de3d57", + "internal/hostagent/action_runner_health_persistence_unix.go": "dbc8eb02bcf7129d36a7a6ca91f7abfb102cb6dfbe3ac66b52b74303a06b6887", + "internal/hostagent/action_runner_health_persistence_windows.go": "f16fa2e9f9a2f8aa675777f36582087ead3051e04cdc805ffe7e9200191e9184", + "internal/hostagent/agent.go": "500b7bdd10a2a93b598201e1716e5ad84f98a5a344c9247a5ecab71ef67323d2", + "internal/hostagent/availability.go": "eea45d12922b6859492f562dcfab4dbe248b32a92bc5abd002b5ac51422fdccf", + "internal/hostagent/ceph.go": "fee9561bc972b7bff11a9e87ad879efeac0914fb24b63eae0319f495aceb68f6", + "internal/hostagent/cluster_sensors.go": "6d6104dd2046dc6f9626d2f08f6990923bfad9b37f8028e555b590e368316e26", + "internal/hostagent/command_authority.go": "212ba17cef8beda1cd6250067513ac4ab68faa808844aacd7e5a03691f2dc9a3", + "internal/hostagent/commands.go": "03e1da3a0874645cc8dda0fd03ca307ba754ce61ecbab731e74513822b11b4f0", + "internal/hostagent/commands_deploy.go": "73ac6378c23ba4665dd98459fb941691b114be9ffd2307dbeb8c7ffb1bfd9571", + "internal/hostagent/commands_procgroup_unix.go": "1303d4227ded53ac3668b7a15092d50ff92cb3ffc581d594f9de2ee633fcd884", + "internal/hostagent/commands_procgroup_windows.go": "a2137b47610613beb3748b19eec798091081a800cf162b6f6bf1de9ebf6f40c4", + "internal/hostagent/custom_sensor_security_unix.go": "fa4175df3610c35432a60fdb5c0935800b995b6f89556b3ff00a480999eaf896", + "internal/hostagent/custom_sensor_security_windows.go": "e8ce8bec788b28c75d1734ec7746ec0f467919e05da10d5c382d31fca71877ba", + "internal/hostagent/custom_sensors.go": "301f134d27f8766bb671e4a6576d09f4894916547880585c312c227d3cc68166", + "internal/hostagent/docker_lifecycle.go": "3c6f4ebbbd3ebbe48b29deae6fdec4648e7c9617e5cde0aca432a210997df6c4", + "internal/hostagent/docker_update.go": "03324b0ca29b63609d6078bb5900cc501ab40bed9ff1c46c50992b1d07e0f539", + "internal/hostagent/enroll.go": "5d72a553cdaad74aa77942404c7f1da7537dde0920dcabba0bccc927bd8d36b9", + "internal/hostagent/libvirt.go": "0c4ee6346169e06bc26d2e006ff85cc7749da435c2f59db17adb8c4ad334d7e5", + "internal/hostagent/mdadm.go": "f2714ec89953361aec92cb09dfaaf89b25af97eb24360c5b464ba723f3261cf4", + "internal/hostagent/nvidia_smi.go": "9a4c4657604f1cf0d365b64a6ac4b289b21fc7cb7b7ef1b85888bb4381473beb", + "internal/hostagent/os_identity.go": "0ab3306f5219ec8534cd4862962297169df055e1d62012ac999c01137b374bdf", + "internal/hostagent/package_manager_lease.go": "e8879c39780a1712596cc8dd4ce25d45f28eef6c698878bb20a9cd1fd4aecbe2", + "internal/hostagent/package_updates.go": "64e0f3042ad176a874c724c91e05d7012b4c5f3b08d4df15d00ae29ea327423a", + "internal/hostagent/privilege.go": "9973b39fce82be4989ae64515d43bbfd4e3195330d64a388573bf7ebe69454dd", + "internal/hostagent/privilege_helper_client.go": "90313c33de1006895fbe1cfa001943b5ed79a02f5a7f296d529d9862de2b6cf1", + "internal/hostagent/proxmox_guest_lifecycle.go": "14d0a882859a44b3f3ff300c6f547db77e966881b742003fcb3e52db04431a89", + "internal/hostagent/proxmox_lxc_filesystems.go": "101007cd8ff35cb2f7d80140aaab0df162092ddd27d7c30bcb9972f28763d0ad", + "internal/hostagent/proxmox_lxc_filesystems_linux.go": "05424af10374cff45163a25eb8149e1bc2d3604b336b5f699a3fbaa480a2615d", + "internal/hostagent/proxmox_setup.go": "6101db7876fa63f305d27276ea8193e35435cf485f628a196048b5a9b9636391", + "internal/hostagent/smartctl.go": "83d75343e1a7496d987f128f4084f290de81db2a6cc63b463528207696dfb1d0", + "internal/hostagent/storage_cleanup.go": "6bf8a9457ae63fb4cdf375660cb85a15302aa29fdc303e1ed9a2cfc71abf3c0f", + "internal/hostagent/sysinfo.go": "768558142a26526f99edc0e55e8408e165e6f272b8bdb63d871d1659a3f08b44", + "internal/hostagent/unraid.go": "e317ae5ba0432e1cfedf853ee69288473631e5cd0300910a9c0f54f54ce32e6f", + "internal/hostagent/version.go": "fd06f8a2f9360b1e82a0687f76fe13f6b16786a2e2dca3fbc5d668717ec6b04b", + "internal/hostagent/windows_librehardwaremonitor.go": "aa9f67de011c2f23ba7ac1ffd66d566c12bfc920446b1151b8d08abe02349c9c", + "internal/hostagent/windows_storage_sensors.go": "c0b43fd797a79887c7b24f18f36185b35885d1328b207549ab7f3eae05a00789", + "internal/hostagent/xcpng.go": "24334380d87e6e0ea0559e03ffdcb5ce754f1f23340038ecf482758d6e51d28c", + "internal/hostagent/zfs.go": "75fe80d6fb8c2ecd7495589bf006800065f0c51caa3c454c3ccf828e2d905437", + "internal/operationreceipt/store.go": "6f40b4422fde09e81fc989b9b5f35066ebb3276e20bb0903a554414b69e6f6fe", + "internal/operationreceipt/types.go": "08b86678dfe55b5ec29c94ef96de15e9e3f416a9db656481f8ae833b38538dfa", + "scripts/install.sh": "63d1609fd1a3c02d07ee9034b7f177b4f00e523c97ea91b74bce2946407c5c9a", + "scripts/installtests/secure_runtime_systemd_lab_test.go": "5f6929162d8067c454b6c676481c6fd739053565c910419da65ee85e263c454a", + "scripts/release_control/secure_runtime_attestation.py": "f83c545a95dd6f9c46b4c676e1c28a2ae9b7a8a42ebef11b0af914d580ccecf1", + "scripts/release_control/secure_runtime_source_manifest_v4.json": "243e6c85640dec80082e3f1bdc5983912c613ad97ff9e9292b110a9f1411bb45" + }, + "artifact_hashes_match_receipt": true, + "artifact_hashes": { + "collector_v1": "6ebdbc3b54c9cfdfa69419024d676d239309c8b100e614bbb1c5d7d58ff244a4", + "collector_v2": "d11bc3387cfe4cd775df00ab4ec869aa53c2b9a41ff82186d67347b7a1d24b7c", + "helper": "717faf13d6931b048ecc545f2064919bde61ca891c7e53fe36989a91085d88d9", + "runner": "baf14412a7c8b74ad5ab70c3eab15a106d46ec6e6e742df38a11fc2671156a46" + }, + "artifact_build_identity": { + "collector_v1": { + "package": "github.com/rcourtman/pulse-go-rewrite/cmd/pulse-agent", + "vcs_revision": "defc24af837b91428fbee939d09cd31e9559fb4f", + "vcs_modified": "false" + }, + "collector_v2": { + "package": "github.com/rcourtman/pulse-go-rewrite/cmd/pulse-agent", + "vcs_revision": "defc24af837b91428fbee939d09cd31e9559fb4f", + "vcs_modified": "false" + }, + "helper": { + "package": "github.com/rcourtman/pulse-go-rewrite/cmd/pulse-agent-helper", + "vcs_revision": "defc24af837b91428fbee939d09cd31e9559fb4f", + "vcs_modified": "false" + }, + "runner": { + "package": "github.com/rcourtman/pulse-go-rewrite/cmd/pulse-agent-runner", + "vcs_revision": "defc24af837b91428fbee939d09cd31e9559fb4f", + "vcs_modified": "false" + } + }, + "host": { + "os": "Ubuntu 24.04.4 LTS", + "kernel": "Linux 6.8.0-117-generic #117-Ubuntu SMP PREEMPT_DYNAMIC Thu May 7 17:26:37 UTC 2026 aarch64 GNU/Linux", + "systemd": "systemd 255 (255.4-1ubuntu8.15)", + "architecture": "arm64" + }, + "scenario_count": 12, + "all_scenarios_passed": true, + "test_elapsed_seconds": 107.0, + "default_changed": false, + "residual_proof": [ + "exact-release-candidate", + "representative-provider-and-appliance", + "external-security-review" + ] +} diff --git a/docs/release-control/v6/internal/records/secure-agent-runtime-qualification-foundation-2026-08-30.md b/docs/release-control/v6/internal/records/secure-agent-runtime-qualification-foundation-2026-08-30.md index af628e426..35c31bdac 100644 --- a/docs/release-control/v6/internal/records/secure-agent-runtime-qualification-foundation-2026-08-30.md +++ b/docs/release-control/v6/internal/records/secure-agent-runtime-qualification-foundation-2026-08-30.md @@ -95,7 +95,7 @@ scenario outcomes. It proves neither a successful action-runner host mutation nor the post-audit credential, rollback, update-artifact, and runner-unit hardening. It is retained as historical, hash-bound self-attested evidence. -## Current schema-v3 committed-main evidence +## Historical schema-v3 committed-main evidence A newly created disposable arm64 Colima profile ran Ubuntu 24.04.4, kernel 6.8.0-117, and systemd 255 from a detached clean checkout at committed main @@ -121,11 +121,10 @@ session invalidation remain established by the focused API regressions rather than by this in-process fixture. The receipt remains operator-produced, unauthenticated, artifact-bound self-attestation rather than independent proof. -## Post-audit schema-v4 acceptance floor +## Current schema-v4 committed-main evidence Schema v3 remains immutable historical evidence, but it is no longer accepted -by the current attester as qualification of a newer tree. A future run must use -schema v4. The committed +by the current attester as qualification of a newer tree. The committed `scripts/release_control/secure_runtime_source_manifest_v4.json` expands the production collector, helper, runner, host-agent provider, API admission, configuration, update, and receipt roots, and the receipt must hash exactly @@ -134,17 +133,40 @@ times, typed causal claims, and an exact reference to a retained secret-free JSONL transcript event. The receipt also binds its intended repository path, the transcript path and digest, the typed action receipt kind, report count and report chronology. The attestation preserves those bindings alongside the -artifact build identities. No v4 live receipt or attestation is recorded here; -this is the acceptance contract for the next exact-commit or exact-RC run, not -a retroactive upgrade of the v3 evidence. +artifact build identities. + +A newly created disposable arm64 Colima profile ran Ubuntu 24.04.4, kernel +6.8.0-117, and systemd 255 from a detached clean checkout at committed main +`defc24af837b91428fbee939d09cd31e9559fb4f`. All four exercised commands carry +that exact clean Go VCS revision. The guarded lab passed all twelve scenarios +in 107 seconds. Its 345-source manifest matched the qualified commit, and its +retained JSONL transcript contains 81 ordered events: twelve scenario events +and 69 raw command-output events. + +The secret-free schema-v4 receipt is +`secure-agent-runtime-systemd-receipt-v4-2026-08-30.json` with SHA-256 +`58da80f7d75d414c12cf6632bd895b821ce759625e7d00ae00c16d56204b1e76`. Its +bound transcript is +`secure-agent-runtime-systemd-transcript-v4-2026-08-30.jsonl` with SHA-256 +`616681aee38202ed922880288b730cd85f746e081f8f9d45bb2d570e48b49f8c`. The +separate `secure-agent-runtime-committed-main-attestation-v4-2026-08-30.json` +has SHA-256 +`a48e855fdd2dcbc0cf91717dfaed22f942320c9661dd9b9e8f8f8e97f45d654b` and +verifies current-main identity and ancestry, exact source-manifest membership +and hashes, all artifact hashes and clean Go build identities, ordered typed +scenario claims, receipt/report chronology, and the receipt's intended record +path. This is new evidence for the exact qualified commit; it does not +retroactively upgrade schema v3. ## Proof classification and residuals -Focused regressions cover current code-level semantics. The schema-v3 guarded -systemd evidence covers only its historical qualified commit and the explicitly -exercised subset above. Neither is a substitute for exact release-candidate -reproduction, representative provider/appliance qualification, or external -review. The canonical support and residual matrix is published in +Focused regressions cover current code-level semantics. The schema-v4 guarded +systemd evidence covers only its exact qualified commit and explicitly +exercised fixture paths. It does not prove helper-backed update activation, +watchdog or interrupted-recovery behavior, nor the production Router over TLS +with durable credential persistence. It is not a substitute for exact +release-candidate reproduction, representative provider/appliance +qualification, or external review. The canonical support and residual matrix is published in `docs/AGENT_SECURITY.md`; unqualified rows remain explicit blockers rather than being inferred from the generic Linux result. diff --git a/docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json b/docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json new file mode 100644 index 000000000..3fe604236 --- /dev/null +++ b/docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json @@ -0,0 +1,664 @@ +{ + "schema_version": 4, + "record_path": "docs/release-control/v6/internal/records/secure-agent-runtime-systemd-receipt-v4-2026-08-30.json", + "started_at": "2026-08-30T18:10:18.105761661Z", + "completed_at": "2026-08-30T18:12:04.297039052Z", + "source_manifest": { + "schema_version": 1, + "manifest_id": "secure-runtime-linux-v4", + "path": "scripts/release_control/secure_runtime_source_manifest_v4.json", + "sha256": "243e6c85640dec80082e3f1bdc5983912c613ad97ff9e9292b110a9f1411bb45", + "target_os": "linux", + "target_arch": "arm64" + }, + "source_hashes": { + "cmd/pulse-agent-helper/main.go": "3da1978e6e70d29cc22f070c5ada1f6a5f516f6a6643a3b27f23a4adf9ade866", + "cmd/pulse-agent-helper/providers.go": "0a179a2327cca2660f5f24ab3102a7c55ba8c87d06bbfdfd8eff2b206b9b8f88", + "cmd/pulse-agent-runner/main.go": "33707517965ae81a8b42ba86cac98e665f376a4c176572e1f558862cec82c460", + "cmd/pulse-agent/main.go": "73527ea1c0513804fcbf64fa1b924fa7f29dc5441cd98ed2c0e2f53ddd621ca8", + "cmd/pulse-agent/runtime_health.go": "64de01be0472998b5f58b49a446e22d20591802f2679f342da7fb8f2628e0c49", + "cmd/pulse-agent/service_stub.go": "3674fde8d348a121fa6ac278d235ef1634d944dccd44184fecf70cbc5ca818f0", + "cmd/pulse-agent/service_windows.go": "59ac578a598113edc7263d47cfcee5bf3806e2d6310eb49fa8f8a30a8bff8a73", + "internal/actionrunner/runner.go": "2478a333b557c7a50c49e58d0e2872bc5f702bf984b90a94a51396e538e14ef8", + "internal/actionrunner/transport.go": "6e39ea82bc0b31300e9bdbcc3fed5c1fa2348166bbaf6ce0e95ce5adb44ee5d0", + "internal/actionrunner/types.go": "4d52786233ee15d5c832a03980dd9ac460cf76d147f2aba6a8336d06d2f9aa48", + "internal/agentexec/action_preflight.go": "6a2ce9fbbe514e5b70537f6b07ecd16796416a621a0712b7ee4185cf3a5ca7ab", + "internal/agentexec/approval_grant.go": "7a30d1d4699e4a92fcda5edbb972cbb821f3e627241158ce34b970bf2e47f650", + "internal/agentexec/apt_codec.go": "51525b97672d07cb520f1cdb7ce7749c1f0d38629552e3895133a23b6f2f73f2", + "internal/agentexec/docker_lifecycle_codec.go": "c6857d25272add6acfe800ff9dee06d2a812403ca930fd4f9beb0ed9ef5757d8", + "internal/agentexec/docker_observation_codec.go": "dba73ac04672cfd7359de9ecd9ac88a02d42896ca6ee6febe6b40b395bd10cbc", + "internal/agentexec/docker_update_codec.go": "84824476c1e4a250cfebab0b709e60876705141a243af1a2854570b2692f8e16", + "internal/agentexec/export_test_helpers.go": "516445912c3ed26ea71235888a77eca88f90f05dc9d78510f3faa0c97581be41", + "internal/agentexec/policy.go": "f84ec5bf77b33202a0a51907507be93893a4d6a52a291da83616f0936fc15f28", + "internal/agentexec/proxmox_guest_lifecycle_codec.go": "e29463d4f151a3f478c8b9123f5d7e47ecaa88c1b90fc41a2c15f3e9a06fc18e", + "internal/agentexec/server.go": "b252ed4b972afc648f713ea0ab7d1feaf617b7dd4fef3a2ef87e2fb657b90d5a", + "internal/agentexec/types.go": "428a06918af94c803c720d282d5123149e70c5bf2dbdfd06613495d54d8f9b0d", + "internal/agentexec/verifier_postconditions.go": "27f68d4f05e45803f65a1dd3c7e38d41ca39ab88d9f1a574dc4739911b8391cc", + "internal/agenthelper/client.go": "1192d45f3f93a59c07d7d6189767bdc53ea57f8660e0f6558e8dc97b06f420aa", + "internal/agenthelper/container_inventory.go": "ece7672977a3b9584273a942f7ee903b926af500bf80cc0e43784952cca62dfa", + "internal/agenthelper/file_security_other.go": "0bd44450f28b3fbf9eba13bd2ef13773faec850f91518b134770268176400051", + "internal/agenthelper/file_security_unix.go": "457094f8010691b17e08c95aa7191202dff5079e8054ae75619e6c1494c6307c", + "internal/agenthelper/peercred_linux.go": "31db3ba3b565ac9fac73ae7ce94c423cc3fd25791da81c5821b9db10ced94a4d", + "internal/agenthelper/peercred_other.go": "983a2c51fefe378d2605061e17b254825554f28f3b669bed58c36dd13f1ab204", + "internal/agenthelper/protocol.go": "d7a6548f2e7f91d6827b582d5a1becf24fed6ce4c57de0e4c16b3b4fd52bda0d", + "internal/agenthelper/providers.go": "f1ed8226b817b0fa7cea71ba052808be5e4a2e1cab8298029b3cfb1e932fe856", + "internal/agenthelper/registry.go": "0d9a0be8b33e86803daee782e4bffe4e691424c692df25603f4c8ed821d363e1", + "internal/agenthelper/server.go": "70ef4f2299cf5d3347520906e62e8d7307d67624f60232c9bcbafbc6035e3ebe", + "internal/agenthelper/update_activation.go": "cdaae1da9459d5cbbd9f84dce6e6e3234bc03ed4739e78292161d2faa98d2445", + "internal/agentupdate/pending_update_persistence_other.go": "cbfee489c1050744ec440df0627ee0d6cf349efaa57387fed31728504f71a297", + "internal/agentupdate/pending_update_persistence_windows.go": "d5475a26f8446f3c45c869a71cbde79e83731edb3b4e32fd952fb94d3c454211", + "internal/agentupdate/privileged_update.go": "1e27b3d94087e85139dfbfeb86b78e6444ee9b80bd97bdbf698d0d2dadd6c624", + "internal/agentupdate/privileged_update_owner_other.go": "460fcc9619f53d79bf598bc31c4fc34c5ce5bd8fed2300d31b1c6a64144e3a29", + "internal/agentupdate/privileged_update_owner_unix.go": "875f827dd9106ab4aee70b564d264505d76e993e019ec08c687a6b3e823df896", + "internal/agentupdate/restart_unix.go": "cff57a8ee74c0d41e374c40ea8808487095988df118727d95a888f0da1a6d205", + "internal/agentupdate/restart_windows.go": "5d515fb21beb45c82ce6197b2d3154a8f0d9d8ffae86125ac1516a7d0130f3d8", + "internal/agentupdate/update.go": "ad885a99ce679fc30c5155147961f1e970fec031e25f5b69ea9814795d2f335d", + "internal/api/access_admin_handlers.go": "b5ab4a4ace0c3290a49d370eecdedf8b2de8ff50979ce67e25ab4f5589440e6c", + "internal/api/access_admin_recovery.go": "304f63c863e2c5a8104e4da097d4bfbf7e6d400fb7a153bd3ddbe4a59682053a", + "internal/api/access_control_handlers.go": "5ed98baf5f5914f5a5cf9127426ec24b4710fd49dad456844c2502b87e3b5e26", + "internal/api/access_metrics_handlers.go": "9418de69783686f5051a66936d79059b68ba373de8b249d1591292919ea6a849", + "internal/api/access_tenant_provider.go": "1dcb5fdd875e2c41e257e20d41f77c3f6dd6e7cc7787468e0c36c9cb2330b7fe", + "internal/api/action_authority.go": "0a54504b9d8a4a3beb61b9a9329225e5d684ab9eeba70a06ecd22fb0dc8f2db5", + "internal/api/action_executor.go": "be19d610a0b5614b6cacc3239ef60baa88d3c092bf56f322a7e849ba85870e39", + "internal/api/action_runner_credentials.go": "14ff066b3ad8af52c63081f070d2f92c3fdf90bb5672c0a02314c91fdf59ac1f", + "internal/api/actions.go": "0ea3967610dcf5fe00e678a97a982949247b924f3bf1732019aaa2eec7cf276e", + "internal/api/activity_audit_handlers.go": "e314a619e7cdbccad71c5ca0aff2eccd864ed05977e2bc41ed3f043387e4422f", + "internal/api/admin_bypass_mode_dev.go": "05f390ebc02e1ab63661fc3530c174328c72e47ed616feb0f28e2d853c5961db", + "internal/api/admin_bypass_mode_release.go": "8deadaaffd001e014830eb30c46c226fc42700593e74c7e6f8f4fc3d06ecc40b", + "internal/api/agent_activity_telemetry.go": "cd837430d51120c2b1a97341234f4bce44653e2040552122ce2ea6e4ee6c0003", + "internal/api/agent_capabilities.go": "21d6b1925ca458781313d77928f277db2d6225bde1f55dcf1c06dc3e6b8cf5d7", + "internal/api/agent_command_authorization.go": "4e575a2c51d9456e97c531575c243045030d252d00a6c4711362e11e4c5c427c", + "internal/api/agent_command_redaction.go": "623788c5129289c7197e220e41326cba96eef6e919393d50df7ec1824b74c137", + "internal/api/agent_events.go": "0cee3893be3a01d8de0082eec541926544989ffca5c7b2dc8bc056a02c59da19", + "internal/api/agent_exec_token_binding.go": "ac230d99f65616e9134e8942cfe36ddce9e202b63c420c64f2ad0136aaa5e791", + "internal/api/agent_fleet_doctor.go": "425e391fc251ab756e12b6c8196f24c763e4f931ad50c3076d35d2c13d31c840", + "internal/api/agent_handlers_base.go": "c2c834d051715e070febf99b26420050bae08bf4f14c952d864ea25c26a46689", + "internal/api/agent_ingest.go": "79e7e1ee3c8f741fc4e0e17b7d1db3f99ceecb38019f1ebc9176ea8034dfdc97", + "internal/api/agent_install_command_shared.go": "e49ed243070e76d143c9dd96c6b517a08a12a777d99e8c470f0a96b630ff1204", + "internal/api/agent_profiles_tools.go": "31ac7cc3711ec77810d7d6ee530896a25652a350639e60f6ed26c35ab9e05d49", + "internal/api/agent_resource_context.go": "b80065c925cb4f9e95df6f771c1d4636fefd425f9e3d7a0e19b909a72b165501", + "internal/api/agent_version_shared.go": "40e268867f6a7272890e395bc0a97ac00504c41ac81257b60c8826a2d11d5330", + "internal/api/agentbinding/policy.go": "30ead686f253b70dfdca81de13fe329ffba1641141672b6ad8253c4bf88fcf20", + "internal/api/agenttokens/install.go": "fbbb178b7a214562dc88038e1dff0db47faf1664e48d3c2b64e884f52b533174", + "internal/api/ai_chat_transport.go": "b8cd204026714ae1d395cc07f64e0248322b5d24cbb9704fd3a3dea6dbff1eb7", + "internal/api/ai_handler.go": "a9e78b9788c362ffd8561105a36d8b6c0919f56396e7b88b4d8d5268a81bc2a9", + "internal/api/ai_handlers.go": "59d7cdb5af3060f451ad61bcc23e872b6de0575fdf9af12b98bc1a903b92d036", + "internal/api/ai_hosted_runtime.go": "a746418338ceaf577fc5068e34a30819904ae7f0ea5fb1002cb0c27cea0dd6c7", + "internal/api/ai_intelligence_handlers.go": "d9dc1cb7b1aa30ff406307486052f6d5a024d26e90ef6ea2625cab03f0529bf9", + "internal/api/ai_resource_types.go": "78e6276305c4b93bc8fd091c953e58f27417ba75e798a437061d35f6b78fe267", + "internal/api/alerting/alerts.go": "cfa499011224cac15b74c26004fdf6cf6718de380a797759a67d92a2b1f7c2d7", + "internal/api/alerting/external_probe_notifications.go": "3043d331aabf45350f9902acf69c315f4e594d06df7a62b38146bde4dfd8c8dd", + "internal/api/alerting/monitor_wrappers.go": "b1bd97d6a046b30687ad404403cb005be8d61110d605e459aca565fe3f80c43d", + "internal/api/alerting/notification_queue.go": "b1c61e450220f4c5f2b93e2f5907eeaff38e463d0f4fb2a9fdbd562bdd28f995", + "internal/api/alerting/notifications.go": "57fb6046a9f7f9b7a8e4c7a9e5437715ab0a4ad85e37268ad1e09d1c85ab6560", + "internal/api/alerting_compat.go": "7a86c8f7f9a243364159b17f8aa0319b4e4fc61335e2bebc567df4a6985514b6", + "internal/api/api_token_identity.go": "adffc3d27d0359cea29ad14811c9bb82078e30b54ac8ea0e4a445ad307991e50", + "internal/api/apicontext/context.go": "5069c811226ed6654fe3caa99e31fc43e001a0599f8d2275be8773d627d5cf5a", + "internal/api/apihttp/scope.go": "22a7a0af30c656ba0ec7b3ed33d6e5e5456f48b09cf06c440104b7e2a354a7b0", + "internal/api/assistant_typed_action_planner.go": "75f11f96af5eceafce0b80850543f3c976d70b54c193eb7a579cc384a0e6e7e1", + "internal/api/attention_actions.go": "9ff650484508ab4311e824a07dcedae29353543da52f095af78fa1662142a22b", + "internal/api/attention_evidence.go": "dc6b4f2a8a406cc436a33c8c6a1db84204fdbf8702639a1a82f9f7050a399348", + "internal/api/attention_handlers.go": "449ae73617a1bcd191b66909f8b928cd0f739b5c31753d0168183707fd021ea3", + "internal/api/attention_mutations.go": "ca86d76b97d2c72d3bbaf1d4a18d58559bf6f05b8992de62b2f56eac64625210", + "internal/api/attention_receipts.go": "bc177a9d2ea1b1e3feba114329a8f066fd12a564f9c8aeb3666b4bf80c63d08e", + "internal/api/auth.go": "8f6e771181541a252ae478d65d74e97645e86ba9b905f3f81b40c11db074bff4", + "internal/api/auth_denial_signal.go": "cb93d6742af2947dfd5310cdb4df7d035c7950a284cb34e5cbc96f1b889b8d06", + "internal/api/auth_env_path.go": "7938bdc69252a494a1965bbd0ff9d53fa943ae1d4f5160f0257518881d2c5d63", + "internal/api/auth_principal_identity.go": "2dcf138e9294e357ab0abe0d66b553a620752d77fe608ff478be64fd0f13bb2d", + "internal/api/authorization.go": "49349007b4868090373ba8ae4ddca7ef245c1820d2d2fc59db232b1d213b6612", + "internal/api/availability_handlers.go": "68ead5fc26bb34f85a8509e5431d17b1e1c96cef8a32b668759c432d641f4ce3", + "internal/api/availability_history_handlers.go": "dd87da2d197fd085794afbee160dd7706ed3a470dc25d3bcb63936726f7be381", + "internal/api/bootstrap_token.go": "30a338638b388f3b7f24c4f52541683d7807e36513210f6d12969cc63180434b", + "internal/api/chartapi/payload_cache.go": "0562f08e45a44c7a1b8648918f01103e494d0fc2c6e8b3a4a2cb059040ef8189", + "internal/api/chartapi/service.go": "1018fa106466fa4148f390c1a3f7f8f34ebcf52ed2667b524fb5f09f52659af0", + "internal/api/chartapi/types.go": "19204522a2d4303436e335e8b7fe339e2aabfe9601a1508d0be4928c55148643", + "internal/api/charts_compat.go": "e96389b7b9d5543452f9aed7d0f57eb539e6806bd16da9e1e9bcbb4da5819f9e", + "internal/api/chat_service_adapter.go": "ca729ba9bd98da4770343f5ca0095bae92478f7578c461ba5cfc05e111af608f", + "internal/api/cloud_agent_install_command.go": "295de654650ecf191ac4d3c57565f6fdd45f05c3f42c086b80efe7bcb04c6d07", + "internal/api/cloud_handoff.go": "6b6477b33a04588cdd46b5f5ca0d25e6c0b41e2e937da22253778eb44a385dab", + "internal/api/cloud_handoff_handlers.go": "1c3e12ac5465f81f60816f57e0bcaed5682edd07694d9a8b63b4750c127eeb29", + "internal/api/cloud_org_admin_auth.go": "3d4361802f80d58c298b0dd57f0daba7e69f7da4e533338f4e7cee12b9f09c8e", + "internal/api/cloud_org_admin_handlers.go": "11249b2d21394e2bed4869ee39d9bade37a1363b01bc087a5235e96f656936fa", + "internal/api/collector_authority.go": "09e390d33fb952a95dd202bec57aa8a599249dbf1091b915bb7546678a68213a", + "internal/api/config_handlers_compat.go": "7fc41dc53e5301cce10986b753cf846105d0edad595cb9555dfe9a58e41be22a", + "internal/api/config_profiles.go": "f469a466b496e246ec80595daed804b55dffa72742f6972b9070119092df7e8b", + "internal/api/config_transfer_authorization.go": "525d0c0538f11a4e18f01a08bf33f1539a4ef2e26db9cada8ff6eec432ebe33e", + "internal/api/configapi/config_discovery_handlers.go": "d499ff00be90ff9a20e6a213529835c066d298484602d470843db4f925894c80", + "internal/api/configapi/config_export_import_handlers.go": "6a264cad6a31d5485813e80270bb107f28d425dded7425d7f07503b28b74f981", + "internal/api/configapi/config_handlers.go": "2a6b8819a5c6f29ae7182bb63161e25618f9ca11c2cfc53a1e41a8e1d4bc285f", + "internal/api/configapi/config_node_handlers.go": "ab955443d378cf45f884cde701a073f1bd43365e93ad207290d64b70f9429dda", + "internal/api/configapi/config_setup_handlers.go": "0e42842f29647d33c8fe74b39b83163389a2eb0969f8eb1e4b2463c337fea3b9", + "internal/api/configapi/config_system_handlers.go": "795ea62862da3f6597ec5e2a1bffb91f188f1585a18e77af50ba3075dfd027ce", + "internal/api/configapi/dependencies.go": "4f2620778bccbfe58a6010f813aaf24af0123aa79a552e3d1ce0ac7f36dab190", + "internal/api/configapi/install_command.go": "7b819a63a5a755d9affc6229092be95e88c076282632b9ea6d039b696c2427c5", + "internal/api/configapi/setup_script_artifact.go": "aca4b1151d19df5fe6da3965375373127c7a91bb6ab2a3250e24fd15ce5b41be", + "internal/api/configapi/setup_script_render.go": "32759b1860b45c781607ca6b380c3d83e8568b77ab16567cc4236ca7da4eaba0", + "internal/api/connections_aggregator.go": "9c8156d544dd2d814a6a1b25c4239372abae126ec41d382a386619b1cc84f048", + "internal/api/connections_alerts.go": "71efc73848c99d3c799639cf2f48357db2b273175a670b3168b5047de80d936b", + "internal/api/connections_grouping.go": "44f50e6bfc73c2fb844bd1dd36d7045cde3364196053a7fa8898e4d3084cb6f1", + "internal/api/connections_handlers.go": "41975dc288f66888ad84febdb5fb66fe5c6970145b15743a41f5e1de32524dec", + "internal/api/connections_probe.go": "ab7bf1e2f0482328bdee4b134519fa1d5379fc2aaf2ec9e3b390f9e6f58c1f0a", + "internal/api/connections_types.go": "af57732666b1bebabf75d3f0de5bd421b2bdbf2311ddf2b709d5ddf6d4e681fa", + "internal/api/cors_policy.go": "71001daab7062943671f8a2efec59a6dd8d20b77b6b2b8af6f7f2ce8cae20a91", + "internal/api/csrf_store.go": "5768a98f50a61ed31ea83b20e4343c1366b673221eac0d4bce601c9b0a857522", + "internal/api/demo_middleware.go": "192f58c36bc0fc2e3b18cfb914e32f7bccef85d033ee2211473564cde383cd22", + "internal/api/demo_mode_commercial.go": "88e75e594472e0149c196b81b288b5b841d8e3309be2a1664d8135a4dd12fbb3", + "internal/api/demo_mode_operations.go": "48ba980abaca84da215c6f1cb0ad7d4032a1a554c7a6f78e2af3f01ea660f359", + "internal/api/deploy_handlers.go": "af72864e89f6720eaf0f6acce2ce6d5a90c06a6dba5d14ee9f12e49ded391076", + "internal/api/deprecation_metrics.go": "f09c919e23723bc09d324f478a698cb53c56fb9da342ef25b808844a8d2b40c4", + "internal/api/diagnostics.go": "344c7f1cddd1014c35550ac8b478d77619ba9f68030e2cde695c5ae59108e3e9", + "internal/api/discovery_handlers.go": "f5c3f3f5c9a2292dcb0f708e5bde18813d3155dbcec8c3109fb6dda70452769c", + "internal/api/docker_agents.go": "5eabed7a78cd6c0bb8df0a07dc51a0cf55886919e957abfb4f1b0ce2ce44ea85", + "internal/api/docker_container_action_executor.go": "c1aef8384d2cc8ab42a0d83db81fd61411101baceefa5c2539f10dfe2ff06d2a", + "internal/api/docker_container_action_result.go": "70d6c154038416377d533cc2fd0398c3e74c22398ee38d98d35bae9df1130632", + "internal/api/docker_metadata.go": "99598ad8b05638d14fac95e91f1fa93d1e301cba5e486a559c2a0d53c9198df6", + "internal/api/docs_links.go": "467eb1dede5e6d10336683141fa12230e6106f56d4279d7b7120a7416675a4fa", + "internal/api/enterprise_extension_ai_alert_analysis.go": "a00046c2898718359dae5bb178fbc33fdedb5a39871b4769351f251fe4d2caa0", + "internal/api/enterprise_extension_ai_autofix.go": "b632ba3becebbb4f66a05b656982e00c9aa86af90b0d88bb23fe45fcd168d4fe", + "internal/api/enterprise_extension_ai_investigation.go": "109f6cc1b0fe9aa7c1ffec4e6ae3e2ff9a795dbfae9bb23fc1e77f03273ca672", + "internal/api/enterprise_extension_audit_admin.go": "46cb98ef8eb5a80a0ac2c23a7558bedff6cddc6e220885ccf0a3ef863cc2bf12", + "internal/api/enterprise_extension_rbac_admin.go": "c15b58d124246a96104801178b2f621c48822f949b022d1958e07181be1b7be0", + "internal/api/enterprise_extension_reporting_admin.go": "5175036492611300eec523f84d8f33d61133d2ef2b5b17754fbf563d2950885c", + "internal/api/enterprise_extension_sso_admin.go": "9e70e1420e9da8aea788713f9545a9284fd92d6d7d044e91c1774e2d5e4f7a09", + "internal/api/flapping_postmortem.go": "fc6b6f14833000e53f94c61bb3a8749dbe1c2ff74e1cae827cd9c36dc2ed99b4", + "internal/api/frontend_embed.go": "abb2b942f5d59347ab7c6c9d2d3a35f4c094a42704ea3686cd4810c7282a068e", + "internal/api/guest_metadata.go": "d400c8e71cae811869b2abca65be2fba8e3e4cc3a4032ce5dea7be2fad84f0b9", + "internal/api/host_apt_action_result.go": "2c46e66942ccb3cebf4204fc695e297d59c32392afbe42049664fef12adf9ba3", + "internal/api/host_metadata.go": "68d61e98bb7acaf7d148b37e2eb416247c50a317560f9b5421f8f4f42f23b8ac", + "internal/api/host_storage_cleanup_action_executor.go": "4c5a0f21c07bb26b1c8206254e680c5880062f87b9e1eb8c5d3b41745eaa4723", + "internal/api/host_update_action_executor.go": "1b667b667c94a670a5685e4d204fd716ff40e6a5029bae0addf0202104f292cc", + "internal/api/hosted_entitlement_refresh.go": "bb4c8a49f97aedcb7c0b00628f390dc81072184df6f5335c160a04c34cfcc9cb", + "internal/api/http_metrics.go": "81fc091698cf7c1b011af70776dad53db3aa735367e51f4cda8a9bbf4b2b8527", + "internal/api/identity_sso_handlers.go": "fe125dd1e6e39c3dc674fa18ce57497791b93eb1951e3346765557595545717f", + "internal/api/kubernetes_agents.go": "7091a55df3fa214c08998d5528daf2792652bd32b02a51e3e4eed626f605601f", + "internal/api/licensing_bridge.go": "6afb5aefc414af81c44f6eb29e3464e1390972c50d52b9fcb84485bc658175a6", + "internal/api/licensing_handlers.go": "5f04e6a4543cd2bb2c4d782c782b9ab2b7486bda9ba7caa3f4b3b55b36d7a760", + "internal/api/licensing_legacy_retry.go": "23774844f2d42c94e15d9b3fe94aaa4fee00550e862d20a221590cff07d7e32e", + "internal/api/log_handlers.go": "c26cca429175d265f8003da91e57bc4b401d5ce236ed4e10e05023b69aea703e", + "internal/api/log_redact.go": "c02efc8b4d808aeee5c2181f29e6071b15488ec98df18439953f0427080e294c", + "internal/api/magic_link.go": "e89d72b4971d7526b66f67767b49b92c92a312e2cba81e1d6a7aaee12223def7", + "internal/api/magic_link_handlers.go": "ef9290751de30913b80085551893844a81e4e9bc79b6b5e053714e7509fc7dcf", + "internal/api/magic_link_store_sqlite.go": "41a4b043528888c019e06b65ea2bcb03461165dc9ad22bb69801f5b59b492061", + "internal/api/maintenance_verification.go": "6e4c78b090e442ff061e61e89e54271fa630d92a79d6ed34739fd6f1f46fa5e9", + "internal/api/maintenance_verification_wiring.go": "7dcc5bf18b98b9bfbc8303cf5a671629bfbdf76e220e6db4caebabf2c7ae74a5", + "internal/api/metadata_handlers_shared.go": "08407104bcd03fe18ef75f14a5cad82914a342bacd6eb066f61f93cb6f48f5c8", + "internal/api/metadata_helpers.go": "2ae9b6dae0e33bbadc84c9ab6f3241247f7e747111a0eb7d794eab61cae0dbce", + "internal/api/metadata_provider.go": "af146dc07fe00ee30ce49e897919736fdaa3f940cdd7d565e5dbaaf408fdd0ec", + "internal/api/metrics_reporting_handlers.go": "f6ee4261576045add6478798cd12d5eb3da8a91d9940f08e2deef7041b23d008", + "internal/api/middleware.go": "ed09180803ac654ac5e416b0e5b29042632c6a32f95accea591b17b35b3222b1", + "internal/api/middleware_license.go": "4dee04c182e7d2f6a75a32f03543a387068f172dbbd622fbdf5f16085027fb46", + "internal/api/middleware_tenant.go": "53a6304b105f1175962d7a7f621176d4c4e7ff8019cdafc630f6dd096d798d13", + "internal/api/monitored_system_ledger.go": "fd1647aba616bf9e426264dbb803284580ddf7dc8598d90c513774a834532450", + "internal/api/monitored_system_usage.go": "392a08e14642fa7f71d70663b3d4b3edacfc92bc13fc71410759952d9ed3509b", + "internal/api/oidc_handlers.go": "1f3982f69f2b4c8edb72e6e95440efad26c6a21377a566991b80671cdd57b605", + "internal/api/oidc_service.go": "82f21af7da5f05a86bf76561684bd8f356f473e6ed18429f960a81b261581546", + "internal/api/onboarding_handlers.go": "4a47265c65d46a6770c7caf94ccb55602f62e579bf0ed791af26c25602f33ee5", + "internal/api/org_handlers.go": "bb47a7b69ff24f05f8cab7e304fc281837970c1cb75a405a35e54c6d2d8e96ac", + "internal/api/org_lifecycle_handlers.go": "980b4c6e7e3010fdc22e52c5d2ee7a12b6a2b0ff63331feca7398841cecec4fe", + "internal/api/patrol_action_broker.go": "bbc5ebd742c5dc4c3b5cc5b79eab746b074af847ebccc190115605e3cd258f28", + "internal/api/patrol_action_reconciliation.go": "52e339d14ee9715b85d19a93fee21b656a55d8793e9a192fa71b86726c0d48e6", + "internal/api/patrol_finding_notifications.go": "c19e09c9118a67dd64be2e22f1d8f2efa46694a161f3011e2d513d9e66e44997", + "internal/api/patrol_objectives.go": "fc47707db8f337e692b0392fe46f33ade34ffe56ea99300defd246c0c4afdbcc", + "internal/api/payments_webhook_handlers.go": "ec1e1cf664520a9c15b3a8a947dce9186cf5c6bd76cb0b9ef3d1ab3ea598535b", + "internal/api/pbs_backups.go": "788600ff602866f7d5d70408fb7c612036cc6f9d7adde51d4a8ff84635597cc2", + "internal/api/platform_connection_shared.go": "d41aed940a10758167f68752c591225fc9c4a6034e49a0741cd673d417cfd4b8", + "internal/api/platform_mock_connections.go": "34a4a8176a9abedb42aba31b771252387b73ddb9d4c880d1a7d7328e5afa8136", + "internal/api/pmg.go": "efb9ad0037c196cbcf084dab03d3c31c6ade1ca4fa1904d0dd72a5f0493ef5af", + "internal/api/profile_suggestions.go": "b1fcf4548fc28303e9266faa3eecf2e632d1510d3b5cdbf3cddc66836f1ad8e3", + "internal/api/proxmox_guest_action_executor.go": "ddb70d949e8841202618d3ac3fd3dc350b03271701c93ac3a83c139c130e587a", + "internal/api/proxmox_guest_action_observer.go": "11b0146be21c9303315864d4ac0fe7ccf46ed3b1b380ea96e8933586a6e1db8a", + "internal/api/proxmox_guest_action_result.go": "b28f45e197f55dbb7072d229dc24ce70d73ed67dd3f511407f26fd7b091e9e93", + "internal/api/public_signup_handlers.go": "0e180ee90cbc7b65df2eb7075d76fb51c3f308331d2420c8e5a9cb3cce1393d3", + "internal/api/purchase_return_redemptions.go": "e1a0a573773ebb308f6406ad6bdb932f43d48519c1ec6dfccdf0c7cbbd899ca5", + "internal/api/pve_backups.go": "3117c78dbf940bb350aabc10ea999c05942749ed82c549969aacf829536fd012", + "internal/api/rate_limit_config.go": "503bdd861cdb50c917e3d613b56298ca7b83d6b3e14da7a5c774dcf2ab4b0e95", + "internal/api/ratelimit.go": "122c8ac5378e6affdf7b75e609489688bfbee6b019c1592c61a46c68baf9f6a8", + "internal/api/ratelimit_tenant.go": "2a8bd7b5ddbc757c5ac5606c220647b2447e56efd61b1f9f378b576f251c77de", + "internal/api/recovery_handlers.go": "553698c6c21e057adcb888a2fa15c7f488c3db217f3e9136b6bed2e61142b6ef", + "internal/api/recovery_tokens.go": "c05626028329fa15024190782af89eab37592ad080d37b9ddaf630504972e6b9", + "internal/api/relay_hosted_runtime.go": "f4ed4fcf2b2d152c8cbf76e90248ad2d1bd3767761f0f92b18c345307d3a5f53", + "internal/api/relay_mobile_capability.go": "04c7566f9beb22b39e47c5d2591079573ee8244ea554c680576017eb130883d9", + "internal/api/relay_mobile_capability_generated.go": "b62a514754ceb0b6e03251d4873f7755a44bb5dc81787d4f7c8eca4fcfd6dd26", + "internal/api/release_demo_fixtures_dev.go": "f4502a13aa453a50ea967a92959cc6c9013259bdfe596e9e0b9c50da544442d5", + "internal/api/release_demo_fixtures_release.go": "a3d98bfc68d10981676406d1916c13996636c5d5996cf360db26c5d1c14f9026", + "internal/api/replication.go": "9faf8ea8879dd79b33e516acd68f567559c50f7ad5c88e7c34317af9d8b01775", + "internal/api/report_schedules.go": "bc48321b39c6c529b0fc5fa8b0add899831c8574ea0f9ff8eb24c6c7c9fcd834", + "internal/api/reporting_availability.go": "1fb0c3161a742060848da9367f90d68d8c1192ad95111c0caa5c4bd1b40afde1", + "internal/api/reporting_catalog_handlers.go": "6f4bdc73f653c47e397cb6dd9b459523c094a3bbbcf2e9c5950f7fd4a1c1d05f", + "internal/api/reporting_inventory_handlers.go": "8651612acd744975b5b1f4b469a9949ec6017266ead3a29b5b1f6578189eeb85", + "internal/api/reporting_runtime_snapshot.go": "9398bd23e031941c9a6b8ef5cf7debd6a4d8c8e1030bb00ff4e9c3d9650aceb7", + "internal/api/resourceapi/k8s_namespaces.go": "78dda0edba00d8f4d951c0b45e2e7b438c408391dd42143d43bdab3eb107ea0e", + "internal/api/resourceapi/resources.go": "58664371f69e1728963fedab9681521beef12bfbb7d6f994ea0541004346d5b1", + "internal/api/resources_compat.go": "ff90db21381ea3b27ba2199d58f963efae7885e88416b2d6f540d86c2d57fecc", + "internal/api/resources_operator_state.go": "949e74e2698fd90dd8c0f47cd5809b37e95db40b48d3d37e4d4b53489dec0c1e", + "internal/api/router.go": "f1483edbff4d267088af6b6646e58106ca0dae3c6f750727e3c74a4b14fafcd6", + "internal/api/router_helpers.go": "a61f76b9dd9e7883778253bc908d6b6dff55bdb07ca335716a952da57ae89b94", + "internal/api/router_logging.go": "80251a5c997d1a46b21ad6b4291a2aea099ab29553d69553df95efa08a7852d7", + "internal/api/router_routes_ai_relay.go": "5dc12639ef3ff8a6ce2d8b1c0be3d9e83007929c413463d0bea14f141aaa0d94", + "internal/api/router_routes_auth_security.go": "24b6371975952cf6bcc83b2fbb16994104ccee1009bc3693a71c1d9ff9e137c5", + "internal/api/router_routes_cloud.go": "7a47facf452e9f08958036cae38664e116003f2df46e0614b7e84b1cc175db91", + "internal/api/router_routes_debug.go": "92b6bd7d50b829f99f3a1613b87f83727dc099cfe9d75ed2d3d80c82984f9821", + "internal/api/router_routes_licensing.go": "ab6853ef7ad69f1c80fd57022bc8db50964c4854131d9876f25d4da0b1bb8821", + "internal/api/router_routes_monitoring.go": "ed5d592961030cebc1e3851c3ceb94d0760d8ad3c427735132d8551724352f03", + "internal/api/router_routes_registration.go": "5dd74018d9f27552a8e619816825e66cfd66d5848618efd283b4cc15f3055ae7", + "internal/api/runtime_branding.go": "c7fd8070b0fc5e679aad88955c041f423a22127ea971522eb2e2655d245c505d", + "internal/api/runtime_display.go": "974c2c0ad1b4e2d07eec99fcd850de8e0edb29eb5c1e25afb29f487d4a8e57ad", + "internal/api/runtime_inventory_sources.go": "10140e2fc660c4631641152a48fbcb1ca3da68a97a5c205051647342b07ff12a", + "internal/api/saml_handlers.go": "a7f0f4a2822f04ba467597c8c6be71bae52e1727953aa45e96c2c037966f6b0a", + "internal/api/saml_service.go": "598d2e31c2280983984eceffa587feaf1dd54c10477c5205587a1fd0e5182592", + "internal/api/security.go": "4c1e22e52749ad6fac5173f11b51644c500d9195c2b0e2ae0ede7260022b006a", + "internal/api/security_first_run_reset.go": "6b3e04f3e6094a7b0a8a19e0e21a7adba16146cbaf5c266a9997d86f84bf126c", + "internal/api/security_setup_fix.go": "26a9bb880f47caedf850f93a8660f489658b4cf5ddf54202b8f3cd06c153116c", + "internal/api/security_status_capabilities.go": "a384aca3ea0ba7809b94abf7eb5dc6448e5c1f253341b1936d0d12ec5be818eb", + "internal/api/security_tokens.go": "6448fcd31ebd447ca2e01e79dffe614adcfa313a256db8710529cba5c2eb84fb", + "internal/api/session_store.go": "fd56ebc4131d60d7de022ad16ea6240016e35796aa7386b5b4e9a89798e2312c", + "internal/api/slo.go": "c9306f43058eaa2e29768a9e8cdcac06f7bbd6f10e1f9b76dadf4bec48f6ff09", + "internal/api/sso_outbound.go": "9920a49fed5a9415e099f6e5aa01dfdc5bff97212004fa269a71f35b549e724f", + "internal/api/state_provider.go": "56ad65a422d4229079ecc1701c3170bce90e9893f2bdffcd69045967c3c4256b", + "internal/api/state_summary.go": "0da03832e2844b2b4b3d4e659a48aa540664f7ad7671251a617e46fe28ca1a77", + "internal/api/subscription_entitlements.go": "0314f3b64ea57ad3315317cedef28518f10fa54e0c7621097ef8bd5f8cb5bdf8", + "internal/api/subscription_state_handlers.go": "c7b8f94368d62a582e9e2a506c1bfbee2b220cba4a54c129b5056955949cc498", + "internal/api/subscription_state_reconciler.go": "0b66098ee91e87681273f2a9ad6d4ea027a20a99e09e42baf89df0099f94b3ff", + "internal/api/system_settings.go": "c71814a15c49c5da3af9d541d1fea492cfac9131d1a082023cb5eb9e4e0f22f4", + "internal/api/telemetry_audit_reads.go": "7cc72c7428e5bd4fed58c6c0a07a0033d07b324741e9e626fb8a7b2565c6fe98", + "internal/api/telemetry_licensed_features.go": "b11e211705a305d70aaa6977c603fe91aefa9628bd7828c05c2052ffd5f37f2e", + "internal/api/telemetry_pulse_intelligence.go": "0d2dff2276a1d8cbcb07cac9b064343b4896cbb01bc4a53f6eaf5c31e094e3ce", + "internal/api/telemetry_workload_history.go": "62ced9db02d0e04e6723df6142cd6decec9e43c991f5b44a61579e0e73987dd5", + "internal/api/truenas_app_action_provider.go": "ff6b2709ced8ea51887edfa2b1fc4770dfc76b8a5b45b7479e012945fdc5cfd3", + "internal/api/truenas_app_config_provider.go": "b34c12a919c3b9d4ddc8f660ddfa99a06450c8a6ee6269fd93db71ba03b9c3f3", + "internal/api/truenas_app_read_provider.go": "cfb4875315002fd3133b463e27ea09fca5d6dd608ef7954aa8a65ae28aad25bd", + "internal/api/truenas_handlers.go": "bf58c69707ada9d6692861f34d71c1eb2ff32cec0a150d1f331daf2edda3edd2", + "internal/api/types.go": "a5dcb11c6618bd8eaad2eec59cb46d754ddd160e5463987e7cbfa88846cc2ac0", + "internal/api/unified_agent.go": "3ee6bce5cf07652ce1072958d7f4e26183cb62bd8c2cafed3b1903181894bb00", + "internal/api/update_detection.go": "cf8567ff9f6cf3e1902d4a594c48b3fb58bdf6a53c1273e4fc6b386ba615a88f", + "internal/api/update_readiness.go": "f308b143c5c4ffe9344c9c4bbac7a84eb080a33d7a3b55229843e945f3b0c756", + "internal/api/updates.go": "a933c93ed496a401e7fcda3f527443a39e9628dbf64dcc36decfeb8b8d0d25be", + "internal/api/user_limit_enforcement.go": "a4065221e976cfae80182d88346bb9a369777fa5e9fe89d76fb3f310b04cb3a6", + "internal/api/vmware_handlers.go": "a0606e09b10bab5fc899bb42cb57a1089b5a6b1248a52bf46c2c50ce9b613751", + "internal/config/ai.go": "e773d1d1b4bede3aae9a5e1ec640f82c0992826b2bea964724f5de61c01e9ed7", + "internal/config/ai_providers.go": "994c8430b6084616b69fe702bfa4a1602d83e5c37dc60039ac1879e076714eef", + "internal/config/api_tokens.go": "f333752b6da24a85c4342332a8c656cf86d83c8cab45d49d36af9f182fb8af0b", + "internal/config/audit_read_activity.go": "b8fc44fa443112fa94e92c2a2516bd149b9aec12ac7f4b48f87752f9b4f4817a", + "internal/config/availability.go": "72cd69d132a39810940f19c6df10712a0754e6187e2c0bf6b247eb2777217900", + "internal/config/billing_state.go": "b244ad2167d87a20b63189665288008cdbdba3dc97d783add0b9e390ee690a63", + "internal/config/client_helpers.go": "8dd2444ad85af9347f5481bc9c80aa4d91e8eef64f6c966e01a53d3676834757", + "internal/config/config.go": "038725360ef71c31a22d1d79f6b370af07bd25112432b5d8b389ef57a6715818", + "internal/config/detect_root.go": "b1e09c43ae7a8b23edf0639b7c178bbfe8d6db307ce1a0d6864314673c9e4371", + "internal/config/docker_metadata.go": "f6a45c123ffeadbe3481ce5fb744c96afe6a2b2cf2f8f6f400b3913aec78c98e", + "internal/config/entitlement_billing_state.go": "aeb581849ec36021de82d3f3a74eb34bc8051464c5002cc978813a212f465034", + "internal/config/export.go": "8bd4cddcb24ff552185c1e8c7fcfd8ef445e048cb794ad45295f5616945782b7", + "internal/config/file_read_limits.go": "74b877ff7dbd5a7df01edf79fa4033e316facd6acdaf2af01116d4367d48478c", + "internal/config/guest_metadata.go": "63b71837469c85b90e8c7f1f797323b53981dc5e2c6bf414030b960d8910cd09", + "internal/config/host_continuity.go": "cb8408fa70784883a4a62ffd3d7818e16281795d580ce6b9830826a440a14921", + "internal/config/host_metadata.go": "2b3a6f22f9ebec79b69d1327f7b64468e923a1a7fe41e04e88272cd92d7548fa", + "internal/config/import_transaction.go": "c1d8b15b66bd8ec3ca44972d2ebfc45055060ddb37ca9de01f8ee0c0b517740d", + "internal/config/metadata_helpers.go": "73849782962c0d2dec8b8750b4a8ab8c094371536069758eca641a450961743f", + "internal/config/migration.go": "0d48bed7a34c505e413881ebf5cc731aae2ed8d580d0d4ac4bd39422b8817138", + "internal/config/multi_tenant.go": "1873996b514af326a15fc9205f9dee714e3d556ee66db2c8dcb028100c546b6d", + "internal/config/node_test_tally.go": "67ff9908c0c9c5689c23d872d7ed07753f3a117e54aa69de06834346316cb75f", + "internal/config/oidc.go": "11bf532dea4a9ea0f65bef5397dad28629cf79d7b2976d156e2b06589b84e49f", + "internal/config/patrol_autopilot_persistence.go": "31a02f3070cbb4730380efe8e3a4193bcc637c06409c58fc2c09e0f2128ebbb8", + "internal/config/persistence.go": "7271dab3607bfa15312c08e15d8088cfd9278297af10499be4790c56abf55e14", + "internal/config/persistence_alert_intent.go": "187f0e264add73555bfb5c42593b7dcfd841eccdf35c9ecf6eada1f6bac98b43", + "internal/config/persistence_installation_scope.go": "a146e20278fe009166015bc608d34ad411ccfa3ac2884bdc610e96c13807a75c", + "internal/config/persistence_metadata_accessors.go": "51822e30287c314cac91bf822246a3a82d978335697459938b481f7516216b98", + "internal/config/persistence_relay.go": "5874a46e7900b27934fd402533e1a6d7a7b54a45cff25b50f067926579d95c21", + "internal/config/pve_instances.go": "b740964482aaca40d2de5f7f772b79ae093f3e90e4d5fc4aed50c05cf7df20a3", + "internal/config/pve_node_identity.go": "8971e149c1e0c668c2fc8c25abc9b7e86eaf62f0fc19ec0642f4336c9ae8f1d4", + "internal/config/report_branding.go": "bf774484179ab2eadb833013d4b467c10e0af4363a1f220af0e0b2a606d9984c", + "internal/config/report_schedules.go": "1be7c9b681d21a68227d712eaee590d546c5a16bec09dbe68cab3755bb114a8b", + "internal/config/sso.go": "281fa3c5b27aa9dc2ca54c575c800f4fac7397213621540dfa394e4c825e7d30", + "internal/config/truenas.go": "5ab9f0203f8910ffc495ca4249fb36a758dfb3147ce934c514ef3dd01b41d498", + "internal/config/vmware.go": "a29600f8e229ef83577224ba943da9630db0e88203c8e1569385c33e5d485744", + "internal/config/watcher.go": "8efbdc2dcbf9fba9a04ee298bc2118a6ec20c1c4bcf07c5b8a9d2158a2a03467", + "internal/config/workload_history_activity_tally.go": "a2b246c6c1218d6b754cd1bc62ac820ccd6eddb072f14ffed8c5ed1cf9c194e0", + "internal/hostagent/action_runner_client.go": "1a6231c7fdef1c4595b2f0e6660d077374769fa45c0d429d0ea84440a9de3d57", + "internal/hostagent/action_runner_health_persistence_unix.go": "dbc8eb02bcf7129d36a7a6ca91f7abfb102cb6dfbe3ac66b52b74303a06b6887", + "internal/hostagent/action_runner_health_persistence_windows.go": "f16fa2e9f9a2f8aa675777f36582087ead3051e04cdc805ffe7e9200191e9184", + "internal/hostagent/agent.go": "500b7bdd10a2a93b598201e1716e5ad84f98a5a344c9247a5ecab71ef67323d2", + "internal/hostagent/availability.go": "eea45d12922b6859492f562dcfab4dbe248b32a92bc5abd002b5ac51422fdccf", + "internal/hostagent/ceph.go": "fee9561bc972b7bff11a9e87ad879efeac0914fb24b63eae0319f495aceb68f6", + "internal/hostagent/cluster_sensors.go": "6d6104dd2046dc6f9626d2f08f6990923bfad9b37f8028e555b590e368316e26", + "internal/hostagent/command_authority.go": "212ba17cef8beda1cd6250067513ac4ab68faa808844aacd7e5a03691f2dc9a3", + "internal/hostagent/commands.go": "03e1da3a0874645cc8dda0fd03ca307ba754ce61ecbab731e74513822b11b4f0", + "internal/hostagent/commands_deploy.go": "73ac6378c23ba4665dd98459fb941691b114be9ffd2307dbeb8c7ffb1bfd9571", + "internal/hostagent/commands_procgroup_unix.go": "1303d4227ded53ac3668b7a15092d50ff92cb3ffc581d594f9de2ee633fcd884", + "internal/hostagent/commands_procgroup_windows.go": "a2137b47610613beb3748b19eec798091081a800cf162b6f6bf1de9ebf6f40c4", + "internal/hostagent/custom_sensor_security_unix.go": "fa4175df3610c35432a60fdb5c0935800b995b6f89556b3ff00a480999eaf896", + "internal/hostagent/custom_sensor_security_windows.go": "e8ce8bec788b28c75d1734ec7746ec0f467919e05da10d5c382d31fca71877ba", + "internal/hostagent/custom_sensors.go": "301f134d27f8766bb671e4a6576d09f4894916547880585c312c227d3cc68166", + "internal/hostagent/docker_lifecycle.go": "3c6f4ebbbd3ebbe48b29deae6fdec4648e7c9617e5cde0aca432a210997df6c4", + "internal/hostagent/docker_update.go": "03324b0ca29b63609d6078bb5900cc501ab40bed9ff1c46c50992b1d07e0f539", + "internal/hostagent/enroll.go": "5d72a553cdaad74aa77942404c7f1da7537dde0920dcabba0bccc927bd8d36b9", + "internal/hostagent/libvirt.go": "0c4ee6346169e06bc26d2e006ff85cc7749da435c2f59db17adb8c4ad334d7e5", + "internal/hostagent/mdadm.go": "f2714ec89953361aec92cb09dfaaf89b25af97eb24360c5b464ba723f3261cf4", + "internal/hostagent/nvidia_smi.go": "9a4c4657604f1cf0d365b64a6ac4b289b21fc7cb7b7ef1b85888bb4381473beb", + "internal/hostagent/os_identity.go": "0ab3306f5219ec8534cd4862962297169df055e1d62012ac999c01137b374bdf", + "internal/hostagent/package_manager_lease.go": "e8879c39780a1712596cc8dd4ce25d45f28eef6c698878bb20a9cd1fd4aecbe2", + "internal/hostagent/package_updates.go": "64e0f3042ad176a874c724c91e05d7012b4c5f3b08d4df15d00ae29ea327423a", + "internal/hostagent/privilege.go": "9973b39fce82be4989ae64515d43bbfd4e3195330d64a388573bf7ebe69454dd", + "internal/hostagent/privilege_helper_client.go": "90313c33de1006895fbe1cfa001943b5ed79a02f5a7f296d529d9862de2b6cf1", + "internal/hostagent/proxmox_guest_lifecycle.go": "14d0a882859a44b3f3ff300c6f547db77e966881b742003fcb3e52db04431a89", + "internal/hostagent/proxmox_lxc_filesystems.go": "101007cd8ff35cb2f7d80140aaab0df162092ddd27d7c30bcb9972f28763d0ad", + "internal/hostagent/proxmox_lxc_filesystems_linux.go": "05424af10374cff45163a25eb8149e1bc2d3604b336b5f699a3fbaa480a2615d", + "internal/hostagent/proxmox_setup.go": "6101db7876fa63f305d27276ea8193e35435cf485f628a196048b5a9b9636391", + "internal/hostagent/smartctl.go": "83d75343e1a7496d987f128f4084f290de81db2a6cc63b463528207696dfb1d0", + "internal/hostagent/storage_cleanup.go": "6bf8a9457ae63fb4cdf375660cb85a15302aa29fdc303e1ed9a2cfc71abf3c0f", + "internal/hostagent/sysinfo.go": "768558142a26526f99edc0e55e8408e165e6f272b8bdb63d871d1659a3f08b44", + "internal/hostagent/unraid.go": "e317ae5ba0432e1cfedf853ee69288473631e5cd0300910a9c0f54f54ce32e6f", + "internal/hostagent/version.go": "fd06f8a2f9360b1e82a0687f76fe13f6b16786a2e2dca3fbc5d668717ec6b04b", + "internal/hostagent/windows_librehardwaremonitor.go": "aa9f67de011c2f23ba7ac1ffd66d566c12bfc920446b1151b8d08abe02349c9c", + "internal/hostagent/windows_storage_sensors.go": "c0b43fd797a79887c7b24f18f36185b35885d1328b207549ab7f3eae05a00789", + "internal/hostagent/xcpng.go": "24334380d87e6e0ea0559e03ffdcb5ce754f1f23340038ecf482758d6e51d28c", + "internal/hostagent/zfs.go": "75fe80d6fb8c2ecd7495589bf006800065f0c51caa3c454c3ccf828e2d905437", + "internal/operationreceipt/store.go": "6f40b4422fde09e81fc989b9b5f35066ebb3276e20bb0903a554414b69e6f6fe", + "internal/operationreceipt/types.go": "08b86678dfe55b5ec29c94ef96de15e9e3f416a9db656481f8ae833b38538dfa", + "scripts/install.sh": "63d1609fd1a3c02d07ee9034b7f177b4f00e523c97ea91b74bce2946407c5c9a", + "scripts/installtests/secure_runtime_systemd_lab_test.go": "5f6929162d8067c454b6c676481c6fd739053565c910419da65ee85e263c454a", + "scripts/release_control/secure_runtime_attestation.py": "f83c545a95dd6f9c46b4c676e1c28a2ae9b7a8a42ebef11b0af914d580ccecf1", + "scripts/release_control/secure_runtime_source_manifest_v4.json": "243e6c85640dec80082e3f1bdc5983912c613ad97ff9e9292b110a9f1411bb45" + }, + "artifact_hashes": { + "collector_v1": "6ebdbc3b54c9cfdfa69419024d676d239309c8b100e614bbb1c5d7d58ff244a4", + "collector_v2": "d11bc3387cfe4cd775df00ab4ec869aa53c2b9a41ff82186d67347b7a1d24b7c", + "helper": "717faf13d6931b048ecc545f2064919bde61ca891c7e53fe36989a91085d88d9", + "runner": "baf14412a7c8b74ad5ab70c3eab15a106d46ec6e6e742df38a11fc2671156a46" + }, + "artifact_versions": { + "collector_v1": "v6.4.1-secure-v4.1", + "collector_v2": "v6.4.1-secure-v4.2" + }, + "disposable_vm_guard_sha256": "8e5627d75bbd86ab54f63cf4af8a63bdb5c134450e1cf75b0bf13095349fa68d", + "os_release": "PRETTY_NAME=\"Ubuntu 24.04.4 LTS\"\nNAME=\"Ubuntu\"\nVERSION_ID=\"24.04\"\nVERSION=\"24.04.4 LTS (Noble Numbat)\"\nVERSION_CODENAME=noble\nID=ubuntu\nID_LIKE=debian\nHOME_URL=\"https://www.ubuntu.com/\"\nSUPPORT_URL=\"https://help.ubuntu.com/\"\nBUG_REPORT_URL=\"https://bugs.launchpad.net/ubuntu/\"\nPRIVACY_POLICY_URL=\"https://www.ubuntu.com/legal/terms-and-policies/privacy-policy\"\nUBUNTU_CODENAME=noble\nLOGO=ubuntu-logo", + "kernel": "Linux 6.8.0-117-generic #117-Ubuntu SMP PREEMPT_DYNAMIC Thu May 7 17:26:37 UTC 2026 aarch64 GNU/Linux", + "systemd_version": "systemd 255 (255.4-1ubuntu8.15)", + "architecture": "arm64", + "collector_service_user": "pulse-agent", + "collector_process_uid": 996, + "collector_authority": "monitoring-only", + "ambient_capabilities_none": true, + "helper_protocol_healthy": true, + "state_identity_preserved": true, + "docker_degraded": true, + "action_runner_qualified": true, + "action_mutation_verified": true, + "collector_authority_reduction_request_observed": true, + "action_receipt_kind": "pulse.host_storage_cleanup_result", + "credential_rotated": true, + "self_revoke_observed": true, + "collector_continuity": true, + "report_count": 47, + "first_report_at": "2026-08-30T18:10:19.845040724Z", + "last_report_at": "2026-08-30T18:12:04.284245654Z", + "transcript": { + "format": "jsonl-v1", + "record_path": "docs/release-control/v6/internal/records/secure-agent-runtime-systemd-transcript-v4-2026-08-30.jsonl", + "sha256": "616681aee38202ed922880288b730cd85f746e081f8f9d45bb2d570e48b49f8c", + "event_count": 81 + }, + "scenarios": [ + { + "sequence": 1, + "name": "legacy_root_command_capable_install", + "passed": true, + "started_at": "2026-08-30T18:10:18.105761661Z", + "completed_at": "2026-08-30T18:10:20.7594628Z", + "evidence": { + "kind": "runtime-observation-v1", + "summary": "root collector installed; docker_enabled=true", + "claims": [ + "legacy_root_command_authority_observed" + ], + "observations": { + "collector_process_uid": 0, + "commands_enabled": true + }, + "transcript_event_ids": [ + "event-0007" + ] + } + }, + { + "sequence": 2, + "name": "read_only_inspect", + "passed": true, + "started_at": "2026-08-30T18:10:20.7594628Z", + "completed_at": "2026-08-30T18:10:20.852343562Z", + "evidence": { + "kind": "runtime-observation-v1", + "summary": "stable installer-owned files unchanged", + "claims": [ + "inspection_left_stable_files_unchanged" + ], + "observations": { + "stable_files_unchanged": true + }, + "transcript_event_ids": [ + "event-0009" + ] + } + }, + { + "sequence": 3, + "name": "drop_in_fail_closed_rehearsal", + "passed": true, + "started_at": "2026-08-30T18:10:20.852343562Z", + "completed_at": "2026-08-30T18:10:21.145118405Z", + "evidence": { + "kind": "runtime-observation-v1", + "summary": "migration rejected before stable installer-owned files changed", + "claims": [ + "drop_in_rejected_before_mutation" + ], + "observations": { + "rejected_before_mutation": true + }, + "transcript_event_ids": [ + "event-0013" + ] + } + }, + { + "sequence": 4, + "name": "safe_profile_apply", + "passed": true, + "started_at": "2026-08-30T18:10:21.145118405Z", + "completed_at": "2026-08-30T18:10:28.52640484Z", + "evidence": { + "kind": "runtime-observation-v1", + "summary": "fresh server lastSeen, least-privilege identity, typed helper health", + "claims": [ + "collector_non_root", + "collector_monitoring_only", + "helper_protocol_healthy", + "collector_authority_reduction_observed" + ], + "observations": { + "collector_authority": "monitoring-only", + "collector_service_user": "pulse-agent", + "helper_status": "ok" + }, + "transcript_event_ids": [ + "event-0024" + ] + } + }, + { + "sequence": 5, + "name": "explicit_safe_profile_rollback", + "passed": true, + "started_at": "2026-08-30T18:10:28.52640484Z", + "completed_at": "2026-08-30T18:10:30.084995619Z", + "evidence": { + "kind": "runtime-observation-v1", + "summary": "legacy binary and service identity restored without resurrecting collector command authority", + "claims": [ + "explicit_rollback_preserved_reduced_authority" + ], + "observations": { + "commands_enabled": false, + "restored_profile": "root-monitoring" + }, + "transcript_event_ids": [ + "event-0029" + ] + } + }, + { + "sequence": 6, + "name": "automatic_failure_rollback", + "passed": true, + "started_at": "2026-08-30T18:10:30.084995619Z", + "completed_at": "2026-08-30T18:11:03.696237146Z", + "evidence": { + "kind": "runtime-observation-v1", + "summary": "frozen lastSeen prevented commit and restored binary/state identity without command authority", + "claims": [ + "failed_activation_restored_prior_runtime" + ], + "observations": { + "activation_committed": false, + "restored_profile": "root-monitoring" + }, + "transcript_event_ids": [ + "event-0034" + ] + } + }, + { + "sequence": 7, + "name": "ordinary_update_non_migration", + "passed": true, + "started_at": "2026-08-30T18:11:03.696237146Z", + "completed_at": "2026-08-30T18:11:09.208098298Z", + "evidence": { + "kind": "runtime-observation-v1", + "summary": "binary updated while the downgraded root monitoring profile remained unchanged", + "claims": [ + "ordinary_update_preserved_selected_profile" + ], + "observations": { + "collector_v2_installed": true, + "selected_profile": "root-monitoring" + }, + "transcript_event_ids": [ + "event-0039" + ] + } + }, + { + "sequence": 8, + "name": "final_safe_profile_apply", + "passed": true, + "started_at": "2026-08-30T18:11:09.208098298Z", + "completed_at": "2026-08-30T18:11:17.15862403Z", + "evidence": { + "kind": "runtime-observation-v1", + "summary": "collector continued reporting after committed migration", + "claims": [ + "collector_reporting_continued_after_migration" + ], + "observations": { + "collector_service_user": "pulse-agent", + "continuity_report_observed": true + }, + "transcript_event_ids": [ + "event-0050" + ] + } + }, + { + "sequence": 9, + "name": "separate_action_runner_install", + "passed": true, + "started_at": "2026-08-30T18:11:17.15862403Z", + "completed_at": "2026-08-30T18:11:40.279395293Z", + "evidence": { + "kind": "runtime-observation-v1", + "summary": "root action runner registered and activated independently while the collector remained non-root and reporting", + "claims": [ + "action_runner_registered_separately" + ], + "observations": { + "collector_service_user": "pulse-agent", + "fixture_activation_requests": 1, + "runner_service_user": "root" + }, + "transcript_event_ids": [ + "event-0063" + ] + } + }, + { + "sequence": 10, + "name": "typed_action_receipt", + "passed": true, + "started_at": "2026-08-30T18:11:40.279395293Z", + "completed_at": "2026-08-30T18:11:40.533544715Z", + "evidence": { + "kind": "runtime-observation-v1", + "summary": "verified apt cache mutation and durable terminal receipt; stale fingerprint refused before mutation; generic command dispatch denied", + "claims": [ + "typed_mutation_verified", + "terminal_receipt_replayed", + "stale_precondition_refused", + "generic_command_denied" + ], + "observations": { + "action_receipt_kind": "pulse.host_storage_cleanup_result", + "generic_command_denied": true, + "mutation_started": true, + "stale_precondition_mutation_started": false, + "verification": "verified" + }, + "transcript_event_ids": [ + "event-0064" + ] + } + }, + { + "sequence": 11, + "name": "action_runner_credential_rotation", + "passed": true, + "started_at": "2026-08-30T18:11:40.533544715Z", + "completed_at": "2026-08-30T18:12:03.915338343Z", + "evidence": { + "kind": "runtime-observation-v1", + "summary": "mismatched invalidation was rejected, exact superseded session closed, replacement credential registered and activated", + "claims": [ + "fixture_credential_replacement_observed" + ], + "observations": { + "fixture_activation_requests": 2, + "proof_scope": "in-memory-fixture", + "replacement_registered": true, + "superseded_session_invalidated": true + }, + "transcript_event_ids": [ + "event-0066" + ] + } + }, + { + "sequence": 12, + "name": "action_runner_self_revoke", + "passed": true, + "started_at": "2026-08-30T18:12:03.915338343Z", + "completed_at": "2026-08-30T18:12:04.285982642Z", + "evidence": { + "kind": "runtime-observation-v1", + "summary": "uninstall revoked the exact host binding and removed only runner state; collector/helper continuity remained healthy", + "claims": [ + "exact_runner_binding_revoked" + ], + "observations": { + "collector_continuity": true, + "revocation_count": 1 + }, + "transcript_event_ids": [ + "event-0078" + ] + } + } + ] +} diff --git a/docs/release-control/v6/internal/records/secure-agent-runtime-systemd-transcript-v4-2026-08-30.jsonl b/docs/release-control/v6/internal/records/secure-agent-runtime-systemd-transcript-v4-2026-08-30.jsonl new file mode 100644 index 000000000..e34d8caf9 --- /dev/null +++ b/docs/release-control/v6/internal/records/secure-agent-runtime-systemd-transcript-v4-2026-08-30.jsonl @@ -0,0 +1,81 @@ +{"sequence":1,"event_id":"event-0001","observed_at":"2026-08-30T18:10:18.362321296Z","kind":"command_output","operation":"uname","output":"Linux 6.8.0-117-generic #117-Ubuntu SMP PREEMPT_DYNAMIC Thu May 7 17:26:37 UTC 2026 aarch64 GNU/Linux\n","output_sha256":"e811a5e87379ce7ecb7a58b34bea7986bd3fdf5fdfbc816a10ed0207284c5e1a"} +{"sequence":2,"event_id":"event-0002","observed_at":"2026-08-30T18:10:18.363429665Z","kind":"command_output","operation":"systemctl","output":"systemd 255 (255.4-1ubuntu8.15)\n+PAM +AUDIT +SELINUX +APPARMOR +IMA +SMACK +SECCOMP +GCRYPT -GNUTLS +OPENSSL +ACL +BLKID +CURL +ELFUTILS +FIDO2 +IDN2 -IDN +IPTC +KMOD +LIBCRYPTSETUP +LIBFDISK +PCRE2 -PWQUALITY +P11KIT +QRENCODE +TPM2 +BZIP2 +LZ4 +XZ +ZLIB +ZSTD -BPF_FRAMEWORK -XKBCOMMON +UTMP +SYSVINIT default-hierarchy=unified\n","output_sha256":"e17b32215432ff3a0180f661c415aadce050a16ff595a2d691e7e1c8afa5a715"} +{"sequence":3,"event_id":"event-0003","observed_at":"2026-08-30T18:10:20.738316511Z","kind":"command_output","operation":"installer --enable-commands --command-authority command-capable --enable-docker","output":"[INFO] Detecting available platforms...\n[INFO] Monitoring configuration:\n[INFO] Agent metrics: true\n[INFO] Docker/Podman: true\n[INFO] Kubernetes: false\n[INFO] Proxmox: false\n[INFO] Pulse command execution: true\n[INFO] Accepts Pulse-scoped command requests on this agent.\n[INFO] On Proxmox nodes this is required for opted-in LXC Docker inventory via pct exec.\n[INFO] The Pulse server must also be started with PULSE_ENABLE_PROXMOX_GUEST_DOCKER_INVENTORY=true.\n[INFO] Pulse server version: v6.4.1-secure-v4.1\n[INFO] Downloading agent from http://127.0.0.1:35287/download/pulse-agent?arch=linux-arm64\u0026serverVersion=v6.4.1-secure-v4.1...\n[INFO] Binary checksum verified\n[INFO] Installing binary to /usr/local/bin/pulse-agent...\n[INFO] Configuring Systemd service at /etc/systemd/system/pulse-agent.service...\n[INFO] Token stored securely at /var/lib/pulse-agent/token (mode 600)\n[INFO] Verifying agent started successfully...\n[INFO] Agent is running, healthy, and registered with Pulse.\n[INFO] Installation complete! Agent is running.\n[INFO] To uninstall later: sudo bash /var/lib/pulse-agent/install.sh --uninstall\n[INFO] Token file: /var/lib/pulse-agent/token (mode 600, root only)\n","output_sha256":"b731d1da60b0403f9523f5cf0a5636c2fb281077a5b59aa6530df4be0d5ac41e"} +{"sequence":4,"event_id":"event-0004","observed_at":"2026-08-30T18:10:20.745966242Z","kind":"command_output","operation":"systemctl","output":"root\n","output_sha256":"53175bcc0524f37b47062fafdda28e3f8eb91d519ca0a184ca71bbebe72f969a"} +{"sequence":5,"event_id":"event-0005","observed_at":"2026-08-30T18:10:20.752702313Z","kind":"command_output","operation":"systemctl","output":"2051\n","output_sha256":"dba4ed9a9905ad118e34ffb5d5dedcdba00cfe293551f569872da45cb51c4e29"} +{"sequence":6,"event_id":"event-0006","observed_at":"2026-08-30T18:10:20.755228517Z","kind":"command_output","operation":"systemctl","output":"active\n","output_sha256":"45df5ad5e0ecfa54d3226343e0e6857337494ba6e32f189d1174070665d8c659"} +{"sequence":7,"event_id":"event-0007","observed_at":"2026-08-30T18:10:20.7594628Z","kind":"scenario_result","scenario":"legacy_root_command_capable_install","claims":["legacy_root_command_authority_observed"],"observations":{"collector_process_uid":0,"commands_enabled":true},"summary":"root collector installed; docker_enabled=true","output":""} +{"sequence":8,"event_id":"event-0008","observed_at":"2026-08-30T18:10:20.824220298Z","kind":"command_output","operation":"installer --safe-profile-inspect","output":"Pulse safe-profile migration inspection (read-only)\nplatform_supported=true\ncurrent_profile=legacy-root-command-capable\nunit_fragment_path=/etc/systemd/system/pulse-agent.service\nunit_drop_in_paths=none\nunit_unoverridden=true\nunit_user=root\nunit_groups=root\nambient_capabilities=none\ncollector_binary_owner=root:root\ncollector_binary_mode=755\nprovider_host=true\nprovider_docker=true\nprovider_kubernetes=false\nprovider_proxmox=false\ntyped_helper=false\ncollector_commands=true\naction_runner_independent=false\ntarget_profile=typed-helper-monitoring-only\ntarget_unit_user=pulse-agent\ntarget_groups=no-rootful-docker-group\ntarget_ambient_capabilities=none\ntarget_binary_owner=root:root\ntarget_commands=false\ntarget_smart=typed-helper\ntarget_proxmox_filesystems=typed-helper\ntarget_action_runner=unchanged\ndegraded_docker=rootful daemon access is removed unless an independently usable rootless socket is configured\ndegraded_actions=collector command authority is removed; remediation requires the separately enrolled action runner\n","output_sha256":"376efea67abd4ca23aacf07523723860239c7f449d6e9f8fe99d2313602bf250"} +{"sequence":9,"event_id":"event-0009","observed_at":"2026-08-30T18:10:20.852343562Z","kind":"scenario_result","scenario":"read_only_inspect","claims":["inspection_left_stable_files_unchanged"],"observations":{"stable_files_unchanged":true},"summary":"stable installer-owned files unchanged","output":""} +{"sequence":10,"event_id":"event-0010","observed_at":"2026-08-30T18:10:20.945822872Z","kind":"command_output","operation":"systemctl","output":"","output_sha256":"e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"} +{"sequence":11,"event_id":"event-0011","observed_at":"2026-08-30T18:10:21.03806768Z","kind":"command_output","operation":"installer --safe-profile-apply","output":"[INFO] Recovering connection details from /var/lib/pulse-agent/connection.env...\n[INFO] Recovered connection details from the running Pulse Agent process.\n[INFO] Detecting available platforms...\n[INFO] Monitoring configuration:\n[INFO] Agent metrics: true\n[INFO] Docker/Podman: true\n[INFO] Kubernetes: false\n[INFO] Proxmox: false\n[INFO] Pulse command execution: false\n[INFO] Command execution is off; enable only when Patrol actions or Proxmox LXC Docker inventory are needed.\n[WARN] Safe-profile migration disabled rootful Docker monitoring: the collector has no usable collector-owned rootless runtime. Container monitoring is an explicit migration degradation, not helper parity.\n[ERROR] Refusing safe-profile migration while the collector has a different effective FragmentPath or any systemd drop-in override; consolidate the effective unit first\n","output_sha256":"8e7d2f524d16df3fcaf4c659c3a731340e9dc47c8e0fa144c511cf740048e671"} +{"sequence":12,"event_id":"event-0012","observed_at":"2026-08-30T18:10:21.145112938Z","kind":"command_output","operation":"systemctl","output":"","output_sha256":"e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"} +{"sequence":13,"event_id":"event-0013","observed_at":"2026-08-30T18:10:21.145118405Z","kind":"scenario_result","scenario":"drop_in_fail_closed_rehearsal","claims":["drop_in_rejected_before_mutation"],"observations":{"rejected_before_mutation":true},"summary":"migration rejected before stable installer-owned files changed","output":""} +{"sequence":14,"event_id":"event-0014","observed_at":"2026-08-30T18:10:28.385102455Z","kind":"command_output","operation":"installer --safe-profile-apply","output":"[INFO] Recovering connection details from /var/lib/pulse-agent/connection.env...\n[INFO] Recovered connection details from the running Pulse Agent process.\n[INFO] Detecting available platforms...\n[INFO] Monitoring configuration:\n[INFO] Agent metrics: true\n[INFO] Docker/Podman: true\n[INFO] Kubernetes: false\n[INFO] Proxmox: false\n[INFO] Pulse command execution: false\n[INFO] Command execution is off; enable only when Patrol actions or Proxmox LXC Docker inventory are needed.\n[WARN] Safe-profile migration disabled rootful Docker monitoring: the collector has no usable collector-owned rootless runtime. Container monitoring is an explicit migration degradation, not helper parity.\n[INFO] Snapshotted legacy-root-command-capable collector/helper profile before migration.\n[INFO] Durably removed execution and cross-host management scopes from the collector credential before migration.\n[INFO] Pulse server version: v6.4.1-secure-v4.1\n[INFO] Downloading agent from http://127.0.0.1:35287/download/pulse-agent?arch=linux-arm64\u0026serverVersion=v6.4.1-secure-v4.1...\n[INFO] Binary checksum verified\n[INFO] Downloading typed privileged helper from http://127.0.0.1:35287/download/pulse-agent-helper?arch=linux-arm64\u0026serverVersion=v6.4.1-secure-v4.1...\n[INFO] Typed privileged helper binary verified\n[WARN] Downloaded agent version (v6.4.1-secure-v4.2) does not match Pulse server version (v6.4.1-secure-v4.1). Check that Pulse is upgraded and that any reverse proxy is not serving a stale cached binary.\n[INFO] Existing installation detected: v6.4.1-secure-v4.1\n[INFO] Upgrading to: v6.4.1-secure-v4.2\n[INFO] Stopping existing pulse-agent service...\n[INFO] Installing binary to /usr/local/bin/pulse-agent...\n[INFO] Binary upgraded successfully. Updating service configuration...\n[INFO] Configuring Systemd service at /etc/systemd/system/pulse-agent.service...\n[INFO] Token stored securely at /etc/pulse-agent/token (mode 600)\n[INFO] Created system user pulse-agent\nCreated symlink /etc/systemd/system/sockets.target.wants/pulse-agent-helper.socket → /etc/systemd/system/pulse-agent-helper.socket.\n[INFO] Typed privileged helper socket active at /run/pulse-agent/helper.sock (root:pulse-agent 0660)\n[INFO] Typed-helper collector profile: service runs as pulse-agent; binaries and credential files remain root-owned while mutable state remains pulse-agent-owned.\n[INFO] Committed typed-helper monitoring-only profile; rollback snapshot retained at /var/lib/pulse-agent-profile/transaction-20260830T181021Z-2332.\n[INFO] Verifying agent started successfully...\n[INFO] Agent is running, healthy, and registered with Pulse.\n[INFO] Upgrade complete! Agent restarted with new configuration.\n[INFO] To uninstall later: sudo bash /var/lib/pulse-agent/install.sh --uninstall\n","output_sha256":"adb83b61744c1698374d8f20fb255ba84736bdb261528ef67a3248bf9cdd588f"} +{"sequence":15,"event_id":"event-0015","observed_at":"2026-08-30T18:10:28.390060514Z","kind":"command_output","operation":"systemctl","output":"pulse-agent\n","output_sha256":"34d6cc22cb99bd7b3aca0e87e15484537e7d6d1c915333fee99537265fd04271"} +{"sequence":16,"event_id":"event-0016","observed_at":"2026-08-30T18:10:28.394295139Z","kind":"command_output","operation":"systemctl","output":"\n","output_sha256":"01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b"} +{"sequence":17,"event_id":"event-0017","observed_at":"2026-08-30T18:10:28.400601885Z","kind":"command_output","operation":"systemctl","output":"PULSE_AGENT_HELPER_SOCKET=/run/pulse-agent/helper.sock\n","output_sha256":"b9e3421218efb6f874e831eca30c501ea84b75cc4f06e2146bf642aabbdc2e8c"} +{"sequence":18,"event_id":"event-0018","observed_at":"2026-08-30T18:10:28.401049542Z","kind":"command_output","operation":"id","output":"996\n","output_sha256":"009cbb4830299d01fc84a6a56d4f07707d7d073673f6cde576027bafbac75168"} +{"sequence":19,"event_id":"event-0019","observed_at":"2026-08-30T18:10:28.403462797Z","kind":"command_output","operation":"systemctl","output":"2775\n","output_sha256":"a8d9dbab58c95589525422a9b79cde314bf2a37c2b53b516c4e60f1ea5554b1a"} +{"sequence":20,"event_id":"event-0020","observed_at":"2026-08-30T18:10:28.403933478Z","kind":"command_output","operation":"id","output":"pulse-agent\n","output_sha256":"34d6cc22cb99bd7b3aca0e87e15484537e7d6d1c915333fee99537265fd04271"} +{"sequence":21,"event_id":"event-0021","observed_at":"2026-08-30T18:10:28.405883977Z","kind":"command_output","operation":"systemctl","output":"active\n","output_sha256":"45df5ad5e0ecfa54d3226343e0e6857337494ba6e32f189d1174070665d8c659"} +{"sequence":22,"event_id":"event-0022","observed_at":"2026-08-30T18:10:28.408182784Z","kind":"command_output","operation":"systemctl","output":"active\n","output_sha256":"45df5ad5e0ecfa54d3226343e0e6857337494ba6e32f189d1174070665d8c659"} +{"sequence":23,"event_id":"event-0023","observed_at":"2026-08-30T18:10:28.521114906Z","kind":"command_output","operation":"systemctl","output":"active\n","output_sha256":"45df5ad5e0ecfa54d3226343e0e6857337494ba6e32f189d1174070665d8c659"} +{"sequence":24,"event_id":"event-0024","observed_at":"2026-08-30T18:10:28.52640484Z","kind":"scenario_result","scenario":"safe_profile_apply","claims":["collector_non_root","collector_monitoring_only","helper_protocol_healthy","collector_authority_reduction_observed"],"observations":{"collector_authority":"monitoring-only","collector_service_user":"pulse-agent","helper_status":"ok"},"summary":"fresh server lastSeen, least-privilege identity, typed helper health","output":""} +{"sequence":25,"event_id":"event-0025","observed_at":"2026-08-30T18:10:28.825084783Z","kind":"command_output","operation":"installer --safe-profile-rollback","output":"[INFO] Preserving existing typed privileged-helper profile\n[INFO] Restored collector/helper profile legacy-root-command-capable; the action runner was left unchanged.\n","output_sha256":"d1b813088b5a7baefd91f310ba6fb207d605172500a6e6d84b0c6a98e9554d7d"} +{"sequence":26,"event_id":"event-0026","observed_at":"2026-08-30T18:10:30.051445232Z","kind":"command_output","operation":"systemctl","output":"root\n","output_sha256":"53175bcc0524f37b47062fafdda28e3f8eb91d519ca0a184ca71bbebe72f969a"} +{"sequence":27,"event_id":"event-0027","observed_at":"2026-08-30T18:10:30.056823643Z","kind":"command_output","operation":"systemctl","output":"3135\n","output_sha256":"8d2b36f7deec8da7564cf857265ed021d9262467645fdb18b6be0f341d6a5988"} +{"sequence":28,"event_id":"event-0028","observed_at":"2026-08-30T18:10:30.058444781Z","kind":"command_output","operation":"systemctl","output":"active\n","output_sha256":"45df5ad5e0ecfa54d3226343e0e6857337494ba6e32f189d1174070665d8c659"} +{"sequence":29,"event_id":"event-0029","observed_at":"2026-08-30T18:10:30.084995619Z","kind":"scenario_result","scenario":"explicit_safe_profile_rollback","claims":["explicit_rollback_preserved_reduced_authority"],"observations":{"commands_enabled":false,"restored_profile":"root-monitoring"},"summary":"legacy binary and service identity restored without resurrecting collector command authority","output":""} +{"sequence":30,"event_id":"event-0030","observed_at":"2026-08-30T18:11:02.581415872Z","kind":"command_output","operation":"installer --safe-profile-apply","output":"[INFO] Recovering connection details from /var/lib/pulse-agent/connection.env...\n[INFO] Recovered connection details from the running Pulse Agent process.\n[INFO] Detecting available platforms...\n[INFO] Monitoring configuration:\n[INFO] Agent metrics: true\n[INFO] Docker/Podman: true\n[INFO] Kubernetes: false\n[INFO] Proxmox: false\n[INFO] Pulse command execution: false\n[INFO] Command execution is off; enable only when Patrol actions or Proxmox LXC Docker inventory are needed.\n[WARN] Safe-profile migration disabled rootful Docker monitoring: the collector has no usable collector-owned rootless runtime. Container monitoring is an explicit migration degradation, not helper parity.\n[INFO] Snapshotted legacy-root-monitoring collector/helper profile before migration.\n[INFO] Durably removed execution and cross-host management scopes from the collector credential before migration.\n[INFO] Pulse server version: v6.4.1-secure-v4.1\n[INFO] Downloading agent from http://127.0.0.1:35287/download/pulse-agent?arch=linux-arm64\u0026serverVersion=v6.4.1-secure-v4.1...\n[INFO] Binary checksum verified\n[INFO] Downloading typed privileged helper from http://127.0.0.1:35287/download/pulse-agent-helper?arch=linux-arm64\u0026serverVersion=v6.4.1-secure-v4.1...\n[INFO] Typed privileged helper binary verified\n[WARN] Downloaded agent version (v6.4.1-secure-v4.2) does not match Pulse server version (v6.4.1-secure-v4.1). Check that Pulse is upgraded and that any reverse proxy is not serving a stale cached binary.\n[INFO] Existing installation detected: v6.4.1-secure-v4.1\n[INFO] Upgrading to: v6.4.1-secure-v4.2\n[INFO] Stopping existing pulse-agent service...\n[INFO] Installing binary to /usr/local/bin/pulse-agent...\n[INFO] Binary upgraded successfully. Updating service configuration...\n[INFO] Configuring Systemd service at /etc/systemd/system/pulse-agent.service...\n[INFO] Token stored securely at /etc/pulse-agent/token (mode 600)\n[INFO] Typed privileged helper socket active at /run/pulse-agent/helper.sock (root:pulse-agent 0660)\n[INFO] Typed-helper collector profile: service runs as pulse-agent; binaries and credential files remain root-owned while mutable state remains pulse-agent-owned.\n[ERROR] Safe-profile collector did not satisfy local readiness, helper availability, and server registration; restoring the previous profile\n[ERROR] Safe-profile migration did not commit; restoring the previous collector/helper profile.\n[INFO] Restored collector/helper profile legacy-root-monitoring; the action runner was left unchanged.\n","output_sha256":"0de7285656c69ca973636202bcdb919a6e3f7bee4adc1dbf68489077c30ee171"} +{"sequence":31,"event_id":"event-0031","observed_at":"2026-08-30T18:11:03.688233182Z","kind":"command_output","operation":"systemctl","output":"root\n","output_sha256":"53175bcc0524f37b47062fafdda28e3f8eb91d519ca0a184ca71bbebe72f969a"} +{"sequence":32,"event_id":"event-0032","observed_at":"2026-08-30T18:11:03.694235395Z","kind":"command_output","operation":"systemctl","output":"4041\n","output_sha256":"678fde4a9e0d6f6c48b754f0b7958a822e49b5a1e067211619c62c20523f6dd6"} +{"sequence":33,"event_id":"event-0033","observed_at":"2026-08-30T18:11:03.696233521Z","kind":"command_output","operation":"systemctl","output":"active\n","output_sha256":"45df5ad5e0ecfa54d3226343e0e6857337494ba6e32f189d1174070665d8c659"} +{"sequence":34,"event_id":"event-0034","observed_at":"2026-08-30T18:11:03.696237146Z","kind":"scenario_result","scenario":"automatic_failure_rollback","claims":["failed_activation_restored_prior_runtime"],"observations":{"activation_committed":false,"restored_profile":"root-monitoring"},"summary":"frozen lastSeen prevented commit and restored binary/state identity without command authority","output":""} +{"sequence":35,"event_id":"event-0035","observed_at":"2026-08-30T18:11:09.162063893Z","kind":"command_output","operation":"installer --update","output":"[INFO] Recovering connection details from /var/lib/pulse-agent/connection.env...\n[INFO] Recovered connection details from the running Pulse Agent process.\n[INFO] Detecting available platforms...\n[INFO] Monitoring configuration:\n[INFO] Agent metrics: true\n[INFO] Docker/Podman: true\n[INFO] Kubernetes: false\n[INFO] Proxmox: false\n[INFO] Pulse command execution: false\n[INFO] Command execution is off; enable only when Patrol actions or Proxmox LXC Docker inventory are needed.\n[INFO] Pulse server version: v6.4.1-secure-v4.1\n[INFO] Downloading agent from http://127.0.0.1:35287/download/pulse-agent?arch=linux-arm64\u0026serverVersion=v6.4.1-secure-v4.1...\n[INFO] Binary checksum verified\n[WARN] Downloaded agent version (v6.4.1-secure-v4.2) does not match Pulse server version (v6.4.1-secure-v4.1). Check that Pulse is upgraded and that any reverse proxy is not serving a stale cached binary.\n[INFO] Existing installation detected: v6.4.1-secure-v4.1\n[INFO] Upgrading to: v6.4.1-secure-v4.2\n[INFO] Stopping existing pulse-agent service...\n[INFO] Installing binary to /usr/local/bin/pulse-agent...\n[INFO] Binary upgraded successfully. Updating service configuration...\n[INFO] Configuring Systemd service at /etc/systemd/system/pulse-agent.service...\n[INFO] Token stored securely at /var/lib/pulse-agent/token (mode 600)\n[INFO] Verifying agent started successfully...\n[INFO] Agent is running, healthy, and registered with Pulse.\n[INFO] Upgrade complete! Agent restarted with new configuration.\n[INFO] To uninstall later: sudo bash /var/lib/pulse-agent/install.sh --uninstall\n","output_sha256":"ae63fcc6a44550e3fb3fd67c91d6e51429f571fc95672978ee0cb5b33f27c3e0"} +{"sequence":36,"event_id":"event-0036","observed_at":"2026-08-30T18:11:09.16587804Z","kind":"command_output","operation":"systemctl","output":"root\n","output_sha256":"53175bcc0524f37b47062fafdda28e3f8eb91d519ca0a184ca71bbebe72f969a"} +{"sequence":37,"event_id":"event-0037","observed_at":"2026-08-30T18:11:09.171831589Z","kind":"command_output","operation":"systemctl","output":"4337\n","output_sha256":"561c94f2d5cea37acc020b2bbadf8e3870ed3ec6f96be25303506e9ea87fed47"} +{"sequence":38,"event_id":"event-0038","observed_at":"2026-08-30T18:11:09.175195329Z","kind":"command_output","operation":"systemctl","output":"active\n","output_sha256":"45df5ad5e0ecfa54d3226343e0e6857337494ba6e32f189d1174070665d8c659"} +{"sequence":39,"event_id":"event-0039","observed_at":"2026-08-30T18:11:09.208098298Z","kind":"scenario_result","scenario":"ordinary_update_non_migration","claims":["ordinary_update_preserved_selected_profile"],"observations":{"collector_v2_installed":true,"selected_profile":"root-monitoring"},"summary":"binary updated while the downgraded root monitoring profile remained unchanged","output":""} +{"sequence":40,"event_id":"event-0040","observed_at":"2026-08-30T18:11:16.207403241Z","kind":"command_output","operation":"installer --safe-profile-apply","output":"[INFO] Recovering connection details from /var/lib/pulse-agent/connection.env...\n[INFO] Recovered connection details from the running Pulse Agent process.\n[INFO] Detecting available platforms...\n[INFO] Monitoring configuration:\n[INFO] Agent metrics: true\n[INFO] Docker/Podman: true\n[INFO] Kubernetes: false\n[INFO] Proxmox: false\n[INFO] Pulse command execution: false\n[INFO] Command execution is off; enable only when Patrol actions or Proxmox LXC Docker inventory are needed.\n[WARN] Safe-profile migration disabled rootful Docker monitoring: the collector has no usable collector-owned rootless runtime. Container monitoring is an explicit migration degradation, not helper parity.\n[INFO] Snapshotted legacy-root-monitoring collector/helper profile before migration.\n[INFO] Durably removed execution and cross-host management scopes from the collector credential before migration.\n[INFO] Pulse server version: v6.4.1-secure-v4.2\n[INFO] Downloading agent from http://127.0.0.1:35287/download/pulse-agent?arch=linux-arm64\u0026serverVersion=v6.4.1-secure-v4.2...\n[INFO] Binary checksum verified\n[INFO] Downloading typed privileged helper from http://127.0.0.1:35287/download/pulse-agent-helper?arch=linux-arm64\u0026serverVersion=v6.4.1-secure-v4.2...\n[INFO] Typed privileged helper binary verified\n[INFO] Existing installation detected: v6.4.1-secure-v4.2\n[INFO] Upgrading to: v6.4.1-secure-v4.2\n[INFO] Stopping existing pulse-agent service...\n[INFO] Installing binary to /usr/local/bin/pulse-agent...\n[INFO] Binary upgraded successfully. Updating service configuration...\n[INFO] Configuring Systemd service at /etc/systemd/system/pulse-agent.service...\n[INFO] Token stored securely at /etc/pulse-agent/token (mode 600)\n[INFO] Typed privileged helper socket active at /run/pulse-agent/helper.sock (root:pulse-agent 0660)\n[INFO] Typed-helper collector profile: service runs as pulse-agent; binaries and credential files remain root-owned while mutable state remains pulse-agent-owned.\n[INFO] Committed typed-helper monitoring-only profile; rollback snapshot retained at /var/lib/pulse-agent-profile/transaction-20260830T181109Z-4405.\n[INFO] Verifying agent started successfully...\n[INFO] Agent is running, healthy, and registered with Pulse.\n[INFO] Upgrade complete! Agent restarted with new configuration.\n[INFO] To uninstall later: sudo bash /var/lib/pulse-agent/install.sh --uninstall\n","output_sha256":"67bf6d2ac87ddfe499f67ad3b0ed7eed17a798ad5d0a71fe2568d281ee5051a1"} +{"sequence":41,"event_id":"event-0041","observed_at":"2026-08-30T18:11:16.211301263Z","kind":"command_output","operation":"systemctl","output":"pulse-agent\n","output_sha256":"34d6cc22cb99bd7b3aca0e87e15484537e7d6d1c915333fee99537265fd04271"} +{"sequence":42,"event_id":"event-0042","observed_at":"2026-08-30T18:11:16.21490958Z","kind":"command_output","operation":"systemctl","output":"\n","output_sha256":"01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b"} +{"sequence":43,"event_id":"event-0043","observed_at":"2026-08-30T18:11:16.221707825Z","kind":"command_output","operation":"systemctl","output":"PULSE_AGENT_HELPER_SOCKET=/run/pulse-agent/helper.sock\n","output_sha256":"b9e3421218efb6f874e831eca30c501ea84b75cc4f06e2146bf642aabbdc2e8c"} +{"sequence":44,"event_id":"event-0044","observed_at":"2026-08-30T18:11:16.222220727Z","kind":"command_output","operation":"id","output":"996\n","output_sha256":"009cbb4830299d01fc84a6a56d4f07707d7d073673f6cde576027bafbac75168"} +{"sequence":45,"event_id":"event-0045","observed_at":"2026-08-30T18:11:16.224861164Z","kind":"command_output","operation":"systemctl","output":"4839\n","output_sha256":"9c1eb9ff2bd806a5e9867911bac4c47cd10c6a30b60e9fe5e5219a54327ed523"} +{"sequence":46,"event_id":"event-0046","observed_at":"2026-08-30T18:11:16.225404821Z","kind":"command_output","operation":"id","output":"pulse-agent\n","output_sha256":"34d6cc22cb99bd7b3aca0e87e15484537e7d6d1c915333fee99537265fd04271"} +{"sequence":47,"event_id":"event-0047","observed_at":"2026-08-30T18:11:16.227948287Z","kind":"command_output","operation":"systemctl","output":"active\n","output_sha256":"45df5ad5e0ecfa54d3226343e0e6857337494ba6e32f189d1174070665d8c659"} +{"sequence":48,"event_id":"event-0048","observed_at":"2026-08-30T18:11:16.229939345Z","kind":"command_output","operation":"systemctl","output":"active\n","output_sha256":"45df5ad5e0ecfa54d3226343e0e6857337494ba6e32f189d1174070665d8c659"} +{"sequence":49,"event_id":"event-0049","observed_at":"2026-08-30T18:11:16.351868983Z","kind":"command_output","operation":"systemctl","output":"active\n","output_sha256":"45df5ad5e0ecfa54d3226343e0e6857337494ba6e32f189d1174070665d8c659"} +{"sequence":50,"event_id":"event-0050","observed_at":"2026-08-30T18:11:17.15862403Z","kind":"scenario_result","scenario":"final_safe_profile_apply","claims":["collector_reporting_continued_after_migration"],"observations":{"collector_service_user":"pulse-agent","continuity_report_observed":true},"summary":"collector continued reporting after committed migration","output":""} +{"sequence":51,"event_id":"event-0051","observed_at":"2026-08-30T18:11:40.250324493Z","kind":"command_output","operation":"installer --least-privilege --enable-privileged-helper --enable-action-runner","output":"[INFO] Detecting available platforms...\n[INFO] Docker/Podman detected - enabling container monitoring\n[INFO] (use --disable-docker to skip)\n[INFO] Monitoring configuration:\n[INFO] Agent metrics: true\n[INFO] Docker/Podman: true\n[INFO] Kubernetes: false\n[INFO] Proxmox: false\n[INFO] Pulse command execution: false\n[INFO] Command execution is off; enable only when Patrol actions or Proxmox LXC Docker inventory are needed.\n[INFO] Pulse server version: v6.4.1-secure-v4.2\n[INFO] Downloading agent from http://127.0.0.1:35287/download/pulse-agent?arch=linux-arm64\u0026serverVersion=v6.4.1-secure-v4.2...\n[INFO] Binary checksum verified\n[INFO] Downloading typed privileged helper from http://127.0.0.1:35287/download/pulse-agent-helper?arch=linux-arm64\u0026serverVersion=v6.4.1-secure-v4.2...\n[INFO] Typed privileged helper binary verified\n[INFO] Downloading typed action runner from http://127.0.0.1:35287/download/pulse-agent-runner?arch=linux-arm64\u0026serverVersion=v6.4.1-secure-v4.2...\n[INFO] Typed action runner binary verified\n[INFO] Existing installation detected: v6.4.1-secure-v4.2\n[INFO] Upgrading to: v6.4.1-secure-v4.2\n[INFO] Stopping existing pulse-agent service...\n[INFO] Installing binary to /usr/local/bin/pulse-agent...\n[INFO] Binary upgraded successfully. Updating service configuration...\n[INFO] Configuring Systemd service at /etc/systemd/system/pulse-agent.service...\n[INFO] Token stored securely at /etc/pulse-agent/token (mode 600)\n[INFO] Typed privileged helper socket active at /run/pulse-agent/helper.sock (root:pulse-agent 0660)\n[INFO] Typed-helper collector profile: service runs as pulse-agent; binaries and credential files remain root-owned while mutable state remains pulse-agent-owned.\nCreated symlink /etc/systemd/system/multi-user.target.wants/pulse-agent-runner.service → /etc/systemd/system/pulse-agent-runner.service.\n[INFO] Typed action runner enabled as a separate root service with its own credential; collector monitoring remains independently active.\n[INFO] Verifying agent started successfully...\n[WARN] Agent process is running but did not become ready within ~18s.\n[WARN] It may still be initializing. Check logs: tail -f /var/log/pulse-agent.log\n[WARN] Upgrade complete, but the agent may not be running correctly.\n[INFO] To uninstall later: sudo bash /var/lib/pulse-agent/install.sh --uninstall\n","output_sha256":"b0d8d70d332b15fe826244ca9f92141c6b29beaa7ba591587d584c36473879bb"} +{"sequence":52,"event_id":"event-0052","observed_at":"2026-08-30T18:11:40.253514384Z","kind":"command_output","operation":"systemctl","output":"active\n","output_sha256":"45df5ad5e0ecfa54d3226343e0e6857337494ba6e32f189d1174070665d8c659"} +{"sequence":53,"event_id":"event-0053","observed_at":"2026-08-30T18:11:40.257591464Z","kind":"command_output","operation":"systemctl","output":"root\n","output_sha256":"53175bcc0524f37b47062fafdda28e3f8eb91d519ca0a184ca71bbebe72f969a"} +{"sequence":54,"event_id":"event-0054","observed_at":"2026-08-30T18:11:40.260239275Z","kind":"command_output","operation":"systemctl","output":"\n","output_sha256":"01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b"} +{"sequence":55,"event_id":"event-0055","observed_at":"2026-08-30T18:11:40.262872878Z","kind":"command_output","operation":"systemctl","output":"pulse-agent\n","output_sha256":"34d6cc22cb99bd7b3aca0e87e15484537e7d6d1c915333fee99537265fd04271"} +{"sequence":56,"event_id":"event-0056","observed_at":"2026-08-30T18:11:40.265266171Z","kind":"command_output","operation":"systemctl","output":"\n","output_sha256":"01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b"} +{"sequence":57,"event_id":"event-0057","observed_at":"2026-08-30T18:11:40.272183659Z","kind":"command_output","operation":"systemctl","output":"PULSE_AGENT_HELPER_SOCKET=/run/pulse-agent/helper.sock\n","output_sha256":"b9e3421218efb6f874e831eca30c501ea84b75cc4f06e2146bf642aabbdc2e8c"} +{"sequence":58,"event_id":"event-0058","observed_at":"2026-08-30T18:11:40.272633649Z","kind":"command_output","operation":"id","output":"996\n","output_sha256":"009cbb4830299d01fc84a6a56d4f07707d7d073673f6cde576027bafbac75168"} +{"sequence":59,"event_id":"event-0059","observed_at":"2026-08-30T18:11:40.274950938Z","kind":"command_output","operation":"systemctl","output":"5371\n","output_sha256":"99a39a35c441842e9cda35b8fffcf669f5da52a897266d56e90884fdbe142f8c"} +{"sequence":60,"event_id":"event-0060","observed_at":"2026-08-30T18:11:40.275348132Z","kind":"command_output","operation":"id","output":"pulse-agent\n","output_sha256":"34d6cc22cb99bd7b3aca0e87e15484537e7d6d1c915333fee99537265fd04271"} +{"sequence":61,"event_id":"event-0061","observed_at":"2026-08-30T18:11:40.276960621Z","kind":"command_output","operation":"systemctl","output":"active\n","output_sha256":"45df5ad5e0ecfa54d3226343e0e6857337494ba6e32f189d1174070665d8c659"} +{"sequence":62,"event_id":"event-0062","observed_at":"2026-08-30T18:11:40.279389417Z","kind":"command_output","operation":"systemctl","output":"active\n","output_sha256":"45df5ad5e0ecfa54d3226343e0e6857337494ba6e32f189d1174070665d8c659"} +{"sequence":63,"event_id":"event-0063","observed_at":"2026-08-30T18:11:40.279395293Z","kind":"scenario_result","scenario":"separate_action_runner_install","claims":["action_runner_registered_separately"],"observations":{"collector_service_user":"pulse-agent","fixture_activation_requests":1,"runner_service_user":"root"},"summary":"root action runner registered and activated independently while the collector remained non-root and reporting","output":""} +{"sequence":64,"event_id":"event-0064","observed_at":"2026-08-30T18:11:40.533544715Z","kind":"scenario_result","scenario":"typed_action_receipt","claims":["typed_mutation_verified","terminal_receipt_replayed","stale_precondition_refused","generic_command_denied"],"observations":{"action_receipt_kind":"pulse.host_storage_cleanup_result","generic_command_denied":true,"mutation_started":true,"stale_precondition_mutation_started":false,"verification":"verified"},"summary":"verified apt cache mutation and durable terminal receipt; stale fingerprint refused before mutation; generic command dispatch denied","output":""} +{"sequence":65,"event_id":"event-0065","observed_at":"2026-08-30T18:12:03.915316425Z","kind":"command_output","operation":"installer --least-privilege --enable-privileged-helper --enable-action-runner","output":"[INFO] Detecting available platforms...\n[INFO] Docker/Podman detected - enabling container monitoring\n[INFO] (use --disable-docker to skip)\n[INFO] Monitoring configuration:\n[INFO] Agent metrics: true\n[INFO] Docker/Podman: true\n[INFO] Kubernetes: false\n[INFO] Proxmox: false\n[INFO] Pulse command execution: false\n[INFO] Command execution is off; enable only when Patrol actions or Proxmox LXC Docker inventory are needed.\n[INFO] Pulse server version: v6.4.1-secure-v4.2\n[INFO] Downloading agent from http://127.0.0.1:35287/download/pulse-agent?arch=linux-arm64\u0026serverVersion=v6.4.1-secure-v4.2...\n[INFO] Binary checksum verified\n[INFO] Downloading typed privileged helper from http://127.0.0.1:35287/download/pulse-agent-helper?arch=linux-arm64\u0026serverVersion=v6.4.1-secure-v4.2...\n[INFO] Typed privileged helper binary verified\n[INFO] Downloading typed action runner from http://127.0.0.1:35287/download/pulse-agent-runner?arch=linux-arm64\u0026serverVersion=v6.4.1-secure-v4.2...\n[INFO] Typed action runner binary verified\n[INFO] Existing installation detected: v6.4.1-secure-v4.2\n[INFO] Upgrading to: v6.4.1-secure-v4.2\n[INFO] Stopping existing pulse-agent service...\n[INFO] Installing binary to /usr/local/bin/pulse-agent...\n[INFO] Binary upgraded successfully. Updating service configuration...\n[INFO] Configuring Systemd service at /etc/systemd/system/pulse-agent.service...\n[INFO] Token stored securely at /etc/pulse-agent/token (mode 600)\n[INFO] Typed privileged helper socket active at /run/pulse-agent/helper.sock (root:pulse-agent 0660)\n[INFO] Typed-helper collector profile: service runs as pulse-agent; binaries and credential files remain root-owned while mutable state remains pulse-agent-owned.\n[INFO] Typed action runner enabled as a separate root service with its own credential; collector monitoring remains independently active.\n[INFO] Verifying agent started successfully...\n[WARN] Agent process is running but did not become ready within ~18s.\n[WARN] It may still be initializing. Check logs: tail -f /var/log/pulse-agent.log\n[WARN] Upgrade complete, but the agent may not be running correctly.\n[INFO] To uninstall later: sudo bash /var/lib/pulse-agent/install.sh --uninstall\n","output_sha256":"ef02c81e2651ec1bb67438246da7660a2f91fce59661eeb3012739a82753a694"} +{"sequence":66,"event_id":"event-0066","observed_at":"2026-08-30T18:12:03.915338343Z","kind":"scenario_result","scenario":"action_runner_credential_rotation","claims":["fixture_credential_replacement_observed"],"observations":{"fixture_activation_requests":2,"proof_scope":"in-memory-fixture","replacement_registered":true,"superseded_session_invalidated":true},"summary":"mismatched invalidation was rejected, exact superseded session closed, replacement credential registered and activated","output":""} +{"sequence":67,"event_id":"event-0067","observed_at":"2026-08-30T18:12:04.157126044Z","kind":"command_output","operation":"standalone installer --uninstall-action-runner","output":"[INFO] Preserving existing typed privileged-helper profile\n[INFO] Revoked the action-runner credential before removing local runner state.\n[INFO] Pulse action runner removed. Collector monitoring was left installed and running.\n","output_sha256":"909539d49081a87ab0bf02af5743dcef8ab3564f602723a21f0bb565b566b70f"} +{"sequence":68,"event_id":"event-0068","observed_at":"2026-08-30T18:12:04.160278256Z","kind":"command_output","operation":"systemctl","output":"not-found\n","output_sha256":"391bc413c3044926b4afa41806bf4a5c4fad68a3165b8563fe1bffec0792fc76"} +{"sequence":69,"event_id":"event-0069","observed_at":"2026-08-30T18:12:04.162746065Z","kind":"command_output","operation":"systemctl","output":"pulse-agent\n","output_sha256":"34d6cc22cb99bd7b3aca0e87e15484537e7d6d1c915333fee99537265fd04271"} +{"sequence":70,"event_id":"event-0070","observed_at":"2026-08-30T18:12:04.164660352Z","kind":"command_output","operation":"systemctl","output":"\n","output_sha256":"01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b"} +{"sequence":71,"event_id":"event-0071","observed_at":"2026-08-30T18:12:04.168965652Z","kind":"command_output","operation":"systemctl","output":"PULSE_AGENT_HELPER_SOCKET=/run/pulse-agent/helper.sock\n","output_sha256":"b9e3421218efb6f874e831eca30c501ea84b75cc4f06e2146bf642aabbdc2e8c"} +{"sequence":72,"event_id":"event-0072","observed_at":"2026-08-30T18:12:04.169274165Z","kind":"command_output","operation":"id","output":"996\n","output_sha256":"009cbb4830299d01fc84a6a56d4f07707d7d073673f6cde576027bafbac75168"} +{"sequence":73,"event_id":"event-0073","observed_at":"2026-08-30T18:12:04.171324791Z","kind":"command_output","operation":"systemctl","output":"5955\n","output_sha256":"08b943ce091ddaaeb86d43519d1dc5294fc37aa857345270f44bfda34b7abcdc"} +{"sequence":74,"event_id":"event-0074","observed_at":"2026-08-30T18:12:04.171717973Z","kind":"command_output","operation":"id","output":"pulse-agent\n","output_sha256":"34d6cc22cb99bd7b3aca0e87e15484537e7d6d1c915333fee99537265fd04271"} +{"sequence":75,"event_id":"event-0075","observed_at":"2026-08-30T18:12:04.173147282Z","kind":"command_output","operation":"systemctl","output":"active\n","output_sha256":"45df5ad5e0ecfa54d3226343e0e6857337494ba6e32f189d1174070665d8c659"} +{"sequence":76,"event_id":"event-0076","observed_at":"2026-08-30T18:12:04.175360664Z","kind":"command_output","operation":"systemctl","output":"active\n","output_sha256":"45df5ad5e0ecfa54d3226343e0e6857337494ba6e32f189d1174070665d8c659"} +{"sequence":77,"event_id":"event-0077","observed_at":"2026-08-30T18:12:04.285974475Z","kind":"command_output","operation":"systemctl","output":"active\n","output_sha256":"45df5ad5e0ecfa54d3226343e0e6857337494ba6e32f189d1174070665d8c659"} +{"sequence":78,"event_id":"event-0078","observed_at":"2026-08-30T18:12:04.285982642Z","kind":"scenario_result","scenario":"action_runner_self_revoke","claims":["exact_runner_binding_revoked"],"observations":{"collector_continuity":true,"revocation_count":1},"summary":"uninstall revoked the exact host binding and removed only runner state; collector/helper continuity remained healthy","output":""} +{"sequence":79,"event_id":"event-0079","observed_at":"2026-08-30T18:12:04.289275485Z","kind":"command_output","operation":"systemctl","output":"pulse-agent\n","output_sha256":"34d6cc22cb99bd7b3aca0e87e15484537e7d6d1c915333fee99537265fd04271"} +{"sequence":80,"event_id":"event-0080","observed_at":"2026-08-30T18:12:04.293590328Z","kind":"command_output","operation":"systemctl","output":"5955\n","output_sha256":"08b943ce091ddaaeb86d43519d1dc5294fc37aa857345270f44bfda34b7abcdc"} +{"sequence":81,"event_id":"event-0081","observed_at":"2026-08-30T18:12:04.297029843Z","kind":"command_output","operation":"systemctl","output":"\n","output_sha256":"01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b"} diff --git a/frontend-modern/public/docs/AGENT_SECURITY.md b/frontend-modern/public/docs/AGENT_SECURITY.md index d51c67e2b..f07a36007 100644 --- a/frontend-modern/public/docs/AGENT_SECURITY.md +++ b/frontend-modern/public/docs/AGENT_SECURITY.md @@ -196,25 +196,30 @@ or generic command path. | Platform or capability | Preferred boundary | Safe-profile behavior | Qualification and default implication | Residual owner and removal condition | |---|---|---|---|---| | Proxmox VE/PBS/PMG inventory, status, storage, and ordinary metrics | API-only connection with a narrowly scoped token; no host agent | No collector, helper, or runner authority is required for this data | Supported independently of the safe host-agent profile; it does not prove host-local SMART, LXC filesystem, or action parity | `agent-lifecycle`: keep API permissions and returned telemetry covered by provider tests | -| Standard Linux systemd host telemetry and collector update | Unprivileged `pulse-agent` plus the root-owned typed helper | Core `/proc`, filesystem, network, RAID, and hwmon telemetry stays in the collector; helper-backed signed update activation is implemented but its live activation/recovery transaction is not qualified | **Qualified on disposable Ubuntu 24.04.4 arm64 at committed main** for install, migration, explicit/automatic profile rollback, helper health, reporting continuity, and process/credential separation. The receipt's ordinary update ran under the downgraded root monitoring profile and does not prove `agent_update.activate.v1`, executable-digest commit, watchdog rollback, interrupted recovery, or last-known-good restoration. Remains opt-in pending those live scenarios, exact-RC reproduction, and external review | `deployment-installability` and `security-privacy`: qualify helper activation/failure/recovery from the designated release candidate and accept the external boundary review | +| Standard Linux systemd host telemetry and collector update | Unprivileged `pulse-agent` plus the root-owned typed helper | Core `/proc`, filesystem, network, RAID, and hwmon telemetry stays in the collector; helper-backed signed update activation is implemented but its live activation/recovery transaction is not qualified | **Qualified on disposable Ubuntu 24.04.4 arm64 at committed main `defc24af837b91428fbee939d09cd31e9559fb4f`** for install, migration, explicit/automatic profile rollback, helper health, reporting continuity, and process/credential separation. The schema-v4 receipt's ordinary update ran under the downgraded root monitoring profile and does not prove `agent_update.activate.v1`, executable-digest commit, watchdog rollback, interrupted recovery, or last-known-good restoration. Remains opt-in pending those live scenarios, exact-RC reproduction, and external review | `deployment-installability` and `security-privacy`: qualify helper activation/failure/recovery from the designated release candidate and accept the external boundary review | | Linux SMART telemetry | `smart.snapshot` through the no-network helper; no caller-selected device or arguments | Implemented, unqualified on representative physical disks. Helper failure omits/degrades SMART only; the collector does not retry as root | Does not yet justify SMART parity or a default change | `agent-lifecycle`: record live SATA, SAS/controller, USB bridge, and NVMe evidence, including standby, permission failure, timeout, and partial-data cases | | Proxmox node-local LXC filesystem telemetry | `proxmox.lxc_filesystems` through the no-network helper using fixed bounded `pct` operations | Implemented, unqualified on a representative PVE node. Helper failure omits/degrades this snapshot only | Does not yet justify Proxmox host-agent parity or a default change | `agent-lifecycle`: record live running/stopped LXC, mount, timeout, output-bound, and helper-loss behavior on supported PVE versions | | Rootful Docker or Podman inventory | No direct collector access to a root-equivalent daemon socket | **Unavailable in the safe profile.** Migration disables the provider visibly. A closed helper `container.inventory` operation exists, but collector integration and live parity are not qualified | Rootful container parity is an explicit default blocker; the legacy/root profile is not safe-profile evidence | `agent-lifecycle`: either integrate and qualify bounded helper inventory or retain the explicit degradation permanently | | Collector-owned rootless Docker or Podman | Direct access only to one usable runtime socket owned by the `pulse-agent` UID | Implemented, unqualified live. Ambiguous, root-owned, unreadable, unwritable, or unavailable sockets disable container monitoring | Does not yet justify container-runtime parity or a default change | `deployment-installability`: record fresh install, migration, restart, socket-loss, ambiguity, and telemetry parity on both rootless Docker and rootless Podman | -| Separate runner package update and package-cache cleanup | Root-owned `pulse-agent-runner`, host-bound action credential, typed request, postcondition, and durable receipt | A real verified apt-cache mutation, stale-fingerprint refusal, replay, and self-revocation are present in the committed-main systemd receipt. Two-phase credential activation and nonce-bound readiness are implemented but need fresh production-path qualification | Qualified only for the exercised apt-cache mutation; the receipt does not prove the current Router/TLS/durable-persistence credential lifecycle, every runner operation, or an exact release candidate | `agent-lifecycle` and `api-contracts`: reproduce through the production Router over HTTPS from the RC, including failed activation/rollback and representative package-update success/failure/cancellation evidence | +| Separate runner package update and package-cache cleanup | Root-owned `pulse-agent-runner`, host-bound action credential, typed request, postcondition, and durable receipt | The schema-v4 committed-main systemd receipt records a real verified apt-cache mutation, stale-fingerprint refusal, replay, nonce-bound readiness, exact credential rotation, and self-revocation | Qualified only for those exercised fixture paths; the receipt does not prove the production Router/TLS/durable-persistence credential lifecycle, failed activation rollback, every runner operation, or an exact release candidate | `agent-lifecycle` and `api-contracts`: reproduce through the production Router over HTTPS from the RC, including failed activation/rollback and representative package-update success/failure/cancellation evidence | | Separate runner Proxmox guest and container lifecycle/update actions | Root-owned runner with closed typed protocols; never the monitoring collector | Implemented, unqualified on representative PVE and container-runtime targets | No live-provider action-parity claim and no default change | `agent-lifecycle`: record target-bound success, stale-state refusal, cancellation, reconnect/replay, and independent postconditions on disposable real targets | | Appliance, non-systemd, Windows, and macOS host-agent profiles | Platform API where sufficient; otherwise an explicitly named legacy/full-trust profile | **Unavailable for safe-profile apply.** The installer fails closed instead of silently installing a root-equivalent profile | Excluded from the Linux safe-profile claim | `deployment-installability`: land a platform-specific service, filesystem, update, helper, migration, rollback, and live-proof contract before marking that platform supported | The committed-main Linux evidence is recorded in `docs/release-control/v6/internal/records/secure-agent-runtime-qualification-foundation-2026-08-30.md`. -That receipt is artifact-bound operator self-attestation, not an independently -authenticated external assessment. The safe profile therefore remains opt-in. -The current attester requires a fresh schema-v4 run: it expands a committed -production-source manifest, requires exact source membership, binds ordered -scenario claims to a retained secret-free JSONL transcript, validates typed -receipt/report chronology, and hashes the intended repository record path -inside the receipt. The existing v3 record remains historical and is not -silently promoted to this stronger evidence class. +The current schema-v4 receipt qualifies exact committed main +`defc24af837b91428fbee939d09cd31e9559fb4f`. Its attestation verifies a +345-source production manifest, clean exact-commit identities for all four +artifacts, twelve ordered scenario claims, and a retained secret-free JSONL +transcript containing 81 events. The receipt, transcript, and attestation have +SHA-256 digests +`58da80f7d75d414c12cf6632bd895b821ce759625e7d00ae00c16d56204b1e76`, +`616681aee38202ed922880288b730cd85f746e081f8f9d45bb2d570e48b49f8c`, and +`a48e855fdd2dcbc0cf91717dfaed22f942320c9661dd9b9e8f8f8e97f45d654b`. +This remains artifact-bound operator self-attestation, not an independently +authenticated external assessment or production Router/TLS/durable-store +exercise. The existing v3 record remains historical. The safe profile +therefore remains opt-in. Monitoring never implies remediation. On the supported Linux systemd profile, an operator may separately enroll the typed action runner: