Source-scope incident fingerprints for ingested findings (before remote actuation) #1
Labels
No labels
correctness
coverage
milestone:M4
polish
security
tech-debt
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
public/warden#1
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
From the M2 whole-branch review (deferred; pre-existing since the NATS findings ingest).
An incident fingerprint is
default_fingerprint(check_id, subject)—sourceis excluded. A bus-authorized sensor can publish a finding whose(check_id, subject)collides with a local detector's or another sensor's incident; astatus: okcollision would resolve/suppress that incident. Not a regression (legacyWARDEN_NATS_FINDINGS_SUBJECThad the same shape); acceptable while remediation is local, but MUST be resolved before remote actuation is driven off ingested findings.Fix: source-scoped fingerprints for ingested findings, or a per-sensor allowlist of assertable
check_ids. Seenats_bus.decode_finding,model.default_fingerprint.__probe__ delete meto Source-scope incident fingerprints for ingested findings (before remote actuation)Fixed on main (ships in v0.17.0). default_fingerprint gains an optional source arg: sourceless (local) digest is byte-identical to before and locked by a hardcoded-digest guard test; a non-empty source (ingested finding, source bound to the transport subject) gets its own fingerprint namespace via the existing null-byte separator. The wire fingerprint field is never read — always recomputed locally from validated (check_id, subject, source), so a sensor cannot forge another source’s fingerprint. Store-level test proves sensor-B’s ok cannot resolve sensor-A’s (or a local detector’s) incident. 588 tests.