Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
23 commits
Select commit Hold shift + click to select a range
2277323
storage: bounded in-place retry of the commit step on write-lock cont…
ConstanzeTU Aug 28, 2026
78e5854
storage: serialize SQLite writes on an in-process gate and make commi…
ConstanzeTU Aug 28, 2026
fd86188
storage: add SQLite write-path duress contract and torture suite
ConstanzeTU Aug 28, 2026
dce1692
storage: address review — gate rejects canceled contexts, blank serie…
ConstanzeTU Aug 28, 2026
68e5871
types(rogueartifact): add RogueArtifact aggregated type (pre-codegen)
ConstanzeTU Aug 25, 2026
c86e850
codegen(rogueartifact): generated deepcopy/conversion/openapi/protobu…
ConstanzeTU Aug 25, 2026
8566b2c
registry(rogueartifact): serve RogueArtifact via the aggregated API
ConstanzeTU Aug 25, 2026
1e50780
rogueartifact: table columns from labels + storage round-trip regress…
ConstanzeTU Aug 25, 2026
ef338dd
storage: persist profile status transitions that arrive without new p…
ConstanzeTU Aug 27, 2026
abdd15c
fix(validation): accept 'failed' container profile status
ConstanzeTU Aug 28, 2026
30846c9
fix(dynamicpathdetector): empty path must not mint '.'
ConstanzeTU Aug 29, 2026
012aba6
fix(storage): explicit port 0 must survive the gob payload round-trip
ConstanzeTU Aug 29, 2026
2d88bc4
fix(apis): regenerate conversions for the NetworkPort internal-only f…
ConstanzeTU Aug 30, 2026
f2a1f02
fix(storage): read-path self-heal must never block on the write gate
ConstanzeTU Aug 30, 2026
828e305
fix(storage): refresh the CollapseConfiguration cache off the caller'…
matthyx Sep 8, 2026
420eed5
fix: defer the consolidation transaction's end so a panic rolls it ba…
matthyx Sep 8, 2026
7fc16b5
fix(storage): use GetContainerProfileMetadataNoLock in ComputeAggrega…
matthyx Sep 3, 2026
e800f98
fix(storage): generate metadata.uid for new ContainerProfiles
matthyx Aug 31, 2026
277af94
storage: adapt the cherry-picked upstream tests to this fork's write …
ConstanzeTU Sep 10, 2026
0b6c6b0
Revert the four upstream cherry-picks and their test adaptation
ConstanzeTU Sep 10, 2026
16924fa
dynamicpathdetector: a pid and a tid are identifiers, not names
ConstanzeTU Sep 10, 2026
f56446a
dynamicpathdetector: pin the named procfs reads against the agent's r…
ConstanzeTU Sep 10, 2026
1798f93
fix(dynamicpathdetector): keep * when a ⋯ sits at the same node
entlein Sep 12, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions pkg/apis/softwarecomposition/network_types.go
Original file line number Diff line number Diff line change
Expand Up @@ -50,6 +50,12 @@ type NetworkPort struct {
Name string // protocol-port
Protocol Protocol
Port *int32
// PortZero marks an explicit Port==0 across the gob payload round-trip:
// gob flattens the pointer and omits zero values, so *0 decodes as nil
// (turning a user-authored port-0 literal into an any-port stanza).
// Internal-only; stamped on save, consumed on read, never converted out.
// json:"-": gob carries it (gob ignores json tags); JSON views must not.
PortZero bool `json:"-"`
}

func (p NetworkPort) String() string {
Expand Down
2 changes: 2 additions & 0 deletions pkg/apis/softwarecomposition/register.go
Original file line number Diff line number Diff line change
Expand Up @@ -66,6 +66,8 @@ func addKnownTypes(scheme *runtime.Scheme) error {
&VulnerabilitySummary{},
&VulnerabilitySummaryList{},
&ContainerProfile{},
&RogueArtifact{},
&RogueArtifactList{},
&ContainerProfileList{},
&OpenVulnerabilityExchangeContainer{},
&OpenVulnerabilityExchangeContainerList{},
Expand Down
55 changes: 55 additions & 0 deletions pkg/apis/softwarecomposition/rogueartifact_types.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
package softwarecomposition

import metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"

// RogueArtifact is the in-cluster, discoverable record of a container that is
// not covered by a verified authored profile. One object per firing container;
// node-agent creates it on fire and transitions it to Healed on governance.
// +genclient
// +k8s:deepcopy-gen:interfaces=k8s.io/apimachinery/pkg/runtime.Object
type RogueArtifact struct {
metav1.TypeMeta
metav1.ObjectMeta

Spec RogueArtifactSpec
Status RogueArtifactStatus
}

type RogueArtifactSpec struct {
// State is why the container is uncovered: rogue (no profile label at all),
// unbound (label set but resolves to no profile), unsigned (a profile
// resolves but is unsigned while signature verification is on).
State string
// Learning is true while the container is in kubescape.io/learning mode:
// the effective profile is empty (deny-all, alerting) while node-agent
// records the real behaviour in the background.
Learning bool
// Reason is a human-readable detail (the diverging binding name, verify
// error class, etc.).
Reason string
WorkloadName string
WorkloadKind string
WorkloadUID string
ContainerName string
ContainerID string
PodName string
PodUID string
NodeName string
}

type RogueArtifactStatus struct {
// Phase is Firing while the container remains uncovered, Healed once it is
// governed by a verified profile. A departed (e.g. completed Job) object
// keeps its last Phase until the TTL sweep.
Phase string
FiredAt metav1.Time
HealedAt metav1.Time
}

// +k8s:deepcopy-gen:interfaces=k8s.io/apimachinery/pkg/runtime.Object
type RogueArtifactList struct {
metav1.TypeMeta
metav1.ListMeta

Items []RogueArtifact
}
14 changes: 14 additions & 0 deletions pkg/apis/softwarecomposition/v1beta1/conversion.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
package v1beta1

import (
"github.com/kubescape/storage/pkg/apis/softwarecomposition"
conversion "k8s.io/apimachinery/pkg/conversion"
)

// Convert_softwarecomposition_NetworkPort_To_v1beta1_NetworkPort is manual:
// the internal type carries the gob-only PortZero marker (no v1beta1 peer),
// which must never leak to API clients. Restoring Port from the marker is the
// storage decode layer's job, not conversion's.
func Convert_softwarecomposition_NetworkPort_To_v1beta1_NetworkPort(in *softwarecomposition.NetworkPort, out *NetworkPort, s conversion.Scope) error {
return autoConvert_softwarecomposition_NetworkPort_To_v1beta1_NetworkPort(in, out, s)
}
Loading