| Safe Haskell | None |
|---|---|
| Language | GHC2021 |
Ecluse.Core.Rules.Freshness
Description
How old the advisory push behind a CVE-based deny may be. The clock is the published object's own timestamp, which Ecluse.Core.Cve.Slot carries, so a recompile of unchanged bytes still moves it and a restart does not reset it. What a source says about its own data is diagnostic and is never read here. Ecluse.Core.Rules applies the reading to a prepared rule.
Synopsis
- data MaxAdvisoryAge = MaxAdvisoryAge {}
- data AdvisoryAgeBasis
- maxAdvisoryAgeFor :: Maybe NominalDiffTime -> [Rule] -> MaxAdvisoryAge
- data AdvisoryPublication
- data AdvisoryAge = AdvisoryAge {}
- data AdvisoryFreshness
- assessAdvisoryAge :: MaxAdvisoryAge -> UTCTime -> AdvisoryPublication -> AdvisoryFreshness
- ageAlarmStep :: Bool -> AdvisoryFreshness -> (Bool, Maybe AdvisoryAge)
The effective maximum
data MaxAdvisoryAge Source #
The maximum push age one mount's CVE-based denies accept, and where the value came from. The basis is carried so the boot log can report it beside the number.
Constructors
| MaxAdvisoryAge | |
Fields
| |
Instances
| Show MaxAdvisoryAge Source # | |
Defined in Ecluse.Core.Rules.Freshness Methods showsPrec :: Int -> MaxAdvisoryAge -> ShowS # show :: MaxAdvisoryAge -> String # showList :: [MaxAdvisoryAge] -> ShowS # | |
| Eq MaxAdvisoryAge Source # | |
Defined in Ecluse.Core.Rules.Freshness Methods (==) :: MaxAdvisoryAge -> MaxAdvisoryAge -> Bool # (/=) :: MaxAdvisoryAge -> MaxAdvisoryAge -> Bool # | |
data AdvisoryAgeBasis Source #
Where an effective maximum came from.
Constructors
| AgeConfigured | The operator set |
| AgeBeforeQuarantine NominalDiffTime | Derived to land |
| AgeFloor | The floor, which no derivation goes below. |
Instances
| Show AdvisoryAgeBasis Source # | |
Defined in Ecluse.Core.Rules.Freshness Methods showsPrec :: Int -> AdvisoryAgeBasis -> ShowS # show :: AdvisoryAgeBasis -> String # showList :: [AdvisoryAgeBasis] -> ShowS # | |
| Eq AdvisoryAgeBasis Source # | |
Defined in Ecluse.Core.Rules.Freshness Methods (==) :: AdvisoryAgeBasis -> AdvisoryAgeBasis -> Bool # (/=) :: AdvisoryAgeBasis -> AdvisoryAgeBasis -> Bool # | |
maxAdvisoryAgeFor :: Maybe NominalDiffTime -> [Rule] -> MaxAdvisoryAge Source #
One mount's effective maximum. An explicit value is final, above and below the derivation. One mount's rules are read alone, so another ecosystem's quarantine cannot set this limit.
Reading one push
data AdvisoryPublication Source #
What a slot says about the serving artifact's publication. The undated case is separate because a generation whose age cannot be established is not the same as none serving at all.
Constructors
| NoGeneration | Nothing is serving yet, so there is no artifact to age. |
| PublishedAt UTCTime | The published object's own timestamp. |
| UndatedGeneration | A generation is serving and the store reported no publication time for it. |
Instances
| Show AdvisoryPublication Source # | |
Defined in Ecluse.Core.Rules.Freshness Methods showsPrec :: Int -> AdvisoryPublication -> ShowS # show :: AdvisoryPublication -> String # showList :: [AdvisoryPublication] -> ShowS # | |
| Eq AdvisoryPublication Source # | |
Defined in Ecluse.Core.Rules.Freshness Methods (==) :: AdvisoryPublication -> AdvisoryPublication -> Bool # (/=) :: AdvisoryPublication -> AdvisoryPublication -> Bool # | |
data AdvisoryAge Source #
One reading of a push: when it landed, how old it is now, and the maximum it was read against. An audit line and an alarm both render this, so neither can report a different number.
Constructors
| AdvisoryAge | |
Fields | |
Instances
| Show AdvisoryAge Source # | |
Defined in Ecluse.Core.Rules.Freshness Methods showsPrec :: Int -> AdvisoryAge -> ShowS # show :: AdvisoryAge -> String # showList :: [AdvisoryAge] -> ShowS # | |
| Eq AdvisoryAge Source # | |
Defined in Ecluse.Core.Rules.Freshness | |
data AdvisoryFreshness Source #
What a push permits. AdvisoryAging is still eligible: it is the early warning, raised at
half the maximum so an update outage surfaces while there is still time to act on it.
Constructors
| AdvisoryFresh | Within half the maximum, or nothing serving to age. |
| AdvisoryAging AdvisoryAge | Past half the maximum and still eligible. |
| AdvisoryStale AdvisoryAge | Past the maximum. CVE-based denial refuses, whatever its |
| AdvisoryUndated | A serving generation whose age cannot be established, which is unverified evidence and refuses on the same terms as an expired one. |
Instances
| Show AdvisoryFreshness Source # | |
Defined in Ecluse.Core.Rules.Freshness Methods showsPrec :: Int -> AdvisoryFreshness -> ShowS # show :: AdvisoryFreshness -> String # showList :: [AdvisoryFreshness] -> ShowS # | |
| Eq AdvisoryFreshness Source # | |
Defined in Ecluse.Core.Rules.Freshness Methods (==) :: AdvisoryFreshness -> AdvisoryFreshness -> Bool # (/=) :: AdvisoryFreshness -> AdvisoryFreshness -> Bool # | |
assessAdvisoryAge :: MaxAdvisoryAge -> UTCTime -> AdvisoryPublication -> AdvisoryFreshness Source #
Read one publication against a maximum: equal to it is eligible, and greater expires. Nothing serving is not aged here, leaving the ordinary absent-database path to decide.
ageAlarmStep :: Bool -> AdvisoryFreshness -> (Bool, Maybe AdvisoryAge) Source #
The early warning's next latch state, and the reading to report where this one crosses. An undated generation has no age to report and raises its own alarm where the artifact lands.