ecluse:ecluse-runtime
Safe HaskellNone
LanguageGHC2021

Ecluse.Runtime.Cve.Sync

Description

Advisory artifact sync and the write side of Ecluse.Core.Cve.Slot. Each mount retries at boot, then polls for new artifacts. An empty slot denies by default.

Synopsis

The injected transport

newtype DbEtag #

Constructors

DbEtag Text 

Instances

Instances details
Show DbEtag 
Instance details

Defined in Ecluse.Core.Cve.Types

Eq DbEtag 
Instance details

Defined in Ecluse.Core.Cve.Types

Methods

(==) :: DbEtag -> DbEtag -> Bool #

(/=) :: DbEtag -> DbEtag -> Bool #

data S3CveSource Source #

An S3-backed advisory-fetch source. newS3CveSource captures one amazonka Env, so every mount's CveFetch shares one credential discovery. The composition shell never sees it.

newS3CveSource :: Maybe AwsEndpoint -> IO S3CveSource Source #

Build an S3CveSource over one S3 amazonka env, honouring the resolved endpoint override.

s3CveFetchFor :: S3CveSource -> Text -> Text -> Int -> CveFetch Source #

A CveFetch against one bucket, object key, and byte cap, over the captured env.

One sync cycle

data SyncEnv Source #

Everything one ecosystem's sync task operates on.

Constructors

SyncEnv 

Fields

  • syncFetch :: CveFetch

    The transport for this ecosystem's object key.

  • syncEcosystem :: Ecosystem

    The ecosystem the artifact must verify as.

  • syncEpssRequirement :: EpssRequirement

    Whether this ecosystem requires successful EPSS enrichment.

  • syncDbPath :: FilePath

    The canonical on-disk artifact path (the stable per-ecosystem name).

  • syncSlot :: CveSlot

    The slot this task's swaps publish to.

  • syncStoreRef :: Text

    How the configured store reads back, for the reports that name where an artifact belongs.

The scheduled task

data SyncSchedule Source #

The task's timing: the boot burst's backoff delays and the steady poll interval, both in microseconds. The composition root ships bootBackoffDelays and the configured poll interval.

Constructors

SyncSchedule 

Fields

data SyncHooks Source #

What the shell hangs off one sync task. Both run inside the task, so neither may block it, and both must tolerate being called again.

Constructors

SyncHooks 

Fields

  • hookFirstSync :: IO ()

    Runs after every swap, so it must be idempotent.

  • hookPushAge :: IO ()

    Runs after every step, settled or not, so the push age is read on a poll that changed nothing.

runCveSync :: (MonadUnliftIO m, KatipContext m) => AdvisorySyncMetricsPort -> AdvisorySyncTracingPort -> SyncEnv -> SyncSchedule -> SyncHooks -> m () Source #

Retry at boot, then poll forever. A refused artifact ends the boot burst.

bootBackoffDelays :: [Int] Source #

The shipped boot-burst backoff: an immediate first attempt, then a retry after each delay, then the burst concedes to the steady poll. The poll interval, not this, is the operator's knob.

absentReportInterval :: Int Source #

The shipped gap, in microseconds, between repeats of the unloaded-database and fetch-failure reports. The rules' outage reminder paces on the same gap.