feat: delta runs, signed and proven rounds, one honest progress bar, gentle by default - #68
Merged
Merged
Conversation
…gentle by default Repeat runs recompute only what changed: - cached parses and stored results are keyed on a generated fingerprint of the parsing and analysis code, not the release number - staleness is decided on the evidence's content, not manifest mtime - the collect-time host witness refreshes the per-artifact overlay instead of fully parsing every transcript; analysis decodes events once - per-artifact content scans are memoized (authenticated with the machine key); rule-pack regexes get an exact case-folding literal prefilter and event subjects are prepared once per scope Rounds are signed with a per-machine key, anchored outside the case and proven (signature, anchor, quick verify) before the next round is added; failures are recorded in the round and exit 4. Rounds are transactional: an unsealed round is rolled back to the last seal and logged as round_aborted. The reused overlay is integrity-checked (segment and event hashes, MAC over its state). One progress display for the whole run with elapsed time and an ETA from this machine's timing history that counts down steadily. Gentle by default: lowered priority, capped workers and heap, paced reads, a pause under load and a free-disk floor. Fixes: run --sign signed before sealing; carried-forward records dropped their inode/ctime so alternate runs re-read everything; retiring excluded records forced a full re-parse on every analysis; carried-forward bytes made the collect ETA collapse to zero. Co-Authored-By: Claude <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Repeat
agentdfir runnow recomputes only what changed. Every round is signed and proven before the next one is added, one progress display covers the whole run, and the run is gentle on the machine by default.Measured on a copy of a real case (12.5k artifacts, 3.4 GB evidence, 360k events):
runDelta
internal/fingerprint), not the release number.TestCurrentfails if the fingerprint is stale; regenerate it withgo generate ./internal/fingerprint.runreuses the stored results.internal/artmemo).Integrity
anchors.jsonlfile outside the case, and the seal digest is printed.casepkg.ReopenChecked, after the lock is taken and before anything is written). A failure is recorded in the round and the run exits with code 4.SEAL.sigis archived for every round.round_aborted.Progress and resource use
internal/progress: one bar for the whole run, with elapsed time and an ETA taken fromperf.jsonlhistory that counts down steadily.internal/gentle: lowered priority, capped workers and heap, paced reads, a pause under load, and a free-disk floor (exit 5).Fixes
run --signsigned before sealing.Verification
gofmt,go vetandgo test -race ./...are green on macOS.Generated with Claude Code