Conversation
Add cargo_inventory and cargo_config_audit (schema_version 1) to enterprise telemetry in a new cargo_scan phase after go_scan. The inventory reads Cargo.toml declarations with workspace inheritance, Cargo.lock formats 3 and 4, the registry cache, Git checkouts, vendored sources and local registries, and cargo install receipts. The audit reads .cargo/config(.toml) files, their includes and an allowlisted process environment per invocation context, with findings cargo-001..cargo-004. Everything is static: no cargo, rustc or git command, shell or network call. Reads go through guarded, bounded executor file methods, URL credentials are redacted on the device, credentials files are checked for presence only, and any refusal, failure or limit marks the affected source partial. Bumps go-toml/v2 to v2.4.3.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What does this PR do?
Adds Rust/Cargo evidence to enterprise telemetry as two optional sections,
cargo_inventoryandcargo_config_audit(eachschema_version: 1), in a newcargo_scanphase right aftergo_scan. Both are full bounded snapshots sent on every run. The shape mirrors the Go scanner and reuses its guards, source IDs and budgets.cargo_inventory(static, no Rust toolchain needed)Cargo.toml: normal, dev, build and target-specific tables; aliases, features, optional and explicitdefault-features; registry, Git and path selectors. Workspace inheritance is applied; onlyworkspace.dependenciesentries that members inherit are followed.exclude, in-root path dependencies and explicitpackage.workspace. Membership that can't be established isworkspace_unresolved.Cargo.lockformats 3 and 4, once per workspace root, honoringresolver.lockfile-path. Other formats areunsupported_format.registry/cache+registry/src), Git checkouts (full commit only from a 40/64-hex.git/HEAD), vendored directories, local registries and.crates.toml/.crates2.jsoninstall receipts with bin presence.Cargo.lockand.cargo-checksum.json, alwaysnot_verified.cargo_config_audit.cargo/configand.cargo/config.tomlper project and ancestor inside the search roots, the Cargo home config, includes (depth and count bounded, cycles flagged), and an allowlisted process environment, all resolved per invocation context in precedence order (config_source_ids).cargo-001..cargo-004: HTTP registry/source index, insecure Git source, plaintext token in config,http.check-revoke = false.Safety properties
cargo,rustcorgitcommand, shell, network call, PATH search orUserAwareExecutor. Every read goes through guarded, bounded executor file methods;.cratearchives are read in memory with header, size and path-traversal bounds.include_tcc_protected; there is no Cargo TCC exception.[patch."https://…"]), tokens show only as configured, and custom credential providers becomecustomwith arguments dropped.partialwith a reason code. The record budget is charged during collection, and every owner left unfinished is markedrecord_limit. The combined output is capped at 16 MiB with a status envelope.Other:
github.com/pelletier/go-toml/v2v2.3.1 → v2.4.3. Communityscanoutput is unchanged.Contract:
internal/model/testdata/cargo_inventory_v1_golden.jsonholds IDs recomputed from its displayed paths, and it decodes strictly and round-trips byte-identically. For it to pass the Agent API validator, the API needs to:cached_package+vendor_unknownwhen the owner is alocal_registrysource;unsupportedwithpath_unresolved.Type of change
SCAN_COVERAGE.md,README.md)Testing
make smoke): pendinggo vet, golangci-lint (0 issues)go test ./... -race -count=1Also:
CGO_ENABLED=0builds for linux/amd64, darwin/arm64 and windows/amd64;go mod tidyshows no drift.Not yet done (release checks):
make smoke.cargo metadatareferences.Related Issues