Merge pull request #352 from f3rs3n/fix/audit-safety-wording

fix: clarify audit side effects and boot-check scope
This commit is contained in:
MacRimi
2026-09-18 18:47:23 +02:00
committed by GitHub
6 changed files with 177 additions and 14 deletions
+4 -3
View File
@@ -1,8 +1,9 @@
"""Check registry and evaluation engine for Audit & Report.
A check declares an identifier, an area and the severity its failure
carries, and returns the outcome of one evaluation. Checks never modify
the host: an assessment reads, it does not act.
carries, and returns the outcome of one evaluation. Assessments inspect
host settings and health. They can write reports and logs; boot status
checks can temporarily mount EFI system partitions.
Identifiers are ``<area>.<slug>`` and are frozen once published. Rewording
a title never changes the identifier, because the accepted-risk register
@@ -185,7 +186,7 @@ class AuditContext:
return self._cache[key]
def run(self, cmd: list[str], timeout: int = 10, allowed_codes=(0,)) -> tuple[int, str]:
"""Run a read-only command, returning exit code and output."""
"""Run an inspection command, returning exit code and output."""
key = "cmd:" + json.dumps(cmd)
self.source(key)
if key in self._cache:
+3 -3
View File
@@ -2785,8 +2785,7 @@ def _update_chain(ctx):
inherits the age of that picture.
Whether each repository can still be reached is not tested: finding
out means refreshing the indexes, and an assessment that only reads
does not do that.
out means refreshing the indexes, which this check does not do.
"""
# pkgcache.bin is rebuilt from files already on disk, so its date
# says nothing about contacting a repository. These three do, in
@@ -3392,7 +3391,8 @@ def _boot_loader(ctx):
evidence += ("\nEach partition is an EFI system partition Proxmox keeps in "
"step so the host survives losing any one boot disk. The "
"kernel each would start is read from the tool's own report; "
"no partition is mounted and no boot is attempted.")
"proxmox-boot-tool status can temporarily mount EFI system partitions; "
"no boot is attempted.")
affected = []
for message in problems:
+5 -4
View File
@@ -4,10 +4,11 @@
ProxMenux Audit Routes
Flask blueprint for the Audit & Report assessment engine.
An assessment reads the host and records findings; it never modifies
anything. The run endpoint is therefore the only POST that does real
work, and it is deliberately serialised: two concurrent assessments would
compete for the same collectors without producing a better answer.
An assessment inspects host settings and health and records findings.
It can write reports and logs; boot status checks can temporarily mount
EFI system partitions. Assessment runs are deliberately serialised: two
concurrent assessments would compete for the same collectors without
producing a better answer.
"""
import threading