Initial server source import

This commit is contained in:
sashatrask
2026-09-30 20:30:56 +03:00
commit 170dd941b9
498 changed files with 261563 additions and 0 deletions
@@ -0,0 +1,31 @@
## Why
Large Docker images currently monopolize both Docker scan workers until the 600-second deadline and can retry indefinitely because timeout completion resets the target attempt counter. Over the measured 48-hour window, hard timeouts consumed about 32.7 worker-hours while repeated partial scans produced no usable LLM access, so full-image retries are reducing useful throughput without providing proportional coverage.
## What Changes
- Enforce the existing bounded target-attempt policy for Docker timeouts while preserving findings emitted before termination.
- Resolve immutable image manifests into image configuration and ordered content-addressed layers with bounded size metadata.
- Scan image configuration and selected layer content under an explicit per-image byte budget instead of treating every image as an indivisible download.
- Deduplicate successful layer scans globally by immutable layer digest so shared base layers are not downloaded and scanned repeatedly.
- Prioritize upper application layers and small layers; record oversized or out-of-budget layers as explicit uncovered scope rather than silently claiming complete image coverage.
- Preserve the existing full-image path behind a rollout gate for controlled comparison and rollback.
- Repair currently deferred Docker targets whose timeout attempts were incorrectly reset.
## Capabilities
### New Capabilities
- `docker-layer-content-scanning`: Bounded, content-addressed Docker config and layer scanning with global deduplication, explicit coverage, safe retry limits, and controlled rollout against the existing full-image scanner.
### Modified Capabilities
None.
## Impact
- Affects Docker Registry manifest/blob access, immutable Docker target planning, scan queue state, result metadata, and Docker source configuration.
- Adds durable PostgreSQL state for layer identities, leases, coverage, attempts, and image-to-layer plans.
- Reuses the existing authenticated Docker account pool, scan-slot limiter, Windows Job containment, bundle ingestion, findings projection, and keycheck pipeline.
- Requires an offline additive runtime-safety migration before enabling production layer scanning.
- Does not change Git, Hugging Face, keycheck classification, global guaranteed scan-slot capacity, or secret persistence boundaries.