PCs now report enforcement results back to shopdb, closing the desired-vs-observed loop. - POST /api/geenforce/report (geenforce.report service token): each cycle a PC posts the published version it applied, install/skip/fail/filtered counts, and per-entry outcomes. - Two tables: manifestenforcementreports (latest-per-host + history: applied version, enforcer version, counts, derived status ok/selfhealed/failed) and manifestenforcementresults (per entry: action installed/skipped/failed, selfhealed flag, exit code, warning/error message). - RECEIVED: reports carry the applied version; the admin view derives receivedlatest by comparing it to the scope's current published version, so the fleet view shows which PCs picked up an update. - SELF-HEAL: per-entry action captures drift correction (installed when it should already be present) vs skipped (already good) vs failed, with messages. - Admin reads: GET /reports (fleet compliance rollup) and GET /reports/<id> (per-entry detail). New geenforce.report permission. - Tables added to the (undeployed) 0001 baseline; geenforce.post_report is a service-token endpoint so it is exempt from the JWT authz sweep, like the collector blueprint. 8 reporting tests; full suite green. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
46 lines
978 B
Python
46 lines
978 B
Python
"""GE-Enforce plugin models."""
|
|
|
|
from .manifest import (
|
|
ManifestScope,
|
|
ManifestEntry,
|
|
ManifestEntryPcType,
|
|
ManifestEntryHostname,
|
|
ManifestEntryMachineNumber,
|
|
ManifestInUseCheck,
|
|
ManifestInUseCheckProcess,
|
|
ManifestPublishedVersion,
|
|
ManifestPayload,
|
|
ManifestEnforcementReport,
|
|
ManifestEnforcementResult,
|
|
PcTypeAlias,
|
|
PHASES,
|
|
ENTRY_TYPES,
|
|
REG_TYPES,
|
|
PAYLOAD_SOURCES,
|
|
DETECTION_METHODS,
|
|
APPLY_MODES,
|
|
INUSE_BEHAVIORS,
|
|
)
|
|
|
|
__all__ = [
|
|
'ManifestScope',
|
|
'ManifestEntry',
|
|
'ManifestEntryPcType',
|
|
'ManifestEntryHostname',
|
|
'ManifestEntryMachineNumber',
|
|
'ManifestInUseCheck',
|
|
'ManifestInUseCheckProcess',
|
|
'ManifestPublishedVersion',
|
|
'ManifestPayload',
|
|
'ManifestEnforcementReport',
|
|
'ManifestEnforcementResult',
|
|
'PcTypeAlias',
|
|
'PHASES',
|
|
'ENTRY_TYPES',
|
|
'REG_TYPES',
|
|
'PAYLOAD_SOURCES',
|
|
'DETECTION_METHODS',
|
|
'APPLY_MODES',
|
|
'INUSE_BEHAVIORS',
|
|
]
|