Add first-party verdict and guards to tracker mapping
The tracker-pattern catalog was binary (linked to a vendor or not), so generic and first-party artifacts (loglevel keys, wallet-extension keys, an org's own trackers) were retried forever and, once one row was wrongly attributed, re-propagated to every organization with no re-check. Give catalog rows a terminal attribution verdict (UNDETERMINED, THIRD_PARTY, FIRST_PARTY): FIRST_PARTY short-circuits the whole mapping pipeline so the artifact is never attributed again. Gate deterministic vendor adoption behind a trust bar so only curated/operator rows auto-propagate; lower-confidence agent/heuristic rows are reused as hints and re-resolved, and an independent agent re-confirmation corroborates and promotes them. Make the mapping agent emit an evidence source and reject any attribution that lacks concrete evidence, and let it declare a first-party verdict. Skip the speculative agent for PRE_EXISTING-source patterns, whose low signal invites invented vendors. Add proboctl "ctp mark-first-party" and an --attribution list filter to audit and remediate existing wrong links, and a cursor rule documenting migration naming so the timestamp is taken from date -u, not invented. Signed-off-by: Émile Ré <emile@probo.com>
This commit is contained in:
@@ -36,6 +36,7 @@ func newCmdList(f *cmdutil.Factory) *cobra.Command {
|
||||
flagLinkedOrg string
|
||||
flagKeyword string
|
||||
flagState string
|
||||
flagAttribution string
|
||||
flagWithCommonThirdParty bool
|
||||
flagWithoutDescription bool
|
||||
flagSort string
|
||||
@@ -57,6 +58,7 @@ func newCmdList(f *cmdutil.Factory) *cobra.Command {
|
||||
cmd.Flags().StringVar(&flagLinkedOrg, "linked-org", "", "Filter to catalog rows linked to an organization's patterns (GID)")
|
||||
cmd.Flags().StringVar(&flagKeyword, "keyword", "", "Filter by pattern/description substring")
|
||||
cmd.Flags().StringVar(&flagState, "state", "", "Filter by enrichment state (queued, enriched, unenriched)")
|
||||
cmd.Flags().StringVar(&flagAttribution, "attribution", "", "Filter by attribution verdict (UNDETERMINED, THIRD_PARTY, FIRST_PARTY)")
|
||||
cmd.Flags().BoolVar(&flagWithCommonThirdParty, "with-common-third-party", false, "Filter by whether the pattern is linked to a common third party (true/false); ignored when not set")
|
||||
cmd.Flags().BoolVar(&flagWithoutDescription, "without-description", false, "Only patterns with a blank description")
|
||||
cmd.Flags().StringVar(&flagSort, "sort", "confidence", "Sort field: pattern, confidence, created, updated, attempted")
|
||||
@@ -93,7 +95,7 @@ func newCmdList(f *cmdutil.Factory) *cobra.Command {
|
||||
described = new(false)
|
||||
}
|
||||
|
||||
filter, err := buildListFilter(flagTrackerType, flagMatchType, flagKeyword, flagState, withCommonThirdParty, described)
|
||||
filter, err := buildListFilter(flagTrackerType, flagMatchType, flagKeyword, flagState, flagAttribution, withCommonThirdParty, described)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
@@ -229,7 +231,7 @@ func renderPatternTable(cmd *cobra.Command, f *cmdutil.Factory, patterns coredat
|
||||
return err
|
||||
}
|
||||
|
||||
table := clicmdutil.NewTable("ID", "TYPE", "MATCH", "PATTERN", "CONF", "STATE", "THIRD PARTY", "LAST ATTEMPT", "CREATED", "UPDATED")
|
||||
table := clicmdutil.NewTable("ID", "TYPE", "MATCH", "PATTERN", "CONF", "VERDICT", "STATE", "THIRD PARTY", "LAST ATTEMPT", "CREATED", "UPDATED")
|
||||
|
||||
for _, p := range patterns {
|
||||
thirdParty := ""
|
||||
@@ -248,6 +250,7 @@ func renderPatternTable(cmd *cobra.Command, f *cmdutil.Factory, patterns coredat
|
||||
string(p.MatchType),
|
||||
p.Pattern,
|
||||
fmt.Sprintf("%.2f", p.Confidence),
|
||||
string(p.Attribution),
|
||||
enrichmentState(p),
|
||||
thirdParty,
|
||||
lastAttempt,
|
||||
@@ -309,7 +312,7 @@ func parseOrderBy(sort, order string) (page.OrderBy[coredata.CommonTrackerPatter
|
||||
}
|
||||
|
||||
func buildListFilter(
|
||||
trackerType, matchType, keyword, state string,
|
||||
trackerType, matchType, keyword, state, attribution string,
|
||||
withCommonThirdParty, described *bool,
|
||||
) (*coredata.CommonTrackerPatternFilter, error) {
|
||||
filter := coredata.NewCommonTrackerPatternFilter()
|
||||
@@ -345,6 +348,15 @@ func buildListFilter(
|
||||
filter.WithState(&st)
|
||||
}
|
||||
|
||||
if attribution != "" {
|
||||
attr := coredata.CommonTrackerPatternAttribution(attribution)
|
||||
if !attr.IsValid() {
|
||||
return nil, fmt.Errorf("invalid --attribution value %q: valid values are UNDETERMINED, THIRD_PARTY, FIRST_PARTY", attribution)
|
||||
}
|
||||
|
||||
filter.WithAttribution(&attr)
|
||||
}
|
||||
|
||||
if withCommonThirdParty != nil {
|
||||
filter.WithLinked(withCommonThirdParty)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user