{"schema_version":"2026.06","bundle_schema_version":"2026.06","legacy_bundle_schema_versions":["2026.05"],"metadata_endpoint":"\/diagnostics\/collectors.json","safety_levels":{"level_0":"Level 0: Metadata only, generally safe.","level_1":"Level 1: System config, review recommended.","level_2":"Level 2: Security config, sensitive, review required.","level_3":"Level 3: Logs or identity\/auth data, strong redaction required.","level_4":"Level 4: Customer-provided sensitive bundle, never auto-share."},"bundle_contents":["bundle.json","manifest.json","checksums.sha256","collector.log","raw\/","normalized\/","reports\/","redaction\/","signatures\/"],"inspect_before_upload":["Open bundle.json and confirm the collector name, version, creation time, platform, sensitive-data flag, and handling state.","Review manifest.json and checksums.sha256 so the file list and hashes match the generated bundle.","Review redaction\/coverage.json and treat every raw artifact class as customer-confidential and internal-only.","Inspect raw\/ and normalized\/ for secrets, tokens, keys, customer data, or other material that should be redacted before controlled upload.","Read collector.log for command failures or skipped checks before sharing the bundle."],"collectors":[{"slug":"k8s-resource-audit","name":"Kubernetes Resource Audit","version":"0.2.0","status":"public-preview","safety_level":"Level 2: sensitive cluster configuration inventory; internal review required","summary":"Collects customer-confidential Kubernetes operations, optional usage samples, Pending-pod forensics, version-lifecycle, metadata-only security posture, and offline image supply-chain signals through the supported SaaS evaluator contract.","bundle_schema_version":"2026.06","bundle_contract_version":"1.0.0","contains_sensitive_data":true,"handling_state":"raw","upload_safe_after_review":true,"customer_shareable":false,"platforms":["Kubernetes"],"collects":["Cluster and namespace resource inventory","Exact Kubernetes, k3s, runtime, node OS, kernel, and kubelet versions","Warning events, best-effort k3s certificate status, and filtered security-relevant kubelet warnings","Workload requests, limits, replicas, and scheduling metadata","PodScheduled conditions, container waiting states, and namespace events","PVC, PV, StorageClass, service, ingress, and configuration references","Deployment, StatefulSet, DaemonSet, Job, and ReplicaSet owner chains","Privileged execution, host access, container security context, and service-account metadata","Pod Security Admission, NetworkPolicy, RBAC, service exposure, and ingress TLS metadata","Pod and controller image references, resolved digests, and pull failures","Optional normalized local Syft, Grype, Trivy, and version results","Service, ingress, storage, and configuration references","Optional node and per-container usage samples from the metrics API","Machine-readable capability coverage and advisor input index"],"does_not_collect":["Kubernetes Secret objects or values","Certificate private keys or certificate contents","Unfiltered node or workload journals","Workload environment values or arbitrary annotations","Registry credentials, Docker authentication configuration, or raw scan artifacts","Container filesystem contents","Live workload traffic"],"execution_policy":{"local_collection_only":true,"requires_explicit_upload_step":true,"permits_remediation":false,"metrics_sampling_optional":true,"notes":["The collector only reads through the selected kubectl context and never uploads a bundle.","Missing metrics or permissions are recorded as unavailable capabilities instead of failing the inventory bundle."]},"bundle_spec":{"bundle_metadata":["bundle_schema_version","bundle_contract_version","collector_name","collector_version","created_at","contains_sensitive_data","handling_state","upload_safe_after_review","capabilities"],"capabilities":["cluster_inventory","workload_inventory","resource_policy_inventory","network_storage_inventory","usage_samples","advisor_inputs"],"public_responsibilities":["Capture and hash inventory, request\/limit data, and optional usage samples.","Declare actual capability coverage for worker validation."],"private_responsibilities":["Generate summary CSVs, advisor recommendations, findings, and report variants.","Report possible and unavailable checks under a pinned ruleset."],"compatibility_matrix":[{"collector_version":"0.1.0","bundle_schema_version":"2026.05","bundle_contract_version":null,"evaluator_versions":["0.1.0"],"mode":"legacy-inferred"},{"collector_version":"0.1.0","bundle_schema_version":"2026.06","bundle_contract_version":null,"evaluator_versions":["0.1.0"],"mode":"legacy-inferred"},{"collector_version":"0.2.0","bundle_schema_version":"2026.06","bundle_contract_version":"1.0.0","evaluator_versions":["0.1.0"],"mode":"declared"}]},"sample_bundle":{"fixture_path":"..\/collectors\/k8s-resource-audit\/fixtures\/rich","data_classification":"synthetic-no-customer-data","description":"Synthetic raw-contract bundle that exercises every evaluator capability."},"security_posture":{"report_section":"Security Posture","collection_mode":"metadata-only","expected_agent_classification":"expected_privileged_agent","classification_annotation":"diagnostics.tacitsoft.dev\/security-classification","justification_annotation":"diagnostics.tacitsoft.dev\/privileged-justification","checks":["Privileged containers and privilege escalation","Non-root, capabilities, seccomp, and AppArmor posture","hostPath and host namespace access","Service-account token automount","Pod Security Admission and NetworkPolicy isolation","Service, ingress TLS, and admin\/dashboard exposure","High-privilege RBAC bindings"]},"redaction_coverage":{"path":"redaction\/coverage.json","coverage_schema_version":"2026.06","allowed_statuses":["raw","redacted","omitted","not_collected"],"artifact_classes":["cluster_metadata","namespace_metadata","node_and_topology_metadata","workload_and_pod_metadata","service_and_ingress_metadata","registry_and_image_metadata","storage_metadata","labels_and_annotations","resource_policy_metadata","configmap_names","collector_diagnostics","kubernetes_secrets"]},"handling_states":{"raw":"Sensitive unmodified output; internal-only.","reviewed":"Operator-inspected output; review alone does not redact content.","redacted":"Direct identifiers transformed; residual sensitivity may remain.","anonymized":"Identifiers irreversibly transformed with no raw coverage.","share_safe":"Explicitly approved, non-sensitive output with no raw coverage."},"download":{"artifact_url":"\/downloads\/collectors\/k8s-resource-audit\/0.2.0\/k8s-resource-audit-0.2.0.tar.gz","package_format":"tar.gz release bundle","checksum_sha256":"bf1cf65eac994d0caf9006ee8d2e4ffb7d327254e1d6b297347fde5323dbfa2e","checksum_url":"\/downloads\/collectors\/k8s-resource-audit\/0.2.0\/SHA256SUMS","release_notes_url":"\/downloads\/collectors\/k8s-resource-audit\/0.2.0\/README.md","signature_url":null,"signing_status":"checksum-published unsigned public preview","public_key_ref":"https:\/\/github.com\/tacitness\/tstools\/tree\/main\/signing"},"release_flow":{"channel":"public-preview","published_at":"2026-08-08","install_steps":["curl -fsSLO https:\/\/tacitsoft.dev\/downloads\/collectors\/k8s-resource-audit\/0.2.0\/k8s-resource-audit-0.2.0.tar.gz","curl -fsSLO https:\/\/tacitsoft.dev\/downloads\/collectors\/k8s-resource-audit\/0.2.0\/SHA256SUMS","sha256sum -c SHA256SUMS","tar -xzf k8s-resource-audit-0.2.0.tar.gz",".\/k8s-resource-audit\/install.sh --prefix .\/out\/k8s-resource-audit"],"dry_run_steps":[".\/k8s-resource-audit\/install.sh --dry-run --prefix .\/out\/k8s-resource-audit",".\/out\/k8s-resource-audit\/run-collector.sh --dry-run --output .\/out\/k8s-bundle"],"bundle_expectations":["The bundle is created locally under the output path and is not uploaded automatically.","bundle.json identifies collector, schema, and contract versions, cluster context, safety flags, and capability coverage.","Raw inventory is customer-confidential: bundle.json sets contains_sensitive_data=true and handling_state=raw.","upload_safe_after_review permits controlled internal upload only; it never makes raw content customer-shareable.","redaction\/coverage.json records raw, redacted, omitted, or not-collected status for every artifact class.","bundle.json and redaction\/coverage.json are included in the manifest and checksum chain.","Files left under raw\/ remain raw regardless of a conflicting coverage claim.","raw\/ contains sanitized Kubernetes metadata without Secret objects or values, environment values, arbitrary annotations, or live traffic capture.","Reports identify checks unavailable because optional collector capabilities were missing."]},"share_safe_sample_bundle":{"fixture_path":"tests\/Fixtures\/diagnostics\/k8s-resource-audit\/sample-share-safe-bundle","description":"Pseudonymous share-safe fixture with no raw customer identifiers."},"source_references":["docs\/collectors\/k8s-resource-audit-contract.md","docs\/strategies\/cmmc-stig-diagnostics-saas-platform.md","docs\/strategies\/tacitsoft-full-spectrum-strategy-map.md"]},{"slug":"linux-baseline","name":"Linux Baseline","version":"0.1.0","status":"metadata-preview","safety_level":"Level 3: host configuration and hardening signals","summary":"Collects Linux host baseline facts used to assess hardening posture before deeper compliance mapping.","platforms":["Ubuntu","Debian-family Linux","RHEL-family Linux"],"collects":["OS release, kernel, package, service, and account posture metadata","Filesystem, mount, network listener, and firewall summaries","Selected security configuration files and normalized findings","Collector log, manifest, and checksums"],"does_not_collect":["Private keys or credential stores","User home directory contents","Application databases"],"download":{"artifact_url":null,"package_format":"shell collector bundle","checksum_sha256":"pending-release-sha256","signature_url":null,"signing_status":"placeholder-pending-signed-release","public_key_ref":"https:\/\/github.com\/tacitness\/tstools\/tree\/main\/signing"},"execution_policy":{"local_collection_only":true,"requires_explicit_upload_step":true,"permits_remediation":false,"privilege_profile":"Read-only baseline diagnostics with best-effort elevated reads for system configuration files.","notes":["Collector does not change packages, services, auth settings, firewall state, or kernel parameters.","Any upload or remediation action must be run as a separate operator-initiated step after local review."]},"bundle_spec":{"bundle_metadata":["bundle_schema_version","collector_name","collector_version","created_at","host_count","platform","contains_sensitive_data","upload_safe_after_review","customer_notes"],"collection_commands":[{"id":"os-release","command":"cat \/etc\/os-release","output":"raw\/os-release.txt","sensitive":false},{"id":"kernel-uname","command":"uname -a","output":"raw\/kernel-uname.txt","sensitive":false},{"id":"packages","command":"rpm -qa || dpkg-query -W","output":"raw\/packages.txt","sensitive":false},{"id":"sshd-config","command":"cat \/etc\/ssh\/sshd_config","output":"raw\/sshd\/sshd_config.txt","sensitive":true},{"id":"pam-common-auth","command":"cat \/etc\/pam.d\/common-auth","output":"raw\/pam\/common-auth.txt","sensitive":true},{"id":"auditd-config","command":"cat \/etc\/audit\/auditd.conf","output":"raw\/auditd\/auditd.conf.txt","sensitive":false},{"id":"sysctl-all","command":"sysctl -a","output":"raw\/sysctl\/sysctl-a.txt","sensitive":false},{"id":"network-listeners","command":"ss -tulpn","output":"raw\/network\/ss-listening.txt","sensitive":true}],"raw_artifacts":["raw\/os-release.txt","raw\/kernel-uname.txt","raw\/packages.txt","raw\/systemd-enabled-services.txt","raw\/systemd-running-services.txt","raw\/accounts\/passwd.txt","raw\/accounts\/group.txt","raw\/sshd\/sshd_config.txt","raw\/pam\/common-auth.txt","raw\/auditd\/auditd.conf.txt","raw\/sysctl\/sysctl-a.txt","raw\/network\/ss-listening.txt","raw\/firewall\/ufw-status.txt"],"normalized_outputs":["normalized\/host-summary.json","normalized\/account-posture.json","normalized\/network-exposure.json","normalized\/hardening-signals.json"],"sensitivity_rules":[{"path":"raw\/accounts\/passwd.txt","classification":"internal","contains_secrets":false,"upload_requires_review":true,"notes":"Usernames and service-account naming should be reviewed before upload."},{"path":"raw\/sshd\/sshd_config.txt","classification":"restricted","contains_secrets":false,"upload_requires_review":true,"notes":"Auth and network policy details are allowed for diagnostics but should be customer-reviewed."},{"path":"raw\/network\/ss-listening.txt","classification":"restricted","contains_secrets":false,"upload_requires_review":true,"notes":"Listening ports and bound addresses may expose internal topology."},{"path":"normalized\/*.json","classification":"reviewed-diagnostic","contains_secrets":false,"upload_requires_review":false,"notes":"Normalized findings are intended to be safer upload candidates after bundle review."}]},"sample_bundle":{"fixture_path":"tests\/Fixtures\/diagnostics\/linux-baseline\/sample-bundle","description":"Dry-run Linux baseline bundle fixture for schema and upload-flow validation."},"source_references":["docs\/strategies\/cmmc-stig-diagnostics-saas-platform.md","docs\/strategies\/tacitsoft-full-spectrum-strategy-map.md"]},{"slug":"ubuntu-stig-preflight","name":"Ubuntu STIG Preflight","version":"1.0.0","status":"public-preview","safety_level":"Level 3: Logs or identity\/auth data, strong redaction required.","summary":"Collects Ubuntu STIG and CMMC readiness evidence for SSHD, PAM, auditd, sudo, sysctl, AppArmor, AIDE, chrony, and session-timeout review without applying remediation changes.","bundle_schema_version":"2026.06","bundle_contract_version":"1.0.0","contains_sensitive_data":true,"handling_state":"raw","upload_safe_after_review":true,"customer_shareable":false,"platforms":["Ubuntu 20.04","Ubuntu 22.04","Ubuntu 24.04"],"collects":["Ubuntu release, kernel, package, service, and STIG baseline facts","Sanitized SSHD, PAM, auditd, sudo, sysctl, AppArmor, AIDE, and chrony posture","USG\/SCC\/STIG readiness inputs and dry-run evidence references where present","Authentication transition and rollout-risk indicators needed for human remediation planning","Collector manifest, checksums, normalized findings, and review-ready evidence inventory"],"does_not_collect":["Password hashes","Private SSH keys","Automatic remediation output","Secrets from application stores or user home directories","Hostnames, usernames, account names, internal endpoints, or policy principals","Assessment submissions to STIGViewer, eMASS, or third-party portals"],"readiness_surfaces":[{"surface":"SSHD hardening posture","artifacts":["raw\/sshd\/sshd-t.txt","raw\/sshd\/sshd-config.txt"],"control_families":["AC","IA","SC"],"sensitive":true},{"surface":"PAM authentication and faillock posture","artifacts":["raw\/pam\/common-auth.txt","raw\/pam\/common-password.txt","raw\/pam\/faillock.conf.txt"],"control_families":["AC","IA"],"sensitive":true},{"surface":"auditd service, rules, and lockout state","artifacts":["raw\/auditd\/audit-summary.txt"],"control_families":["AU"],"sensitive":true},{"surface":"sudo policy and logging posture","artifacts":["raw\/sudoers\/sudoers.txt","raw\/sudoers\/sudoers-d.txt"],"control_families":["AC","AU"],"sensitive":true},{"surface":"Kernel sysctl network hardening state","artifacts":["raw\/sysctl\/sysctl-a.txt","raw\/sysctl\/99-sysctl.conf.txt"],"control_families":["CM","SC"],"sensitive":false},{"surface":"AppArmor enforcement status","artifacts":["raw\/apparmor\/aa-status.txt","raw\/apparmor\/enabled.txt"],"control_families":["CM","SI"],"sensitive":false},{"surface":"AIDE package and baseline readiness","artifacts":["raw\/aide\/package-status.txt","raw\/aide\/aide.conf.txt"],"control_families":["CM","SI"],"sensitive":true},{"surface":"chrony time sync posture","artifacts":["raw\/chrony\/chronyc-sources.txt","raw\/chrony\/chrony.conf.txt"],"control_families":["AU","SC"],"sensitive":false},{"surface":"Shell session timeout enforcement","artifacts":["raw\/session-timeout\/profile.txt","raw\/session-timeout\/profile-d.txt"],"control_families":["AC"],"sensitive":false}],"bundle_schema":{"bundle_schema_version":"2026.06","collector_name":"ubuntu-stig-preflight","collector_version":"1.0.0","host_count":"Single host today; fleet aggregation later","platform":"ubuntu","contains_sensitive_data":true,"upload_safe_after_review":true,"customer_notes":"optional","handling_state":"raw"},"sensitivity_profile":{"level":"level_3","summary":"Review and redact identity, authentication, and security configuration artifacts before upload.","review_required_paths":["raw\/sshd\/","raw\/pam\/","raw\/sudoers\/","raw\/auditd\/","raw\/aide\/"],"upload_notes":["Treat effective SSHD, PAM, sudoers, and auditd outputs as sensitive even when they do not contain secrets.","Redact hostnames, email addresses, IP addresses, account names, and internal pathing if they are not required for review.","Keep bundle.json, manifest.json, checksums.sha256, and normalized findings consistent after any redaction step."]},"upload_review_expectations":["Confirm the bundle is from the intended Ubuntu host and that bundle.json still reports contains_sensitive_data=true before upload.","Review raw authentication and authorization artifacts for service-account names, internal domains, bastion hostnames, and network ranges.","Verify collector.log only shows dry-run inspection commands and no remediation mutation steps.","Document any omitted files or redactions in redaction\/notes.md so later control mapping can distinguish missing evidence from noncompliance."],"sample_output_inventory_path":"docs\/collectors\/ubuntu-stig-preflight-sample-output-inventory.json","sample_output_inventory":["bundle.json","manifest.json","raw\/os-release.txt","raw\/sshd\/sshd-t.txt","raw\/pam\/common-auth.txt","raw\/auditd\/rules.txt","raw\/sudoers\/sudoers-d.txt","raw\/sysctl\/sysctl-a.txt","raw\/apparmor\/aa-status.txt","raw\/aide\/aide.conf.txt","raw\/chrony\/chrony.conf.txt","raw\/session-timeout\/profile-d.txt","normalized\/findings.json","reports\/review-notes.md","redaction\/notes.md"],"control_mapping_readiness":["Maps observed surfaces to later CMMC\/STIG control interpretation without claiming automated compliance.","Preserves evidence paths needed for dry-run remediation planning and human signoff.","Separates raw artifacts from normalized findings so later rulesets can add control logic without changing collection scope."],"download":{"artifact_url":"\/downloads\/collectors\/ubuntu-stig-preflight\/1.0.0\/ubuntu-stig-preflight-1.0.0.tar.gz","package_format":"tar.gz shell collector release","checksum_sha256":"b33ee1e39c77582dd854c87f647c38dcfc4840bf9d7eddc3b719e4a7078d71ad","checksum_url":"\/downloads\/collectors\/ubuntu-stig-preflight\/1.0.0\/SHA256SUMS","signature_url":"\/downloads\/collectors\/ubuntu-stig-preflight\/1.0.0\/SHA256SUMS.sig","release_notes_url":"\/downloads\/collectors\/ubuntu-stig-preflight\/1.0.0\/README.md","sbom_url":"\/downloads\/collectors\/ubuntu-stig-preflight\/1.0.0\/SBOM.spdx.json","provenance_url":"\/downloads\/collectors\/ubuntu-stig-preflight\/1.0.0\/provenance.json","signing_status":"checksum and detached release signature published","public_key_ref":"\/downloads\/collectors\/ubuntu-stig-preflight\/1.0.0\/release-signing.pub"},"release_flow":{"channel":"public-preview","published_at":"2026-08-12","install_steps":["curl -fsSLO https:\/\/tacitsoft.dev\/downloads\/collectors\/ubuntu-stig-preflight\/1.0.0\/ubuntu-stig-preflight-1.0.0.tar.gz","curl -fsSLO https:\/\/tacitsoft.dev\/downloads\/collectors\/ubuntu-stig-preflight\/1.0.0\/SHA256SUMS","curl -fsSLO https:\/\/tacitsoft.dev\/downloads\/collectors\/ubuntu-stig-preflight\/1.0.0\/SHA256SUMS.sig","sha256sum -c SHA256SUMS","tar -xzf ubuntu-stig-preflight-1.0.0.tar.gz",".\/ubuntu-stig-preflight\/install.sh --prefix .\/out\/ubuntu-stig-preflight"]},"source_references":["docs\/strategies\/cmmc-stig-diagnostics-saas-platform.md","docs\/strategies\/tacitsoft-full-spectrum-strategy-map.md"]},{"slug":"cmmc-evidence-prep","name":"CMMC Evidence Prep","version":"1.0.0","status":"public-preview","safety_level":"Level 3: compliance evidence preparation","summary":"Builds a control-family-oriented evidence-prep bundle for CMMC Level 2 readiness, audit artifact planning, and later control mapping.","bundle_schema_version":"2026.06","bundle_contract_version":"1.0.0","contains_sensitive_data":true,"handling_state":"raw","upload_safe_after_review":true,"customer_shareable":false,"platforms":["Ubuntu 20.04","Ubuntu 22.04","Ubuntu 24.04"],"scope":"Separate from the generic Linux baseline: this track organizes artifacts around CMMC evidence expectations instead of broad host posture inventory.","collects":["Control-family evidence inputs for access control, audit logging, configuration management, identification\/authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, situational awareness, system communications protection, and system\/information integrity","Policy, procedure, configuration, and audit-readiness file references","Evidence ownership, system boundary, and POA&M preparation metadata","Bundle manifest, checksums, and collector logs"],"does_not_collect":["Full policy repositories by default","Customer proprietary evidence unless explicitly added","Assessment submissions to third-party systems"],"control_families":["AC","AU","CM","IA","IR","MA","MP","PS","PE","RA","CA","SC","SI"],"evidence_artifacts":["Ubuntu release metadata without host identity","Sanitized system and human account counts","Control-family policy and procedure references","Identity, access, MFA, and privileged account evidence pointers","Audit logging, retention, and review evidence pointers","Configuration baselines, change-control records, and exception notes","Vulnerability, patch, and remediation tracking snapshots","Incident response, media handling, and maintenance evidence references"],"mapping_hooks":["ruleset:cmmc-l2-linux-evidence","report:evidence-pack","report:control-map","export:poam-seed","export:evidence-artifact-registry"],"download":{"artifact_url":"\/downloads\/collectors\/cmmc-evidence-prep\/1.0.0\/cmmc-evidence-prep-1.0.0.tar.gz","package_format":"tar.gz shell collector release","checksum_sha256":"39a1a084118f2018dd7617fdd629eeb2245d3cff3dea8e3b6684642a863fc008","checksum_url":"\/downloads\/collectors\/cmmc-evidence-prep\/1.0.0\/SHA256SUMS","signature_url":"\/downloads\/collectors\/cmmc-evidence-prep\/1.0.0\/SHA256SUMS.sig","release_notes_url":"\/downloads\/collectors\/cmmc-evidence-prep\/1.0.0\/README.md","sbom_url":"\/downloads\/collectors\/cmmc-evidence-prep\/1.0.0\/SBOM.spdx.json","provenance_url":"\/downloads\/collectors\/cmmc-evidence-prep\/1.0.0\/provenance.json","signing_status":"checksum and detached release signature published","public_key_ref":"\/downloads\/collectors\/cmmc-evidence-prep\/1.0.0\/release-signing.pub"},"release_flow":{"channel":"public-preview","published_at":"2026-08-12","install_steps":["curl -fsSLO https:\/\/tacitsoft.dev\/downloads\/collectors\/cmmc-evidence-prep\/1.0.0\/cmmc-evidence-prep-1.0.0.tar.gz","curl -fsSLO https:\/\/tacitsoft.dev\/downloads\/collectors\/cmmc-evidence-prep\/1.0.0\/SHA256SUMS","curl -fsSLO https:\/\/tacitsoft.dev\/downloads\/collectors\/cmmc-evidence-prep\/1.0.0\/SHA256SUMS.sig","sha256sum -c SHA256SUMS","tar -xzf cmmc-evidence-prep-1.0.0.tar.gz",".\/cmmc-evidence-prep\/install.sh --prefix .\/out\/cmmc-evidence-prep"]},"source_references":["docs\/strategies\/cmmc-stig-diagnostics-saas-platform.md","docs\/strategies\/tacitsoft-full-spectrum-strategy-map.md"]},{"slug":"linux-crash-rca","name":"Linux Crash RCA Preflight","version":"1.0.0","status":"public-preview","safety_level":"Level 4: crash memory and customer-provided evidence; private manual review only","summary":"Inventories and validates operator-selected Linux vmcore or user-space core evidence locally, without executing artifacts or uploading data.","bundle_schema_version":"2026.06","bundle_spec_version":"linux-crash-rca\/v1","contains_sensitive_data":true,"handling_state":"raw","upload_safe_after_review":false,"customer_shareable":false,"platforms":["Linux kernel vmcore","Linux user-space ELF core"],"collects":["Exactly one operator-selected kernel vmcore or user-space ELF core","Exact build ID, release, architecture, endianness, configuration, and module identity metadata","Optional symbols, debug info, logs, platform\/hardware, container, source-map, and reproduction evidence","Local preflight report, capability matrix, manifest, checksums, sensitivity coverage, consent, and retention declarations"],"does_not_collect":["Files not explicitly listed in the local inventory descriptor","Kubernetes Secret objects or any live-cluster data","Cloud metadata, remote URLs, or automatic uploads","Executed cores, binaries, modules, symbols, or reproduction inputs"],"execution_policy":{"local_collection_only":true,"requires_explicit_upload_step":true,"permits_remediation":false,"permits_artifact_execution":false,"upload_policy":"manual_only","privilege_profile":"Reads only operator-selected regular files; rejects links, devices, and unsafe paths.","notes":["Dry run validates the closed inventory without reading evidence or creating output.","Private-analysis consent is recorded only by a separate explicit collector invocation.","The preflight and worker parse bounded ELF headers and notes without subprocesses."]},"bundle_spec":{"family":"linux-crash-rca","major_version":1,"schemas":["schemas\/bundle.schema.json","schemas\/manifest.schema.json","schemas\/preflight-input.schema.json","schemas\/capabilities.schema.json"],"raw_artifacts":["raw\/core\/vmcore or raw\/core\/user.core","raw\/debug\/","raw\/kernel\/","raw\/logs\/","raw\/context\/","raw\/reproduction\/"],"normalized_outputs":["reports\/preflight.json","reports\/capabilities.json","redaction\/coverage.json"],"artifact_classes":["kernel_vmcore","user_core","kernel_image","user_executable","kernel_symbols","user_symbols","kernel_config","module_inventory","module_binary","module_symbols","system_log","platform_inventory","hardware_inventory","container_context","source_map","reproduction_input"]},"capabilities":{"states":["available","degraded","unavailable","blocked"],"names":["stack_unwind","slab_analysis","module_symbols","source_mapping","live_reproduction"],"missing_evidence_never_upgrades":true},"stable_error_codes":["artifact_identity_missing","build_id_mismatch","architecture_mismatch","module_symbols_incomplete","archive_unsafe","artifact_corrupt","sensitive_input_undisclosed","consent_required"],"sensitivity_profile":{"level":"level_4","summary":"Core memory is always secret and private\/manual-review-only; review never makes it customer-shareable.","review_required_paths":["raw\/core\/","raw\/logs\/","raw\/context\/","raw\/reproduction\/"],"upload_notes":["Inspect reports\/preflight.json for non-identifying secret\/PII flags and mismatched evidence before consent.","An unconsented bundle is intentionally rejected with consent_required.","Regenerate the manifest and checksum chain after any redaction; never relabel raw paths as share-safe."]},"download":{"artifact_url":"\/downloads\/collectors\/linux-crash-rca\/1.0.0\/linux-crash-rca-1.0.0.tar.gz","package_format":"tar.gz local preflight release","checksum_sha256":"ebe9c6e7da776f048246411482abab94f5a0b5e6c70108c30273a9f0c3bb3fa7","checksum_url":"\/downloads\/collectors\/linux-crash-rca\/1.0.0\/SHA256SUMS","release_notes_url":"\/downloads\/collectors\/linux-crash-rca\/1.0.0\/README.md","signature_url":null,"signing_status":"checksum-published unsigned public preview","public_key_ref":"https:\/\/github.com\/tacitness\/tstools\/tree\/main\/signing"},"release_flow":{"channel":"public-preview","published_at":"2026-08-08","install_steps":["curl -fsSLO https:\/\/tacitsoft.dev\/downloads\/collectors\/linux-crash-rca\/1.0.0\/linux-crash-rca-1.0.0.tar.gz","curl -fsSLO https:\/\/tacitsoft.dev\/downloads\/collectors\/linux-crash-rca\/1.0.0\/SHA256SUMS","sha256sum -c SHA256SUMS","tar -xzf linux-crash-rca-1.0.0.tar.gz",".\/linux-crash-rca\/install.sh --prefix .\/out\/linux-crash-rca"],"dry_run_steps":[".\/linux-crash-rca\/install.sh --dry-run --prefix .\/out\/linux-crash-rca",".\/linux-crash-rca\/run-collector.sh --inventory .\/linux-crash-rca\/example-inventory.json --source-root .\/local-case --output .\/out\/crash-review --dry-run"],"bundle_expectations":["The collector writes a local review directory and has no upload, cloud, network, or Kubernetes behavior.","Kernel vmcore and user-space core are distinct closed artifact classes and cannot be inferred from one another.","Every manifested file is relative, classified, bounded, exactly sized, and SHA-256 checksummed.","Identity mismatches block affected capabilities; missing evidence never upgrades confidence.","Core memory remains Level 4 secret evidence and customer_shareable=false after review."]},"sample_bundle":{"fixture_path":"tests\/Fixtures\/diagnostics\/linux-crash-rca\/v1","description":"CC0 synthetic valid, degraded, mismatched, corrupt, malicious, and redacted conformance archives."},"conformance_fixture_index":"tests\/Fixtures\/diagnostics\/linux-crash-rca\/v1\/index.json","source_references":["collectors\/linux-crash-rca\/1.0.0\/bundle-spec.yaml","docs\/collectors\/linux-crash-rca-v1.md","docs\/issues\/CUSTOM-BUNDLES-BUNDLESPEC.md"]}]}