diff --git a/awareness.el b/awareness.el index 6df6e0e..127f58d 100644 --- a/awareness.el +++ b/awareness.el @@ -243,18 +243,47 @@ fn emit_heartbeat() -> Void { // here; healthy rotation shows it moving with the promotion scores. let wm_top0_wm_raw: String = json_get(wm_top0, "wm") let wm_top0_wm: String = if str_eq(wm_top0_wm_raw, "") { "0" } else { wm_top0_wm_raw } - // Activation observability (2026-07-27 self-review): per-call counters - // from the runtime for the soul's own in-process store. wm_evicted / - // breakthroughs describe the LAST activate call (curiosity scan); - // embed_breaker_open=1 means semantic activation is silently degraded - // to lexical-only until the Ollama circuit-breaker cooldown expires — - // the failure mode embed_ok structurally cannot see (it pings the - // Ollama root, not the embed pipeline). + // Activation observability (2026-07-27 self-review; cumulative since + // 2026-07-31): counters from the runtime for the soul's own in-process + // store. wm_evicted / breakthroughs are now MONOTONIC process-lifetime + // totals (the old per-call values described only the LAST activate call, + // so this 60s heartbeat missed nearly every event — curiosity alone runs + // 2 activates per 30s between beats). We emit the cumulative totals plus + // *_delta fields (change since the previous heartbeat, state-tracked the + // same way as node_delta). embed_breaker_open=1 means semantic activation + // is silently degraded to lexical-only until the Ollama circuit-breaker + // cooldown expires — the failure mode embed_ok structurally cannot see + // (it pings the Ollama root, not the embed pipeline). let act_stats: String = engram_act_stats_json() let act_evict_raw: String = json_get(act_stats, "wm_evicted") let act_evict: String = if str_eq(act_evict_raw, "") { "-1" } else { act_evict_raw } let act_bt_raw: String = json_get(act_stats, "breakthroughs") let act_bt: String = if str_eq(act_bt_raw, "") { "-1" } else { act_bt_raw } + let evict_now: Int = if str_eq(act_evict_raw, "") { 0 - 1 } else { str_to_int(act_evict_raw) } + let bt_now: Int = if str_eq(act_bt_raw, "") { 0 - 1 } else { str_to_int(act_bt_raw) } + let prev_evict_raw: String = state_get("soul.prev_wm_evicted") + let prev_evict: Int = if str_eq(prev_evict_raw, "") { 0 } else { str_to_int(prev_evict_raw) } + let prev_bt_raw: String = state_get("soul.prev_breakthroughs") + let prev_bt: Int = if str_eq(prev_bt_raw, "") { 0 } else { str_to_int(prev_bt_raw) } + // Clamp deltas at 0: prev > now can only mean the counter restarted + // (fresh process) — report the new absolute count, not a negative delta. + let evict_delta: Int = if evict_now < 0 { 0 } else { if evict_now < prev_evict { evict_now } else { evict_now - prev_evict } } + let bt_delta: Int = if bt_now < 0 { 0 } else { if bt_now < prev_bt { bt_now } else { bt_now - prev_bt } } + if evict_now >= 0 { state_set("soul.prev_wm_evicted", int_to_str(evict_now)) } + if bt_now >= 0 { state_set("soul.prev_breakthroughs", int_to_str(bt_now)) } + // embed_eligible (2026-07-31 self-review): true denominator for embedding + // coverage on the authoritative :8742 store. Absolute embed_count alone + // invites the documented "~30% coverage, something is broken" misdiagnosis + // — most nodes are ISE/Tag/short-content and permanently ineligible. + // Real coverage = embed_count / embed_eligible. -1 = stats unreachable. + let hb_stats: String = http_get(hb_engram_url + "/api/stats") + let embed_elig_raw: String = json_get(hb_stats, "embed_eligible_count") + let embed_elig: String = if str_eq(embed_elig_raw, "") { "-1" } else { embed_elig_raw } + // auto_term_streak (2026-07-31): consecutive curiosity scans with the same + // auto seed term — already state-tracked by proactive_curiosity; surfaced + // here so the stuck-term failure is visible in the heartbeat stream too. + let hb_ats_raw: String = state_get("soul.auto_term_streak") + let hb_ats: Int = if str_eq(hb_ats_raw, "") { 0 } else { str_to_int(hb_ats_raw) } let act_brk_raw: String = json_get(act_stats, "embed_breaker_open") let act_brk: String = if str_eq(act_brk_raw, "") { "-1" } else { act_brk_raw } // ctx_cos (2026-07-29 self-review): cos(query, context centroid) at the @@ -264,7 +293,7 @@ fn emit_heartbeat() -> Void { // down) and semantic continuity is silently absent. let ctx_cos_raw: String = json_get(act_stats, "ctx_cos") let ctx_cos: String = if str_eq(ctx_cos_raw, "") { "-2" } else { ctx_cos_raw } - let payload: String = "{\"event\":\"heartbeat\",\"pulse\":" + pulse + ",\"tick\":" + pulse + ",\"boot\":" + boot + ",\"idle\":" + idle + ",\"idle_ms\":" + int_to_str(idle_ms) + ",\"node_count\":" + int_to_str(nc) + ",\"edge_count\":" + int_to_str(ec) + ",\"node_delta\":" + int_to_str(node_delta) + ",\"edge_delta\":" + int_to_str(edge_delta) + ",\"wm_active\":" + int_to_str(wmc) + ",\"wm_delta\":" + int_to_str(wm_delta) + ",\"wm_saturated\":" + int_to_str(wm_sat) + ",\"wm_top0_streak\":" + int_to_str(t0streak) + ",\"wm_churn\":" + int_to_str(wm_churn) + ",\"wm_top0_wm\":" + wm_top0_wm + ",\"sync_added_total\":" + sat_str + ",\"sync_age_ms\":" + int_to_str(sync_age) + ",\"wm_avg_weight\":" + wm_avg_str + ",\"wm_top\":" + wm_top + ",\"ts\":" + int_to_str(ts) + ",\"uptime_ms\":" + int_to_str(up_ms) + ",\"uptime\":\"" + up_human + "\",\"embed_ok\":" + int_to_str(emb_ok) + ",\"embed_backfilled\":" + bf_done + ",\"embed_count\":" + bf_total + ",\"wm_evicted\":" + act_evict + ",\"breakthroughs\":" + act_bt + ",\"embed_breaker_open\":" + act_brk + ",\"ctx_cos\":" + ctx_cos + ",\"ise_fail\":" + fail_str + "}" + let payload: String = "{\"event\":\"heartbeat\",\"pulse\":" + pulse + ",\"tick\":" + pulse + ",\"boot\":" + boot + ",\"idle\":" + idle + ",\"idle_ms\":" + int_to_str(idle_ms) + ",\"node_count\":" + int_to_str(nc) + ",\"edge_count\":" + int_to_str(ec) + ",\"node_delta\":" + int_to_str(node_delta) + ",\"edge_delta\":" + int_to_str(edge_delta) + ",\"wm_active\":" + int_to_str(wmc) + ",\"wm_delta\":" + int_to_str(wm_delta) + ",\"wm_saturated\":" + int_to_str(wm_sat) + ",\"wm_top0_streak\":" + int_to_str(t0streak) + ",\"wm_churn\":" + int_to_str(wm_churn) + ",\"wm_top0_wm\":" + wm_top0_wm + ",\"sync_added_total\":" + sat_str + ",\"sync_age_ms\":" + int_to_str(sync_age) + ",\"wm_avg_weight\":" + wm_avg_str + ",\"wm_top\":" + wm_top + ",\"ts\":" + int_to_str(ts) + ",\"uptime_ms\":" + int_to_str(up_ms) + ",\"uptime\":\"" + up_human + "\",\"embed_ok\":" + int_to_str(emb_ok) + ",\"embed_backfilled\":" + bf_done + ",\"embed_count\":" + bf_total + ",\"embed_eligible\":" + embed_elig + ",\"wm_evicted\":" + act_evict + ",\"wm_evicted_delta\":" + int_to_str(evict_delta) + ",\"breakthroughs\":" + act_bt + ",\"breakthroughs_delta\":" + int_to_str(bt_delta) + ",\"auto_term_streak\":" + int_to_str(hb_ats) + ",\"embed_breaker_open\":" + act_brk + ",\"ctx_cos\":" + ctx_cos + ",\"ise_fail\":" + fail_str + "}" ise_post(payload) } @@ -426,11 +455,11 @@ fn proactive_curiosity() -> Bool { // loop. A single phrase activation matches few (often zero) nodes lexically; // small counts here are the point, not a regression. hops=1 as before. // - // NOTE: a semantic seed supplement (cosine sim ≥ 0.70 scan over embedded nodes) - // was planned alongside hops=1 but is NOT yet implemented — embed_ok in - // heartbeats confirms Ollama is reachable, but no embedding call is made during - // activation. The seed-finding loop in el_runtime.c uses istr_contains only. - // (2026-06-30 self-review: corrected stale comment) + // NOTE (2026-07-31 self-review): semantic seeding/gating IS implemented in + // engram_activate (el_runtime.c): the query is embedded, top-K cosine + // matches supplement the lexical istr_contains seeds, cosine gates + // propagation, and a semantic term feeds the WM promotion score. Lexical + // matching is the fallback when the embedder/breaker is unavailable. let curiosity_seed: String = curiosity_term_a + " " + curiosity_term_b + " " + curiosity_term_c let results_all: String = engram_activate_json(curiosity_seed, 1) let found: Int = json_array_len(results_all) diff --git a/dist/awareness.c b/dist/awareness.c index 5d39087..d53e548 100644 --- a/dist/awareness.c +++ b/dist/awareness.c @@ -198,11 +198,30 @@ el_val_t emit_heartbeat(void) { el_val_t act_evict = ({ el_val_t _if_result_31 = 0; if (str_eq(act_evict_raw, EL_STR(""))) { _if_result_31 = (EL_STR("-1")); } else { _if_result_31 = (act_evict_raw); } _if_result_31; }); el_val_t act_bt_raw = json_get(act_stats, EL_STR("breakthroughs")); el_val_t act_bt = ({ el_val_t _if_result_32 = 0; if (str_eq(act_bt_raw, EL_STR(""))) { _if_result_32 = (EL_STR("-1")); } else { _if_result_32 = (act_bt_raw); } _if_result_32; }); + el_val_t evict_now = ({ el_val_t _if_result_33 = 0; if (str_eq(act_evict_raw, EL_STR(""))) { _if_result_33 = ((0 - 1)); } else { _if_result_33 = (str_to_int(act_evict_raw)); } _if_result_33; }); + el_val_t bt_now = ({ el_val_t _if_result_34 = 0; if (str_eq(act_bt_raw, EL_STR(""))) { _if_result_34 = ((0 - 1)); } else { _if_result_34 = (str_to_int(act_bt_raw)); } _if_result_34; }); + el_val_t prev_evict_raw = state_get(EL_STR("soul.prev_wm_evicted")); + el_val_t prev_evict = ({ el_val_t _if_result_35 = 0; if (str_eq(prev_evict_raw, EL_STR(""))) { _if_result_35 = (0); } else { _if_result_35 = (str_to_int(prev_evict_raw)); } _if_result_35; }); + el_val_t prev_bt_raw = state_get(EL_STR("soul.prev_breakthroughs")); + el_val_t prev_bt = ({ el_val_t _if_result_36 = 0; if (str_eq(prev_bt_raw, EL_STR(""))) { _if_result_36 = (0); } else { _if_result_36 = (str_to_int(prev_bt_raw)); } _if_result_36; }); + el_val_t evict_delta = ({ el_val_t _if_result_37 = 0; if ((evict_now < 0)) { _if_result_37 = (0); } else { _if_result_37 = (({ el_val_t _if_result_38 = 0; if ((evict_now < prev_evict)) { _if_result_38 = (evict_now); } else { _if_result_38 = ((evict_now - prev_evict)); } _if_result_38; })); } _if_result_37; }); + el_val_t bt_delta = ({ el_val_t _if_result_39 = 0; if ((bt_now < 0)) { _if_result_39 = (0); } else { _if_result_39 = (({ el_val_t _if_result_40 = 0; if ((bt_now < prev_bt)) { _if_result_40 = (bt_now); } else { _if_result_40 = ((bt_now - prev_bt)); } _if_result_40; })); } _if_result_39; }); + if (evict_now >= 0) { + state_set(EL_STR("soul.prev_wm_evicted"), int_to_str(evict_now)); + } + if (bt_now >= 0) { + state_set(EL_STR("soul.prev_breakthroughs"), int_to_str(bt_now)); + } + el_val_t hb_stats = http_get(el_str_concat(hb_engram_url, EL_STR("/api/stats"))); + el_val_t embed_elig_raw = json_get(hb_stats, EL_STR("embed_eligible_count")); + el_val_t embed_elig = ({ el_val_t _if_result_41 = 0; if (str_eq(embed_elig_raw, EL_STR(""))) { _if_result_41 = (EL_STR("-1")); } else { _if_result_41 = (embed_elig_raw); } _if_result_41; }); + el_val_t hb_ats_raw = state_get(EL_STR("soul.auto_term_streak")); + el_val_t hb_ats = ({ el_val_t _if_result_42 = 0; if (str_eq(hb_ats_raw, EL_STR(""))) { _if_result_42 = (0); } else { _if_result_42 = (str_to_int(hb_ats_raw)); } _if_result_42; }); el_val_t act_brk_raw = json_get(act_stats, EL_STR("embed_breaker_open")); - el_val_t act_brk = ({ el_val_t _if_result_33 = 0; if (str_eq(act_brk_raw, EL_STR(""))) { _if_result_33 = (EL_STR("-1")); } else { _if_result_33 = (act_brk_raw); } _if_result_33; }); + el_val_t act_brk = ({ el_val_t _if_result_43 = 0; if (str_eq(act_brk_raw, EL_STR(""))) { _if_result_43 = (EL_STR("-1")); } else { _if_result_43 = (act_brk_raw); } _if_result_43; }); el_val_t ctx_cos_raw = json_get(act_stats, EL_STR("ctx_cos")); - el_val_t ctx_cos = ({ el_val_t _if_result_34 = 0; if (str_eq(ctx_cos_raw, EL_STR(""))) { _if_result_34 = (EL_STR("-2")); } else { _if_result_34 = (ctx_cos_raw); } _if_result_34; }); - el_val_t payload = el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(EL_STR("{\"event\":\"heartbeat\",\"pulse\":"), pulse), EL_STR(",\"tick\":")), pulse), EL_STR(",\"boot\":")), boot), EL_STR(",\"idle\":")), idle), EL_STR(",\"idle_ms\":")), int_to_str(idle_ms)), EL_STR(",\"node_count\":")), int_to_str(nc)), EL_STR(",\"edge_count\":")), int_to_str(ec)), EL_STR(",\"node_delta\":")), int_to_str(node_delta)), EL_STR(",\"edge_delta\":")), int_to_str(edge_delta)), EL_STR(",\"wm_active\":")), int_to_str(wmc)), EL_STR(",\"wm_delta\":")), int_to_str(wm_delta)), EL_STR(",\"wm_saturated\":")), int_to_str(wm_sat)), EL_STR(",\"wm_top0_streak\":")), int_to_str(t0streak)), EL_STR(",\"wm_churn\":")), int_to_str(wm_churn)), EL_STR(",\"wm_top0_wm\":")), wm_top0_wm), EL_STR(",\"sync_added_total\":")), sat_str), EL_STR(",\"sync_age_ms\":")), int_to_str(sync_age)), EL_STR(",\"wm_avg_weight\":")), wm_avg_str), EL_STR(",\"wm_top\":")), wm_top), EL_STR(",\"ts\":")), int_to_str(ts)), EL_STR(",\"uptime_ms\":")), int_to_str(up_ms)), EL_STR(",\"uptime\":\"")), up_human), EL_STR("\",\"embed_ok\":")), int_to_str(emb_ok)), EL_STR(",\"embed_backfilled\":")), bf_done), EL_STR(",\"embed_count\":")), bf_total), EL_STR(",\"wm_evicted\":")), act_evict), EL_STR(",\"breakthroughs\":")), act_bt), EL_STR(",\"embed_breaker_open\":")), act_brk), EL_STR(",\"ctx_cos\":")), ctx_cos), EL_STR(",\"ise_fail\":")), fail_str), EL_STR("}")); + el_val_t ctx_cos = ({ el_val_t _if_result_44 = 0; if (str_eq(ctx_cos_raw, EL_STR(""))) { _if_result_44 = (EL_STR("-2")); } else { _if_result_44 = (ctx_cos_raw); } _if_result_44; }); + el_val_t payload = el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(EL_STR("{\"event\":\"heartbeat\",\"pulse\":"), pulse), EL_STR(",\"tick\":")), pulse), EL_STR(",\"boot\":")), boot), EL_STR(",\"idle\":")), idle), EL_STR(",\"idle_ms\":")), int_to_str(idle_ms)), EL_STR(",\"node_count\":")), int_to_str(nc)), EL_STR(",\"edge_count\":")), int_to_str(ec)), EL_STR(",\"node_delta\":")), int_to_str(node_delta)), EL_STR(",\"edge_delta\":")), int_to_str(edge_delta)), EL_STR(",\"wm_active\":")), int_to_str(wmc)), EL_STR(",\"wm_delta\":")), int_to_str(wm_delta)), EL_STR(",\"wm_saturated\":")), int_to_str(wm_sat)), EL_STR(",\"wm_top0_streak\":")), int_to_str(t0streak)), EL_STR(",\"wm_churn\":")), int_to_str(wm_churn)), EL_STR(",\"wm_top0_wm\":")), wm_top0_wm), EL_STR(",\"sync_added_total\":")), sat_str), EL_STR(",\"sync_age_ms\":")), int_to_str(sync_age)), EL_STR(",\"wm_avg_weight\":")), wm_avg_str), EL_STR(",\"wm_top\":")), wm_top), EL_STR(",\"ts\":")), int_to_str(ts)), EL_STR(",\"uptime_ms\":")), int_to_str(up_ms)), EL_STR(",\"uptime\":\"")), up_human), EL_STR("\",\"embed_ok\":")), int_to_str(emb_ok)), EL_STR(",\"embed_backfilled\":")), bf_done), EL_STR(",\"embed_count\":")), bf_total), EL_STR(",\"embed_eligible\":")), embed_elig), EL_STR(",\"wm_evicted\":")), act_evict), EL_STR(",\"wm_evicted_delta\":")), int_to_str(evict_delta)), EL_STR(",\"breakthroughs\":")), act_bt), EL_STR(",\"breakthroughs_delta\":")), int_to_str(bt_delta)), EL_STR(",\"auto_term_streak\":")), int_to_str(hb_ats)), EL_STR(",\"embed_breaker_open\":")), act_brk), EL_STR(",\"ctx_cos\":")), ctx_cos), EL_STR(",\"ise_fail\":")), fail_str), EL_STR("}")); ise_post(payload); return 0; } @@ -348,14 +367,14 @@ el_val_t proactive_curiosity(void) { auto_term_try_slot(json_get(wm10_n1, EL_STR("node_type")), json_get(wm10_n1, EL_STR("label"))); auto_term_try_slot(json_get(wm10_n0, EL_STR("node_type")), json_get(wm10_n0, EL_STR("label"))); el_val_t auto_term = state_get(EL_STR("cseed_auto")); - el_val_t results_auto = ({ el_val_t _if_result_35 = 0; if (str_eq(auto_term, EL_STR(""))) { _if_result_35 = (EL_STR("[]")); } else { _if_result_35 = (engram_activate_json(auto_term, 1)); } _if_result_35; }); + el_val_t results_auto = ({ el_val_t _if_result_45 = 0; if (str_eq(auto_term, EL_STR(""))) { _if_result_45 = (EL_STR("[]")); } else { _if_result_45 = (engram_activate_json(auto_term, 1)); } _if_result_45; }); el_val_t found_auto = json_array_len(results_auto); el_val_t total_found = (found + found_auto); el_val_t safe_auto = str_replace(auto_term, EL_STR("\""), EL_STR("'")); el_val_t prev_auto = state_get(EL_STR("soul.prev_auto_term")); el_val_t atstreak_raw = state_get(EL_STR("soul.auto_term_streak")); - el_val_t atstreak_prev = ({ el_val_t _if_result_36 = 0; if (str_eq(atstreak_raw, EL_STR(""))) { _if_result_36 = (0); } else { _if_result_36 = (str_to_int(atstreak_raw)); } _if_result_36; }); - el_val_t atstreak = ({ el_val_t _if_result_37 = 0; if (str_eq(auto_term, prev_auto)) { _if_result_37 = ((atstreak_prev + 1)); } else { _if_result_37 = (1); } _if_result_37; }); + el_val_t atstreak_prev = ({ el_val_t _if_result_46 = 0; if (str_eq(atstreak_raw, EL_STR(""))) { _if_result_46 = (0); } else { _if_result_46 = (str_to_int(atstreak_raw)); } _if_result_46; }); + el_val_t atstreak = ({ el_val_t _if_result_47 = 0; if (str_eq(auto_term, prev_auto)) { _if_result_47 = ((atstreak_prev + 1)); } else { _if_result_47 = (1); } _if_result_47; }); state_set(EL_STR("soul.prev_auto_term"), auto_term); state_set(EL_STR("soul.auto_term_streak"), int_to_str(atstreak)); if (!str_eq(auto_term, EL_STR(""))) { @@ -549,16 +568,16 @@ el_val_t awareness_run(void) { state_set(EL_STR("soul.boot_ts"), int_to_str(time_now())); } el_val_t tick_raw = env(EL_STR("SOUL_TICK_MS")); - el_val_t tick_ms = ({ el_val_t _if_result_38 = 0; if (str_eq(tick_raw, EL_STR(""))) { _if_result_38 = (200); } else { _if_result_38 = (str_to_int(tick_raw)); } _if_result_38; }); + el_val_t tick_ms = ({ el_val_t _if_result_48 = 0; if (str_eq(tick_raw, EL_STR(""))) { _if_result_48 = (200); } else { _if_result_48 = (str_to_int(tick_raw)); } _if_result_48; }); el_val_t beat_ms_raw = env(EL_STR("SOUL_HEARTBEAT_MS")); - el_val_t beat_ms = ({ el_val_t _if_result_39 = 0; if (str_eq(beat_ms_raw, EL_STR(""))) { _if_result_39 = (60000); } else { _if_result_39 = (str_to_int(beat_ms_raw)); } _if_result_39; }); + el_val_t beat_ms = ({ el_val_t _if_result_49 = 0; if (str_eq(beat_ms_raw, EL_STR(""))) { _if_result_49 = (60000); } else { _if_result_49 = (str_to_int(beat_ms_raw)); } _if_result_49; }); el_val_t scan_ms = (beat_ms / 2); while (1) { el_val_t tick_mark = el_arena_push(); el_val_t running = state_get(EL_STR("soul.running")); if (str_eq(running, EL_STR("false"))) { el_val_t sd_boot_raw = state_get(EL_STR("soul_boot_count")); - el_val_t sd_boot = ({ el_val_t _if_result_40 = 0; if (str_eq(sd_boot_raw, EL_STR(""))) { _if_result_40 = (EL_STR("0")); } else { _if_result_40 = (sd_boot_raw); } _if_result_40; }); + el_val_t sd_boot = ({ el_val_t _if_result_50 = 0; if (str_eq(sd_boot_raw, EL_STR(""))) { _if_result_50 = (EL_STR("0")); } else { _if_result_50 = (sd_boot_raw); } _if_result_50; }); ise_post(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(EL_STR("{\"event\":\"shutdown\",\"boot\":"), sd_boot), EL_STR(",\"pulse\":")), int_to_str(pulse_count())), EL_STR(",\"uptime_ms\":")), int_to_str(elapsed_ms())), EL_STR(",\"ts\":")), int_to_str(time_now())), EL_STR("}"))); println(EL_STR("[awareness] exiting")); el_arena_pop(tick_mark); @@ -574,7 +593,7 @@ el_val_t awareness_run(void) { } el_val_t now_ts = time_now(); el_val_t last_beat_str = state_get(EL_STR("soul.last_beat_ts")); - el_val_t last_beat_ts = ({ el_val_t _if_result_41 = 0; if (str_eq(last_beat_str, EL_STR(""))) { _if_result_41 = (0); } else { _if_result_41 = (str_to_int(last_beat_str)); } _if_result_41; }); + el_val_t last_beat_ts = ({ el_val_t _if_result_51 = 0; if (str_eq(last_beat_str, EL_STR(""))) { _if_result_51 = (0); } else { _if_result_51 = (str_to_int(last_beat_str)); } _if_result_51; }); el_val_t beat_elapsed = (now_ts - last_beat_ts); el_val_t should_beat = (beat_elapsed >= beat_ms); if (should_beat) { @@ -586,7 +605,7 @@ el_val_t awareness_run(void) { } } el_val_t last_scan_str = state_get(EL_STR("soul.last_scan_ts")); - el_val_t last_scan_ts = ({ el_val_t _if_result_42 = 0; if (str_eq(last_scan_str, EL_STR(""))) { _if_result_42 = (0); } else { _if_result_42 = (str_to_int(last_scan_str)); } _if_result_42; }); + el_val_t last_scan_ts = ({ el_val_t _if_result_52 = 0; if (str_eq(last_scan_str, EL_STR(""))) { _if_result_52 = (0); } else { _if_result_52 = (str_to_int(last_scan_str)); } _if_result_52; }); el_val_t scan_elapsed = (now_ts - last_scan_ts); el_val_t should_scan = (!did_work && (scan_elapsed >= scan_ms)); if (should_scan) { @@ -594,15 +613,15 @@ el_val_t awareness_run(void) { state_set(EL_STR("soul.last_scan_ts"), int_to_str(now_ts)); } el_val_t refresh_ms_raw = env(EL_STR("SOUL_REFRESH_MS")); - el_val_t refresh_ms = ({ el_val_t _if_result_43 = 0; if (str_eq(refresh_ms_raw, EL_STR(""))) { _if_result_43 = (600000); } else { _if_result_43 = (str_to_int(refresh_ms_raw)); } _if_result_43; }); + el_val_t refresh_ms = ({ el_val_t _if_result_53 = 0; if (str_eq(refresh_ms_raw, EL_STR(""))) { _if_result_53 = (600000); } else { _if_result_53 = (str_to_int(refresh_ms_raw)); } _if_result_53; }); el_val_t last_refresh_str = state_get(EL_STR("soul.last_refresh_ts")); - el_val_t last_refresh_ts = ({ el_val_t _if_result_44 = 0; if (str_eq(last_refresh_str, EL_STR(""))) { _if_result_44 = (0); } else { _if_result_44 = (str_to_int(last_refresh_str)); } _if_result_44; }); + el_val_t last_refresh_ts = ({ el_val_t _if_result_54 = 0; if (str_eq(last_refresh_str, EL_STR(""))) { _if_result_54 = (0); } else { _if_result_54 = (str_to_int(last_refresh_str)); } _if_result_54; }); el_val_t refresh_elapsed = (now_ts - last_refresh_ts); el_val_t should_refresh = (refresh_elapsed >= refresh_ms); if (should_refresh) { el_val_t sync_env_url = env(EL_STR("SOUL_ISE_URL")); - el_val_t sync_state_url = ({ el_val_t _if_result_45 = 0; if (str_eq(sync_env_url, EL_STR(""))) { _if_result_45 = (state_get(EL_STR("soul_engram_url"))); } else { _if_result_45 = (sync_env_url); } _if_result_45; }); - el_val_t engram_url = ({ el_val_t _if_result_46 = 0; if (str_eq(sync_state_url, EL_STR(""))) { _if_result_46 = (EL_STR("http://localhost:8742")); } else { _if_result_46 = (sync_state_url); } _if_result_46; }); + el_val_t sync_state_url = ({ el_val_t _if_result_55 = 0; if (str_eq(sync_env_url, EL_STR(""))) { _if_result_55 = (state_get(EL_STR("soul_engram_url"))); } else { _if_result_55 = (sync_env_url); } _if_result_55; }); + el_val_t engram_url = ({ el_val_t _if_result_56 = 0; if (str_eq(sync_state_url, EL_STR(""))) { _if_result_56 = (EL_STR("http://localhost:8742")); } else { _if_result_56 = (sync_state_url); } _if_result_56; }); if (!str_eq(engram_url, EL_STR(""))) { el_val_t sync_json = http_get(el_str_concat(engram_url, EL_STR("/api/sync"))); el_val_t sync_ok = (!str_eq(sync_json, EL_STR("")) && !str_eq(sync_json, EL_STR("{}"))); @@ -615,10 +634,10 @@ el_val_t awareness_run(void) { fs_write(tmp, sync_json); el_val_t added = engram_load_merge(tmp); el_val_t ret_raw = env(EL_STR("ENGRAM_ISE_RETENTION_MS")); - el_val_t ret_ms = ({ el_val_t _if_result_47 = 0; if (str_eq(ret_raw, EL_STR(""))) { _if_result_47 = (172800000); } else { _if_result_47 = (str_to_int(ret_raw)); } _if_result_47; }); + el_val_t ret_ms = ({ el_val_t _if_result_57 = 0; if (str_eq(ret_raw, EL_STR(""))) { _if_result_57 = (172800000); } else { _if_result_57 = (str_to_int(ret_raw)); } _if_result_57; }); el_val_t pruned_sync = engram_prune_telemetry(ret_ms); el_val_t sat_raw = state_get(EL_STR("soul.sync_added_total")); - el_val_t sat_n = ({ el_val_t _if_result_48 = 0; if (str_eq(sat_raw, EL_STR(""))) { _if_result_48 = (0); } else { _if_result_48 = (str_to_int(sat_raw)); } _if_result_48; }); + el_val_t sat_n = ({ el_val_t _if_result_58 = 0; if (str_eq(sat_raw, EL_STR(""))) { _if_result_58 = (0); } else { _if_result_58 = (str_to_int(sat_raw)); } _if_result_58; }); state_set(EL_STR("soul.sync_added_total"), int_to_str((sat_n + added))); el_val_t ts2 = time_now(); state_set(EL_STR("soul.last_sync_ok_ts"), int_to_str(ts2)); @@ -644,78 +663,78 @@ el_val_t security_research_authorized(void) { } el_val_t threat_score_command(el_val_t cmd) { - el_val_t s1 = ({ el_val_t _if_result_49 = 0; if (str_contains(cmd, EL_STR("nmap"))) { _if_result_49 = (30); } else { _if_result_49 = (0); } _if_result_49; }); - el_val_t s2 = ({ el_val_t _if_result_50 = 0; if (str_contains(cmd, EL_STR("masscan"))) { _if_result_50 = (40); } else { _if_result_50 = (0); } _if_result_50; }); - el_val_t s3 = ({ el_val_t _if_result_51 = 0; if (str_contains(cmd, EL_STR(" nc "))) { _if_result_51 = (20); } else { _if_result_51 = (0); } _if_result_51; }); - el_val_t s4 = ({ el_val_t _if_result_52 = 0; if (str_contains(cmd, EL_STR("netcat"))) { _if_result_52 = (20); } else { _if_result_52 = (0); } _if_result_52; }); - el_val_t s5 = ({ el_val_t _if_result_53 = 0; if (str_contains(cmd, EL_STR("/etc/shadow"))) { _if_result_53 = (80); } else { _if_result_53 = (0); } _if_result_53; }); - el_val_t s6 = ({ el_val_t _if_result_54 = 0; if (str_contains(cmd, EL_STR("/etc/passwd"))) { _if_result_54 = (30); } else { _if_result_54 = (0); } _if_result_54; }); - el_val_t s7 = ({ el_val_t _if_result_55 = 0; if (str_contains(cmd, EL_STR("id_rsa"))) { _if_result_55 = (60); } else { _if_result_55 = (0); } _if_result_55; }); - el_val_t s8 = ({ el_val_t _if_result_56 = 0; if (str_contains(cmd, EL_STR(".ssh/"))) { _if_result_56 = (50); } else { _if_result_56 = (0); } _if_result_56; }); - el_val_t s9 = ({ el_val_t _if_result_57 = 0; if (str_contains(cmd, EL_STR("crontab"))) { _if_result_57 = (30); } else { _if_result_57 = (0); } _if_result_57; }); - el_val_t s10 = ({ el_val_t _if_result_58 = 0; if (str_contains(cmd, EL_STR("LaunchDaemon"))) { _if_result_58 = (40); } else { _if_result_58 = (0); } _if_result_58; }); - el_val_t s11 = ({ el_val_t _if_result_59 = 0; if ((str_contains(cmd, EL_STR("curl")) && str_contains(cmd, EL_STR("bash")))) { _if_result_59 = (75); } else { _if_result_59 = (0); } _if_result_59; }); - el_val_t s12 = ({ el_val_t _if_result_60 = 0; if ((str_contains(cmd, EL_STR("wget")) && str_contains(cmd, EL_STR("bash")))) { _if_result_60 = (75); } else { _if_result_60 = (0); } _if_result_60; }); - el_val_t s13 = ({ el_val_t _if_result_61 = 0; if ((str_contains(cmd, EL_STR("curl")) && str_contains(cmd, EL_STR("| sh")))) { _if_result_61 = (60); } else { _if_result_61 = (0); } _if_result_61; }); - el_val_t s14 = ({ el_val_t _if_result_62 = 0; if ((str_contains(cmd, EL_STR("base64")) && str_contains(cmd, EL_STR("curl")))) { _if_result_62 = (50); } else { _if_result_62 = (0); } _if_result_62; }); - el_val_t s15 = ({ el_val_t _if_result_63 = 0; if (str_contains(cmd, EL_STR("mkfifo"))) { _if_result_63 = (50); } else { _if_result_63 = (0); } _if_result_63; }); - el_val_t s16 = ({ el_val_t _if_result_64 = 0; if (str_contains(cmd, EL_STR("chmod +s"))) { _if_result_64 = (70); } else { _if_result_64 = (0); } _if_result_64; }); - el_val_t s17 = ({ el_val_t _if_result_65 = 0; if (str_contains(cmd, EL_STR("chmod 4755"))) { _if_result_65 = (70); } else { _if_result_65 = (0); } _if_result_65; }); + el_val_t s1 = ({ el_val_t _if_result_59 = 0; if (str_contains(cmd, EL_STR("nmap"))) { _if_result_59 = (30); } else { _if_result_59 = (0); } _if_result_59; }); + el_val_t s2 = ({ el_val_t _if_result_60 = 0; if (str_contains(cmd, EL_STR("masscan"))) { _if_result_60 = (40); } else { _if_result_60 = (0); } _if_result_60; }); + el_val_t s3 = ({ el_val_t _if_result_61 = 0; if (str_contains(cmd, EL_STR(" nc "))) { _if_result_61 = (20); } else { _if_result_61 = (0); } _if_result_61; }); + el_val_t s4 = ({ el_val_t _if_result_62 = 0; if (str_contains(cmd, EL_STR("netcat"))) { _if_result_62 = (20); } else { _if_result_62 = (0); } _if_result_62; }); + el_val_t s5 = ({ el_val_t _if_result_63 = 0; if (str_contains(cmd, EL_STR("/etc/shadow"))) { _if_result_63 = (80); } else { _if_result_63 = (0); } _if_result_63; }); + el_val_t s6 = ({ el_val_t _if_result_64 = 0; if (str_contains(cmd, EL_STR("/etc/passwd"))) { _if_result_64 = (30); } else { _if_result_64 = (0); } _if_result_64; }); + el_val_t s7 = ({ el_val_t _if_result_65 = 0; if (str_contains(cmd, EL_STR("id_rsa"))) { _if_result_65 = (60); } else { _if_result_65 = (0); } _if_result_65; }); + el_val_t s8 = ({ el_val_t _if_result_66 = 0; if (str_contains(cmd, EL_STR(".ssh/"))) { _if_result_66 = (50); } else { _if_result_66 = (0); } _if_result_66; }); + el_val_t s9 = ({ el_val_t _if_result_67 = 0; if (str_contains(cmd, EL_STR("crontab"))) { _if_result_67 = (30); } else { _if_result_67 = (0); } _if_result_67; }); + el_val_t s10 = ({ el_val_t _if_result_68 = 0; if (str_contains(cmd, EL_STR("LaunchDaemon"))) { _if_result_68 = (40); } else { _if_result_68 = (0); } _if_result_68; }); + el_val_t s11 = ({ el_val_t _if_result_69 = 0; if ((str_contains(cmd, EL_STR("curl")) && str_contains(cmd, EL_STR("bash")))) { _if_result_69 = (75); } else { _if_result_69 = (0); } _if_result_69; }); + el_val_t s12 = ({ el_val_t _if_result_70 = 0; if ((str_contains(cmd, EL_STR("wget")) && str_contains(cmd, EL_STR("bash")))) { _if_result_70 = (75); } else { _if_result_70 = (0); } _if_result_70; }); + el_val_t s13 = ({ el_val_t _if_result_71 = 0; if ((str_contains(cmd, EL_STR("curl")) && str_contains(cmd, EL_STR("| sh")))) { _if_result_71 = (60); } else { _if_result_71 = (0); } _if_result_71; }); + el_val_t s14 = ({ el_val_t _if_result_72 = 0; if ((str_contains(cmd, EL_STR("base64")) && str_contains(cmd, EL_STR("curl")))) { _if_result_72 = (50); } else { _if_result_72 = (0); } _if_result_72; }); + el_val_t s15 = ({ el_val_t _if_result_73 = 0; if (str_contains(cmd, EL_STR("mkfifo"))) { _if_result_73 = (50); } else { _if_result_73 = (0); } _if_result_73; }); + el_val_t s16 = ({ el_val_t _if_result_74 = 0; if (str_contains(cmd, EL_STR("chmod +s"))) { _if_result_74 = (70); } else { _if_result_74 = (0); } _if_result_74; }); + el_val_t s17 = ({ el_val_t _if_result_75 = 0; if (str_contains(cmd, EL_STR("chmod 4755"))) { _if_result_75 = (70); } else { _if_result_75 = (0); } _if_result_75; }); return ((((((((((((((((s1 + s2) + s3) + s4) + s5) + s6) + s7) + s8) + s9) + s10) + s11) + s12) + s13) + s14) + s15) + s16) + s17); return 0; } el_val_t threat_score_path(el_val_t path) { - el_val_t s1 = ({ el_val_t _if_result_66 = 0; if (str_starts_with(path, EL_STR("/etc/"))) { _if_result_66 = (60); } else { _if_result_66 = (0); } _if_result_66; }); - el_val_t s2 = ({ el_val_t _if_result_67 = 0; if (str_contains(path, EL_STR("/.ssh/"))) { _if_result_67 = (70); } else { _if_result_67 = (0); } _if_result_67; }); - el_val_t s3 = ({ el_val_t _if_result_68 = 0; if (str_contains(path, EL_STR("/LaunchDaemons/"))) { _if_result_68 = (80); } else { _if_result_68 = (0); } _if_result_68; }); - el_val_t s4 = ({ el_val_t _if_result_69 = 0; if (str_contains(path, EL_STR("/LaunchAgents/"))) { _if_result_69 = (40); } else { _if_result_69 = (0); } _if_result_69; }); - el_val_t s5 = ({ el_val_t _if_result_70 = 0; if (str_contains(path, EL_STR("/cron"))) { _if_result_70 = (60); } else { _if_result_70 = (0); } _if_result_70; }); - el_val_t s6 = ({ el_val_t _if_result_71 = 0; if (str_contains(path, EL_STR("/.bashrc"))) { _if_result_71 = (35); } else { _if_result_71 = (0); } _if_result_71; }); - el_val_t s7 = ({ el_val_t _if_result_72 = 0; if (str_contains(path, EL_STR("/.zshrc"))) { _if_result_72 = (35); } else { _if_result_72 = (0); } _if_result_72; }); - el_val_t s8 = ({ el_val_t _if_result_73 = 0; if (str_contains(path, EL_STR("/.profile"))) { _if_result_73 = (35); } else { _if_result_73 = (0); } _if_result_73; }); - el_val_t s9 = ({ el_val_t _if_result_74 = 0; if (str_starts_with(path, EL_STR("/usr/"))) { _if_result_74 = (50); } else { _if_result_74 = (0); } _if_result_74; }); - el_val_t s10 = ({ el_val_t _if_result_75 = 0; if (str_starts_with(path, EL_STR("/bin/"))) { _if_result_75 = (70); } else { _if_result_75 = (0); } _if_result_75; }); - el_val_t s11 = ({ el_val_t _if_result_76 = 0; if (str_starts_with(path, EL_STR("/sbin/"))) { _if_result_76 = (70); } else { _if_result_76 = (0); } _if_result_76; }); + el_val_t s1 = ({ el_val_t _if_result_76 = 0; if (str_starts_with(path, EL_STR("/etc/"))) { _if_result_76 = (60); } else { _if_result_76 = (0); } _if_result_76; }); + el_val_t s2 = ({ el_val_t _if_result_77 = 0; if (str_contains(path, EL_STR("/.ssh/"))) { _if_result_77 = (70); } else { _if_result_77 = (0); } _if_result_77; }); + el_val_t s3 = ({ el_val_t _if_result_78 = 0; if (str_contains(path, EL_STR("/LaunchDaemons/"))) { _if_result_78 = (80); } else { _if_result_78 = (0); } _if_result_78; }); + el_val_t s4 = ({ el_val_t _if_result_79 = 0; if (str_contains(path, EL_STR("/LaunchAgents/"))) { _if_result_79 = (40); } else { _if_result_79 = (0); } _if_result_79; }); + el_val_t s5 = ({ el_val_t _if_result_80 = 0; if (str_contains(path, EL_STR("/cron"))) { _if_result_80 = (60); } else { _if_result_80 = (0); } _if_result_80; }); + el_val_t s6 = ({ el_val_t _if_result_81 = 0; if (str_contains(path, EL_STR("/.bashrc"))) { _if_result_81 = (35); } else { _if_result_81 = (0); } _if_result_81; }); + el_val_t s7 = ({ el_val_t _if_result_82 = 0; if (str_contains(path, EL_STR("/.zshrc"))) { _if_result_82 = (35); } else { _if_result_82 = (0); } _if_result_82; }); + el_val_t s8 = ({ el_val_t _if_result_83 = 0; if (str_contains(path, EL_STR("/.profile"))) { _if_result_83 = (35); } else { _if_result_83 = (0); } _if_result_83; }); + el_val_t s9 = ({ el_val_t _if_result_84 = 0; if (str_starts_with(path, EL_STR("/usr/"))) { _if_result_84 = (50); } else { _if_result_84 = (0); } _if_result_84; }); + el_val_t s10 = ({ el_val_t _if_result_85 = 0; if (str_starts_with(path, EL_STR("/bin/"))) { _if_result_85 = (70); } else { _if_result_85 = (0); } _if_result_85; }); + el_val_t s11 = ({ el_val_t _if_result_86 = 0; if (str_starts_with(path, EL_STR("/sbin/"))) { _if_result_86 = (70); } else { _if_result_86 = (0); } _if_result_86; }); return ((((((((((s1 + s2) + s3) + s4) + s5) + s6) + s7) + s8) + s9) + s10) + s11); return 0; } el_val_t threat_score_history(el_val_t history) { - el_val_t s1 = ({ el_val_t _if_result_77 = 0; if (str_contains(history, EL_STR("port scan"))) { _if_result_77 = (15); } else { _if_result_77 = (0); } _if_result_77; }); - el_val_t s2 = ({ el_val_t _if_result_78 = 0; if (str_contains(history, EL_STR("enumerate"))) { _if_result_78 = (10); } else { _if_result_78 = (0); } _if_result_78; }); - el_val_t s3 = ({ el_val_t _if_result_79 = 0; if (str_contains(history, EL_STR("exploit"))) { _if_result_79 = (20); } else { _if_result_79 = (0); } _if_result_79; }); - el_val_t s4 = ({ el_val_t _if_result_80 = 0; if (str_contains(history, EL_STR("payload"))) { _if_result_80 = (15); } else { _if_result_80 = (0); } _if_result_80; }); - el_val_t s5 = ({ el_val_t _if_result_81 = 0; if (str_contains(history, EL_STR("persistence"))) { _if_result_81 = (15); } else { _if_result_81 = (0); } _if_result_81; }); - el_val_t s6 = ({ el_val_t _if_result_82 = 0; if (str_contains(history, EL_STR("lateral movement"))) { _if_result_82 = (25); } else { _if_result_82 = (0); } _if_result_82; }); - el_val_t s7 = ({ el_val_t _if_result_83 = 0; if (str_contains(history, EL_STR("privilege escalation"))) { _if_result_83 = (25); } else { _if_result_83 = (0); } _if_result_83; }); - el_val_t s8 = ({ el_val_t _if_result_84 = 0; if (str_contains(history, EL_STR("reverse shell"))) { _if_result_84 = (40); } else { _if_result_84 = (0); } _if_result_84; }); - el_val_t s9 = ({ el_val_t _if_result_85 = 0; if (str_contains(history, EL_STR("bind shell"))) { _if_result_85 = (40); } else { _if_result_85 = (0); } _if_result_85; }); - el_val_t s10 = ({ el_val_t _if_result_86 = 0; if (str_contains(history, EL_STR("command and control"))) { _if_result_86 = (35); } else { _if_result_86 = (0); } _if_result_86; }); - el_val_t s11 = ({ el_val_t _if_result_87 = 0; if (str_contains(history, EL_STR("self-replicate"))) { _if_result_87 = (45); } else { _if_result_87 = (0); } _if_result_87; }); - el_val_t s12 = ({ el_val_t _if_result_88 = 0; if (str_contains(history, EL_STR("propagat"))) { _if_result_88 = (20); } else { _if_result_88 = (0); } _if_result_88; }); - el_val_t s13 = ({ el_val_t _if_result_89 = 0; if (str_contains(history, EL_STR("ransomware"))) { _if_result_89 = (30); } else { _if_result_89 = (0); } _if_result_89; }); - el_val_t s14 = ({ el_val_t _if_result_90 = 0; if (str_contains(history, EL_STR("encrypt files"))) { _if_result_90 = (40); } else { _if_result_90 = (0); } _if_result_90; }); - el_val_t s15 = ({ el_val_t _if_result_91 = 0; if (str_contains(history, EL_STR("exfiltrat"))) { _if_result_91 = (35); } else { _if_result_91 = (0); } _if_result_91; }); - el_val_t s16 = ({ el_val_t _if_result_92 = 0; if (str_contains(history, EL_STR("zero-day"))) { _if_result_92 = (20); } else { _if_result_92 = (0); } _if_result_92; }); - el_val_t s17 = ({ el_val_t _if_result_93 = 0; if (str_contains(history, EL_STR("rootkit"))) { _if_result_93 = (45); } else { _if_result_93 = (0); } _if_result_93; }); - el_val_t s18 = ({ el_val_t _if_result_94 = 0; if (str_contains(history, EL_STR("keylogger"))) { _if_result_94 = (45); } else { _if_result_94 = (0); } _if_result_94; }); - el_val_t s19 = ({ el_val_t _if_result_95 = 0; if (str_contains(history, EL_STR("botnet"))) { _if_result_95 = (40); } else { _if_result_95 = (0); } _if_result_95; }); - el_val_t s20 = ({ el_val_t _if_result_96 = 0; if (str_contains(history, EL_STR("malware"))) { _if_result_96 = (15); } else { _if_result_96 = (0); } _if_result_96; }); + el_val_t s1 = ({ el_val_t _if_result_87 = 0; if (str_contains(history, EL_STR("port scan"))) { _if_result_87 = (15); } else { _if_result_87 = (0); } _if_result_87; }); + el_val_t s2 = ({ el_val_t _if_result_88 = 0; if (str_contains(history, EL_STR("enumerate"))) { _if_result_88 = (10); } else { _if_result_88 = (0); } _if_result_88; }); + el_val_t s3 = ({ el_val_t _if_result_89 = 0; if (str_contains(history, EL_STR("exploit"))) { _if_result_89 = (20); } else { _if_result_89 = (0); } _if_result_89; }); + el_val_t s4 = ({ el_val_t _if_result_90 = 0; if (str_contains(history, EL_STR("payload"))) { _if_result_90 = (15); } else { _if_result_90 = (0); } _if_result_90; }); + el_val_t s5 = ({ el_val_t _if_result_91 = 0; if (str_contains(history, EL_STR("persistence"))) { _if_result_91 = (15); } else { _if_result_91 = (0); } _if_result_91; }); + el_val_t s6 = ({ el_val_t _if_result_92 = 0; if (str_contains(history, EL_STR("lateral movement"))) { _if_result_92 = (25); } else { _if_result_92 = (0); } _if_result_92; }); + el_val_t s7 = ({ el_val_t _if_result_93 = 0; if (str_contains(history, EL_STR("privilege escalation"))) { _if_result_93 = (25); } else { _if_result_93 = (0); } _if_result_93; }); + el_val_t s8 = ({ el_val_t _if_result_94 = 0; if (str_contains(history, EL_STR("reverse shell"))) { _if_result_94 = (40); } else { _if_result_94 = (0); } _if_result_94; }); + el_val_t s9 = ({ el_val_t _if_result_95 = 0; if (str_contains(history, EL_STR("bind shell"))) { _if_result_95 = (40); } else { _if_result_95 = (0); } _if_result_95; }); + el_val_t s10 = ({ el_val_t _if_result_96 = 0; if (str_contains(history, EL_STR("command and control"))) { _if_result_96 = (35); } else { _if_result_96 = (0); } _if_result_96; }); + el_val_t s11 = ({ el_val_t _if_result_97 = 0; if (str_contains(history, EL_STR("self-replicate"))) { _if_result_97 = (45); } else { _if_result_97 = (0); } _if_result_97; }); + el_val_t s12 = ({ el_val_t _if_result_98 = 0; if (str_contains(history, EL_STR("propagat"))) { _if_result_98 = (20); } else { _if_result_98 = (0); } _if_result_98; }); + el_val_t s13 = ({ el_val_t _if_result_99 = 0; if (str_contains(history, EL_STR("ransomware"))) { _if_result_99 = (30); } else { _if_result_99 = (0); } _if_result_99; }); + el_val_t s14 = ({ el_val_t _if_result_100 = 0; if (str_contains(history, EL_STR("encrypt files"))) { _if_result_100 = (40); } else { _if_result_100 = (0); } _if_result_100; }); + el_val_t s15 = ({ el_val_t _if_result_101 = 0; if (str_contains(history, EL_STR("exfiltrat"))) { _if_result_101 = (35); } else { _if_result_101 = (0); } _if_result_101; }); + el_val_t s16 = ({ el_val_t _if_result_102 = 0; if (str_contains(history, EL_STR("zero-day"))) { _if_result_102 = (20); } else { _if_result_102 = (0); } _if_result_102; }); + el_val_t s17 = ({ el_val_t _if_result_103 = 0; if (str_contains(history, EL_STR("rootkit"))) { _if_result_103 = (45); } else { _if_result_103 = (0); } _if_result_103; }); + el_val_t s18 = ({ el_val_t _if_result_104 = 0; if (str_contains(history, EL_STR("keylogger"))) { _if_result_104 = (45); } else { _if_result_104 = (0); } _if_result_104; }); + el_val_t s19 = ({ el_val_t _if_result_105 = 0; if (str_contains(history, EL_STR("botnet"))) { _if_result_105 = (40); } else { _if_result_105 = (0); } _if_result_105; }); + el_val_t s20 = ({ el_val_t _if_result_106 = 0; if (str_contains(history, EL_STR("malware"))) { _if_result_106 = (15); } else { _if_result_106 = (0); } _if_result_106; }); return (((((((((((((((((((s1 + s2) + s3) + s4) + s5) + s6) + s7) + s8) + s9) + s10) + s11) + s12) + s13) + s14) + s15) + s16) + s17) + s18) + s19) + s20); return 0; } el_val_t threat_trajectory_check(el_val_t tool_name, el_val_t tool_input) { el_val_t history = state_get(EL_STR("agentic_conv_history")); - el_val_t computed_tool_score = ({ el_val_t _if_result_97 = 0; if (str_eq(tool_name, EL_STR("run_command"))) { el_val_t cmd = json_get(tool_input, EL_STR("command")); _if_result_97 = (threat_score_command(cmd)); } else { _if_result_97 = (({ el_val_t _if_result_98 = 0; if ((str_eq(tool_name, EL_STR("write_file")) || str_eq(tool_name, EL_STR("edit_file")))) { el_val_t path = json_get(tool_input, EL_STR("path")); _if_result_98 = (threat_score_path(path)); } else { _if_result_98 = (0); } _if_result_98; })); } _if_result_97; }); + el_val_t computed_tool_score = ({ el_val_t _if_result_107 = 0; if (str_eq(tool_name, EL_STR("run_command"))) { el_val_t cmd = json_get(tool_input, EL_STR("command")); _if_result_107 = (threat_score_command(cmd)); } else { _if_result_107 = (({ el_val_t _if_result_108 = 0; if ((str_eq(tool_name, EL_STR("write_file")) || str_eq(tool_name, EL_STR("edit_file")))) { el_val_t path = json_get(tool_input, EL_STR("path")); _if_result_108 = (threat_score_path(path)); } else { _if_result_108 = (0); } _if_result_108; })); } _if_result_107; }); el_val_t history_score = threat_score_history(history); el_val_t history_contrib = (history_score / 3); el_val_t combined = (computed_tool_score + history_contrib); el_val_t should_log = (combined >= 40); if (should_log) { el_val_t ts = time_now(); - el_val_t authorized_str = ({ el_val_t _if_result_99 = 0; if (security_research_authorized()) { _if_result_99 = (EL_STR("true")); } else { _if_result_99 = (EL_STR("false")); } _if_result_99; }); + el_val_t authorized_str = ({ el_val_t _if_result_109 = 0; if (security_research_authorized()) { _if_result_109 = (EL_STR("true")); } else { _if_result_109 = (EL_STR("false")); } _if_result_109; }); el_val_t log_content = el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(EL_STR("{\"event\":\"threat_check\",\"tool\":\""), tool_name), EL_STR("\",\"score\":")), int_to_str(combined)), EL_STR(",\"tool_score\":")), int_to_str(computed_tool_score)), EL_STR(",\"history_score\":")), int_to_str(history_score)), EL_STR(",\"authorized\":")), authorized_str), EL_STR(",\"ts\":")), int_to_str(ts)), EL_STR("}")); el_val_t log_tags = EL_STR("[\"security-audit\",\"threat-check\"]"); el_val_t discard = mem_remember(log_content, log_tags); @@ -732,7 +751,7 @@ el_val_t threat_history_append(el_val_t text) { el_val_t safe_text = str_to_lower(text); el_val_t combined = el_str_concat(el_str_concat(current, EL_STR(" ")), safe_text); el_val_t len = str_len(combined); - el_val_t trimmed = ({ el_val_t _if_result_100 = 0; if ((len > 2000)) { _if_result_100 = (str_slice(combined, (len - 2000), len)); } else { _if_result_100 = (combined); } _if_result_100; }); + el_val_t trimmed = ({ el_val_t _if_result_110 = 0; if ((len > 2000)) { _if_result_110 = (str_slice(combined, (len - 2000), len)); } else { _if_result_110 = (combined); } _if_result_110; }); state_set(EL_STR("agentic_conv_history"), trimmed); return 0; }