<#1073 Identify osctrl-mcp in API logs; make alert...
# osctrl
g
#1073 Identify osctrl-mcp in API logs; make alert detail deterministic; fix lint Pull request opened by javuto Identify osctrl-mcp in API logs; make alert detail deterministic; fix lint Three small follow-ups from the earlier performance and security work.
osctrl-mcp
sends its own User-Agent
The standalone MCP binary reused the API client's hardcoded
osctrl-cli-http-client/<version>
, so agent traffic was indistinguishable from
osctrl-cli
in osctrl-api logs. •
apiclient.OsctrlAPI
gains an optional
UserAgent
field. Empty keeps the existing default, so
osctrl-cli
requests are unchanged. •
osctrl-mcp
sets
osctrl-mcp/<version>
. • Hosted MCP already forwards the calling client's User-Agent, so no change is needed there. Result-log and query-result alerts report a stable detail
matchFields
walked a Go map when evaluating match-any rules, so when several columns matched, the one visited first supplied the hit's
Detail
and varied from run to run. Status logs were fixed earlier; this applies the same fix to the other two paths. • Keys are sorted once per log entry and reused across rules. • For an empty pattern, the detail is the first non-empty value, since
action
is often blank and sorts early. • Which entries match is unchanged; only the reported detail is now consistent. • Cost: about 3% slower in the existing matcher benchmarks (20x500: 1.45 ms to 1.50 ms; 50x1000: 5.42 ms to 5.55 ms), plus one small allocation per entry for the sorted keys. Lint
"testing"
moved into the standard-library import group in
pkg/queries/events_test.go
.
golangci-lint run ./...
now reports 0 issues. Validation •
go build ./...
and
go vet ./...
are clean, and all 54 packages pass
go test ./...
. • New tests: User-Agent default and override; alert detail determinism over 50 runs. The determinism test fails against the previous matcher and passes now. jmpsec/osctrl