Skip to content

Implement sourceos.event.v0.1 JSON Schema and fixtures #4

Description

@mdheller

Goal

Implement the canonical sourceos.event.v0.1 JSON Schema from docs/canonical-event-envelope.md and add validation fixtures.

Scope

  • Add JSON Schema for the canonical event envelope.
  • Enforce controlled vocabularies for event_class, lane, severity, outcome, and privacy tier.
  • Add fixtures for process.exec, policy.decision, trust.evaluation, and telemetry.coalesced.
  • Add invalid fixtures that prove validation rejects bad severity/outcome/lane/event-class values.

Acceptance criteria

  • Required causality fields are enforced.
  • Privacy tier is required.
  • Network trust posture is explicit.
  • Sample fixtures validate cleanly.
  • Invalid fixtures fail predictably.

Activity

  1. mdheller commented on May 6, 2026

    @mdheller
    ContributorAuthor

    Implemented Turn 2 baseline.

    Artifacts landed on main:

    • schemas/sourceos.event.v0.1.schema.json
    • valid fixtures for process exec, policy decision, trust evaluation, and coalesced telemetry under examples/events/
    • invalid fixtures under examples/events/invalid/
    • tools/validate_events.py
    • requirements-dev.txt with jsonschema
    • Makefile integration through validate-events and the top-level validate target
    • docs/canonical-event-envelope.md parity update for power.wake, power, observed, uploaded evidence sources, and attestation_state=not_applicable

    Notes:

    • The schema was widened intentionally to support existing Apple-derived event examples already present in the repo, including MDM entitlement-denial coalescing and DarkWake receipts.
    • Expected policy blocks remain notice + blocked_expected; noisy repeats are modeled as telemetry.coalesced.
    • Full CI execution is still a follow-up if/when workflow wiring is enabled, but the local repo contract is now make validate-events or full make validate.
  2. mdheller commented on Jul 18, 2026

    @mdheller
    ContributorAuthor

    Closed: sourceos.event.v0.1 JSON Schema and fixtures shipped in PR #42 (control-plane-toolkit-20260603), which delivers the canonical event envelope schema, controlled vocabularies, and event fixtures including process.exec, policy.decision, trust.evaluation, and telemetry.coalesced.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions