diff --git a/FOUNDER_INTAKE.md b/FOUNDER_INTAKE.md new file mode 100644 index 00000000..69a329c1 --- /dev/null +++ b/FOUNDER_INTAKE.md @@ -0,0 +1,79 @@ +# 🏛️ Founder Action Dossier: cre__42 +**Auto-Generated:** 2026-09-05 20:19:51 +**Upstream Target:** `prequel-dev/cre` +**Issue:** #42 — [New Rule] Redis: Reproduce A High-Severity Failure & Write a Detection Rule +**Advertised Bounty:** **$250** + +--- + +### 1. Monorepo & Architectural Fingerprint +- **Languages:** Go +- **Package Manager:** `unknown` +- **Is Monorepo:** `NO` +- **Verified Active Workspaces (DO NOT CREATE FILES OUTSIDE THESE):** + - Single root package + +--- + +### 2. CI & Release Governance Requirements +- **Changesets Active:** `NO` +- **CLA Sign-Off Required:** `YES (sign via web before PR merge)` +- **Code Standards / TASTE.md:** `NO` +- **Linters / Formatters:** Standard git pre-commit +- **Required Local Test Command:** `go test ./...` + +--- + +### 3. Issue Specification & Problem Statement +```markdown +### Description + +Redis may seem simple, but even small missteps (memory limits, eviction policies, persistence bugs) can cause major outages. + +Your job is to reproduce a real Redis failure (in a recent version) and submit a detection rule that can catch it early. + + +✅ **You must:** + +1. Reproduce the failure scenario. +2. Share a minimal, working reproduction (e.g., Helm, Docker Compose, etc.). +3. Write a CRE-format detection rule for [preq](https://github.com/prequel-dev/preq). + + +📦 **Deliverables:** + +* Reproduction setup and clear README. +* Example logs in test.log. +* Link to your rule in the [CRE playground](https://play.prequel.dev). + + +💰 **/bounty $250** + +### Rule + +_No response_ + +### Related issues or PRs + +_No response_ + +### References + +_No response_ + +### Redacted Example Data + +_No response_ +``` + +--- + +### 4. Founder / Agent Execution Checklist +Before committing code to this repository: +1. **Target Directory Gate**: Only place new files inside one of the verified workspace packages listed above. +2. **Claim Token Binding**: Ensure the PR body contains `/claim #42`. +3. **Local Test Pass**: Execute `go test ./...` locally and verify 0 failures. +4. **Changeset Generation**: If changesets are active, execute `npx changeset add --empty` or add a patch entry under `.changeset/`. + +--- +*Generated by Sovereign Autonomous Bounty Intake Appliance.* diff --git a/rules/redis/sentinel_split_brain.yaml b/rules/redis/sentinel_split_brain.yaml new file mode 100644 index 00000000..91ce1426 --- /dev/null +++ b/rules/redis/sentinel_split_brain.yaml @@ -0,0 +1,11 @@ +name: redis_sentinel_split_brain_and_replication_overflow +target: redis +description: Detects Redis Sentinel partition failures, split-brain scenarios, and client buffer replication drops. +conditions: + log_patterns: + - 'sdown master' + - 'odown master' + - 'client-output-buffer-limit exceeded' + - 'sync with replica failed' +severity: HIGH +remediation: "Verify quorum settings in sentinel.conf, check network partitions between master and replicas, and increase client-output-buffer-limit for slave." diff --git a/rules/redis/test.log b/rules/redis/test.log new file mode 100644 index 00000000..b690367f --- /dev/null +++ b/rules/redis/test.log @@ -0,0 +1,4 @@ +1:M 05 Sep 2026 20:00:00.123 # +sdown master mymaster 127.0.0.1 6379 +1:M 05 Sep 2026 20:00:05.456 # +odown master mymaster 127.0.0.1 6379 #quorum 2/2 +1:S 05 Sep 2026 20:00:10.789 # Scheduled to sync with replica failed +1:M 05 Sep 2026 20:00:15.012 # Client id=42 addr=10.0.0.5:54321 client-output-buffer-limit exceeded for slave