{
  "_shipped_profile_meta": {
    "layer": "shipped default (tracked in git)",
    "note": "Sane per-scan-type memory envelopes for a fresh install. Merged OVER the built-in fallbacks in resource_governor.py and UNDER the host-specific resource_profile.json (gitignored, written by mem_calibrate.py), which wins because it is measured on the real host. Figures are the observed peak of the scan container PLUS its sibling tool containers, inflated for safety; they are what admission reserves per scan.",
    "observed_peaks_mib": {
      "partial_recon": 153,
      "full_recon": 1229,
      "_provenance": "partial_recon measured directly (_measured_scan_mb.job_envelope_peak); full_recon derived from the 1.5 GiB envelope right-sized in 6.0.2 at MEM_SAFETY_TOLERANCE 0.25"
    },
    "tool_envelope_note": "tool_container_envelope_bytes holds SIBLING containers spawned by a scan, not scan jobs themselves. supply_chain_analyzer is the DIRTY sandbox; its value is the expected PEAK, and container_cap() applies CONTAINER_CAP_HEADROOM (1.5x) on top to get the hard mem_limit.",
    "how_to_replace": "bash tests/redamon_mem_calibrate.sh baseline && bash tests/redamon_mem_calibrate.sh scan <project_id>"
  },
  "tool_container_envelope_bytes": {
    "supply_chain_analyzer": 1073741824,
    "_default": 1500000000
  },
  "scan_job_envelope_bytes": {
    "full_recon": 2147483648,
    "partial_recon": 805306368,
    "partial_recon:SupplyChainRecon": 1879048192,
    "ai_attack": 1073741824,
    "gvm": 2684354560,
    "github_hunt": 805306368,
    "trufflehog": 805306368,
    "trufflehog:docker": 1610612736,
    "trufflehog:huggingface": 1610612736,
    "trufflehog:s3": 1207959552,
    "trufflehog:gcs": 1207959552,
    "supply_chain": 1879048192,
    "codefix": 2147483648,
    "_default": 2147483648
  }
}
