# Read-only relevant dpkg inventory `Inventory(fs.FS) Snapshot` reads fixed `var/lib/dpkg/status` (regular file, nonempty, at most 16 MiB) and checks the fixed `var/lib/dpkg/updates` directory is empty before and after reading. It invokes no package tools and writes nothing. The filesystem must provide metadata via `fs.StatFS`; unsupported, inaccessible, malformed, oversized, changing or journal-busy input returns `state=unknown`, an empty digest and empty packages array. Missing status is not a clean machine. It validates stanza structure/identity/status before filtering. Field names are case-insensitive; duplicate keys, malformed scalar continuations and duplicate package/architecture records are rejected. Descriptions/other values are never returned. Distinct multiarch records are retained; ambiguous all/unspecified architecture duplicates fail closed. Bare not-installed selections are permitted and still returned when relevant, so a caller cannot mistake them for no record. An observed snapshot contains the SHA-256 of the complete status file bytes and deterministically ordered name/version/architecture/status records for: docker-ce, docker-ce-cli, containerd.io, docker-buildx-plugin, docker-compose-plugin, docker.io, docker-compose, docker-compose-v2, docker-doc, docker-buildx, podman-docker, containerd and runc. The `Installed` type means a database record exists, not that it is fully installed. Callers must conservatively review **every** returned record, including hold, partial installation, residual config and not-installed selections. OS paths/ancestors and filesystem implementation are trusted. Metadata/journal rechecks detect ordinary changes but do not lock dpkg or produce an atomic transaction against concurrent writes. The digest is not a host identity or approval. This does not scan custom package databases, rootless/manual runtimes, APT sources, package dependencies, or unrelated packages' operational health. Format reference: [Debian control files](https://www.debian.org/doc/debian-policy/ch-controlfields.html).