feat(controls): B2 — grounded surface checks for absence-based CRA controls
CI / Check (push) Skipped
CI / Check (pull_request) Successful in 5m44s
CI / Detect Changes (pull_request) Skipped
CI / Deploy Agent (pull_request) Skipped
CI / Deploy Dashboard (pull_request) Skipped
CI / Deploy Docs (pull_request) Skipped
CI / Deploy MCP (pull_request) Skipped
CI / Check (push) Skipped
CI / Check (pull_request) Successful in 5m44s
CI / Detect Changes (pull_request) Skipped
CI / Deploy Agent (pull_request) Skipped
CI / Deploy Dashboard (pull_request) Skipped
CI / Deploy Docs (pull_request) Skipped
CI / Deploy MCP (pull_request) Skipped
Second slice of B (hybrid coverage): the controls violated by an *absence* (no rate limiting, no security logging, no update-signature check) have no syntactic pattern for semgrep, so we retrieve the code surface each governs and let the grounded judge decide whether the control holds. - controls/surface.rs: deterministic, bounded surface retrieval (keyword + window, capped per control) for cra-ai-6,11,24,27,28,29,30. - grounded_surface_findings(): retrieve surfaces -> GroundedControlChecker -> net-new findings, each already tagged with its control and grounded to a real snippet (ground() drops anything not quoting verbatim code). - orchestrator Stage 5d, gated on breakpilot.grounded_control_checks (BREAKPILOT_GROUNDED_CHECKS, default off) — absence detection is the least deterministic path, kept off until tuned against live scans. - LUT: the 7 controls' notes now point to the gated grounded mechanism (kept needs_tooling; coverage stays honest until live-validated). Local validation (real Qwen, temp 0), correct positive+negative discrimination: cra-ai-11 unprotected login -> violates, CWE-307, grounded; protected -> false cra-ai-24 unlogged admin del -> violates, CWE-778, grounded; logged -> false Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5
parent
38fedc661b
commit
82ed4afd10
@@ -80,6 +80,11 @@ pub struct BreakpilotConfig {
|
||||
/// scale path and stays gated until verified live against a deployed
|
||||
/// master-controls catalog.
|
||||
pub semantic_mapping: bool,
|
||||
/// Enable the **grounded surface** pass for absence-based controls (retrieve
|
||||
/// the code surface a control governs, judge whether it holds). Off by
|
||||
/// default: absence detection is the least deterministic path and stays gated
|
||||
/// until tuned against live scans.
|
||||
pub grounded_control_checks: bool,
|
||||
}
|
||||
|
||||
impl Default for BreakpilotConfig {
|
||||
@@ -89,6 +94,7 @@ impl Default for BreakpilotConfig {
|
||||
token: None,
|
||||
snapshot_dir: "/data/compliance-scanner/oscal".to_string(),
|
||||
semantic_mapping: false,
|
||||
grounded_control_checks: false,
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user