Compare commits
6
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
31f1635ee8 | ||
|
|
60601d8215 | ||
|
|
a7ff36edf3 | ||
|
|
4ef257bfe2 | ||
|
|
38fedc661b | ||
|
|
36a49cdeac |
+16
-8
@@ -206,11 +206,13 @@ jobs:
|
||||
apk add --no-cache git curl openssl
|
||||
git init && git remote add origin "${GITHUB_SERVER_URL}/${GITHUB_REPOSITORY}.git"
|
||||
git fetch --depth=1 origin "${GITHUB_SHA}" && git checkout FETCH_HEAD
|
||||
IMAGE=registry.meghsakha.com/compliance-agent
|
||||
echo "${{ secrets.REGISTRY_PASSWORD }}" | docker login registry.meghsakha.com -u "${{ secrets.REGISTRY_USERNAME }}" --password-stdin
|
||||
IMAGE=repo.meghsakha.com/certifai/compliance-agent
|
||||
echo "${{ secrets.REGISTRY_PASSWORD }}" | docker login repo.meghsakha.com -u "${{ secrets.REGISTRY_USERNAME }}" --password-stdin
|
||||
DOCKER_BUILDKIT=1 docker build --secret id=tramiton_token,env=TRAMITON_FETCH_TOKEN \
|
||||
-f Dockerfile.agent -t "$IMAGE:latest" -t "$IMAGE:${GITHUB_SHA}" .
|
||||
docker push "$IMAGE:latest" && docker push "$IMAGE:${GITHUB_SHA}"
|
||||
command -v cosign >/dev/null 2>&1 || { curl -sSfLo /usr/local/bin/cosign https://github.com/sigstore/cosign/releases/download/v2.4.3/cosign-linux-amd64 && chmod +x /usr/local/bin/cosign; }
|
||||
cosign sign --yes --key env://COSIGN_KEY "$IMAGE:latest" || echo "::warning::cosign failed"
|
||||
PAYLOAD=$(printf '{"ref":"refs/heads/main","repository":{"full_name":"sharang/compliance-scanner-agent"},"head_commit":{"id":"%s","message":"deploy agent"}}' "${GITHUB_SHA}")
|
||||
SIG=$(printf '%s' "$PAYLOAD" | openssl dgst -sha256 -hmac "${{ secrets.ORCA_WEBHOOK_SECRET }}" | awk '{print $2}')
|
||||
RESP=$(curl -fsS -w "\nHTTP %{http_code}" -X POST "http://46.225.100.82:6880/api/v1/webhooks/github" -H "Content-Type: application/json" -H "X-Hub-Signature-256: sha256=$SIG" -d "$PAYLOAD"); echo "$RESP"
|
||||
@@ -230,11 +232,13 @@ jobs:
|
||||
apk add --no-cache git curl openssl
|
||||
git init && git remote add origin "${GITHUB_SERVER_URL}/${GITHUB_REPOSITORY}.git"
|
||||
git fetch --depth=1 origin "${GITHUB_SHA}" && git checkout FETCH_HEAD
|
||||
IMAGE=registry.meghsakha.com/compliance-dashboard
|
||||
echo "${{ secrets.REGISTRY_PASSWORD }}" | docker login registry.meghsakha.com -u "${{ secrets.REGISTRY_USERNAME }}" --password-stdin
|
||||
IMAGE=repo.meghsakha.com/certifai/compliance-dashboard
|
||||
echo "${{ secrets.REGISTRY_PASSWORD }}" | docker login repo.meghsakha.com -u "${{ secrets.REGISTRY_USERNAME }}" --password-stdin
|
||||
DOCKER_BUILDKIT=1 docker build --secret id=tramiton_token,env=TRAMITON_FETCH_TOKEN \
|
||||
-f Dockerfile.dashboard -t "$IMAGE:latest" -t "$IMAGE:${GITHUB_SHA}" .
|
||||
docker push "$IMAGE:latest" && docker push "$IMAGE:${GITHUB_SHA}"
|
||||
command -v cosign >/dev/null 2>&1 || { curl -sSfLo /usr/local/bin/cosign https://github.com/sigstore/cosign/releases/download/v2.4.3/cosign-linux-amd64 && chmod +x /usr/local/bin/cosign; }
|
||||
cosign sign --yes --key env://COSIGN_KEY "$IMAGE:latest" || echo "::warning::cosign failed"
|
||||
PAYLOAD=$(printf '{"ref":"refs/heads/main","repository":{"full_name":"sharang/compliance-scanner-agent"},"head_commit":{"id":"%s","message":"deploy dashboard"}}' "${GITHUB_SHA}")
|
||||
SIG=$(printf '%s' "$PAYLOAD" | openssl dgst -sha256 -hmac "${{ secrets.ORCA_WEBHOOK_SECRET }}" | awk '{print $2}')
|
||||
RESP=$(curl -fsS -w "\nHTTP %{http_code}" -X POST "http://46.225.100.82:6880/api/v1/webhooks/github" -H "Content-Type: application/json" -H "X-Hub-Signature-256: sha256=$SIG" -d "$PAYLOAD"); echo "$RESP"
|
||||
@@ -252,10 +256,12 @@ jobs:
|
||||
apk add --no-cache git curl openssl
|
||||
git init && git remote add origin "${GITHUB_SERVER_URL}/${GITHUB_REPOSITORY}.git"
|
||||
git fetch --depth=1 origin "${GITHUB_SHA}" && git checkout FETCH_HEAD
|
||||
IMAGE=registry.meghsakha.com/compliance-docs
|
||||
echo "${{ secrets.REGISTRY_PASSWORD }}" | docker login registry.meghsakha.com -u "${{ secrets.REGISTRY_USERNAME }}" --password-stdin
|
||||
IMAGE=repo.meghsakha.com/certifai/compliance-docs
|
||||
echo "${{ secrets.REGISTRY_PASSWORD }}" | docker login repo.meghsakha.com -u "${{ secrets.REGISTRY_USERNAME }}" --password-stdin
|
||||
docker build -f Dockerfile.docs -t "$IMAGE:latest" -t "$IMAGE:${GITHUB_SHA}" .
|
||||
docker push "$IMAGE:latest" && docker push "$IMAGE:${GITHUB_SHA}"
|
||||
command -v cosign >/dev/null 2>&1 || { curl -sSfLo /usr/local/bin/cosign https://github.com/sigstore/cosign/releases/download/v2.4.3/cosign-linux-amd64 && chmod +x /usr/local/bin/cosign; }
|
||||
cosign sign --yes --key env://COSIGN_KEY "$IMAGE:latest" || echo "::warning::cosign failed"
|
||||
PAYLOAD=$(printf '{"ref":"refs/heads/main","repository":{"full_name":"sharang/compliance-scanner-agent"},"head_commit":{"id":"%s","message":"deploy docs"}}' "${GITHUB_SHA}")
|
||||
SIG=$(printf '%s' "$PAYLOAD" | openssl dgst -sha256 -hmac "${{ secrets.ORCA_WEBHOOK_SECRET }}" | awk '{print $2}')
|
||||
RESP=$(curl -fsS -w "\nHTTP %{http_code}" -X POST "http://46.225.100.82:6880/api/v1/webhooks/github" -H "Content-Type: application/json" -H "X-Hub-Signature-256: sha256=$SIG" -d "$PAYLOAD"); echo "$RESP"
|
||||
@@ -275,11 +281,13 @@ jobs:
|
||||
apk add --no-cache git curl openssl
|
||||
git init && git remote add origin "${GITHUB_SERVER_URL}/${GITHUB_REPOSITORY}.git"
|
||||
git fetch --depth=1 origin "${GITHUB_SHA}" && git checkout FETCH_HEAD
|
||||
IMAGE=registry.meghsakha.com/compliance-mcp
|
||||
echo "${{ secrets.REGISTRY_PASSWORD }}" | docker login registry.meghsakha.com -u "${{ secrets.REGISTRY_USERNAME }}" --password-stdin
|
||||
IMAGE=repo.meghsakha.com/certifai/compliance-mcp
|
||||
echo "${{ secrets.REGISTRY_PASSWORD }}" | docker login repo.meghsakha.com -u "${{ secrets.REGISTRY_USERNAME }}" --password-stdin
|
||||
DOCKER_BUILDKIT=1 docker build --secret id=tramiton_token,env=TRAMITON_FETCH_TOKEN \
|
||||
-f Dockerfile.mcp -t "$IMAGE:latest" -t "$IMAGE:${GITHUB_SHA}" .
|
||||
docker push "$IMAGE:latest" && docker push "$IMAGE:${GITHUB_SHA}"
|
||||
command -v cosign >/dev/null 2>&1 || { curl -sSfLo /usr/local/bin/cosign https://github.com/sigstore/cosign/releases/download/v2.4.3/cosign-linux-amd64 && chmod +x /usr/local/bin/cosign; }
|
||||
cosign sign --yes --key env://COSIGN_KEY "$IMAGE:latest" || echo "::warning::cosign failed"
|
||||
PAYLOAD=$(printf '{"ref":"refs/heads/main","repository":{"full_name":"sharang/compliance-scanner-agent"},"head_commit":{"id":"%s","message":"deploy mcp"}}' "${GITHUB_SHA}")
|
||||
SIG=$(printf '%s' "$PAYLOAD" | openssl dgst -sha256 -hmac "${{ secrets.ORCA_WEBHOOK_SECRET }}" | awk '{print $2}')
|
||||
RESP=$(curl -fsS -w "\nHTTP %{http_code}" -X POST "http://46.225.100.82:6880/api/v1/webhooks/github" -H "Content-Type: application/json" -H "X-Hub-Signature-256: sha256=$SIG" -d "$PAYLOAD"); echo "$RESP"
|
||||
|
||||
@@ -103,5 +103,8 @@ fn load_breakpilot_config() -> BreakpilotConfig {
|
||||
semantic_mapping: env_var_opt("BREAKPILOT_SEMANTIC_MAPPING")
|
||||
.map(|v| v == "1" || v.eq_ignore_ascii_case("true"))
|
||||
.unwrap_or(d.semantic_mapping),
|
||||
grounded_control_checks: env_var_opt("BREAKPILOT_GROUNDED_CHECKS")
|
||||
.map(|v| v == "1" || v.eq_ignore_ascii_case("true"))
|
||||
.unwrap_or(d.grounded_control_checks),
|
||||
}
|
||||
}
|
||||
|
||||
@@ -11,12 +11,13 @@ mod judge;
|
||||
mod oscal_provider;
|
||||
mod scan_triage;
|
||||
mod semantic;
|
||||
mod surface;
|
||||
mod triage;
|
||||
|
||||
pub use checker::GroundedControlChecker;
|
||||
pub use index::ControlIndex;
|
||||
pub use judge::{ControlJudge, LlmControlJudge, PROMPT_VERSION};
|
||||
pub use oscal_provider::OscalControlsProvider;
|
||||
pub use scan_triage::{semantic_stamp_findings, triage_repo_findings};
|
||||
pub use scan_triage::{grounded_surface_findings, semantic_stamp_findings, triage_repo_findings};
|
||||
pub use semantic::SemanticControlChecker;
|
||||
pub use triage::{ControlTriage, TriageOutcome};
|
||||
|
||||
@@ -16,9 +16,10 @@ use compliance_core::models::onboarding::ComplianceFramework;
|
||||
use compliance_core::AgentConfig;
|
||||
use control_map::ControlMap;
|
||||
|
||||
use super::surface;
|
||||
use super::{
|
||||
ControlIndex, ControlTriage, LlmControlJudge, OscalControlsProvider, SemanticControlChecker,
|
||||
TriageOutcome,
|
||||
ControlIndex, ControlTriage, GroundedControlChecker, LlmControlJudge, OscalControlsProvider,
|
||||
SemanticControlChecker, TriageOutcome,
|
||||
};
|
||||
use crate::llm::LlmClient;
|
||||
|
||||
@@ -105,6 +106,50 @@ async fn build_specs(provider: &OscalControlsProvider) -> HashMap<String, Contro
|
||||
specs
|
||||
}
|
||||
|
||||
/// Absence-based control pass (the grounded half of the hybrid coverage): for each
|
||||
/// control with a [`surface`] definition, deterministically retrieve the code
|
||||
/// surfaces it governs (login routes, logging setup, update/download code) and have
|
||||
/// the grounded judge decide whether the control holds there. Returns net-new
|
||||
/// findings, each already tagged with its control and grounded to a real snippet.
|
||||
///
|
||||
/// Gated: the orchestrator runs this only when `breakpilot.grounded_control_checks`
|
||||
/// is set. Absence detection is the least deterministic path (the judge decides
|
||||
/// presence/absence, not a syntactic pattern), so it stays off until tuned live.
|
||||
pub async fn grounded_surface_findings(
|
||||
config: &AgentConfig,
|
||||
llm: Arc<LlmClient>,
|
||||
repo_path: &Path,
|
||||
repo_id: &str,
|
||||
) -> Vec<Finding> {
|
||||
let Some(base_url) = config.breakpilot.base_url.clone() else {
|
||||
return Vec::new();
|
||||
};
|
||||
let provider = OscalControlsProvider::new(
|
||||
reqwest::Client::new(),
|
||||
base_url,
|
||||
config.breakpilot.token.clone(),
|
||||
&config.breakpilot.snapshot_dir,
|
||||
);
|
||||
let specs = build_specs(&provider).await;
|
||||
if specs.is_empty() {
|
||||
return Vec::new();
|
||||
}
|
||||
let checker = GroundedControlChecker::new(LlmControlJudge::new(llm));
|
||||
|
||||
let mut out = Vec::new();
|
||||
for surf in surface::SURFACES {
|
||||
let Some(spec) = specs.get(surf.control_id) else {
|
||||
continue; // catalog doesn't carry this control
|
||||
};
|
||||
let regions = surface::retrieve(repo_path, surf.terms);
|
||||
if regions.is_empty() {
|
||||
continue;
|
||||
}
|
||||
out.extend(checker.check(spec, ®ions, repo_id).await);
|
||||
}
|
||||
out
|
||||
}
|
||||
|
||||
/// Read a window of lines around `line` (1-based) from `repo_path/file`.
|
||||
fn fetch_region(repo_path: &Path, file: &str, line: u32) -> Option<CandidateRegion> {
|
||||
let content = std::fs::read_to_string(repo_path.join(file)).ok()?;
|
||||
@@ -189,13 +234,22 @@ pub async fn semantic_stamp_findings(
|
||||
let Some(region) = fetch_region(repo_path, &file, line) else {
|
||||
continue;
|
||||
};
|
||||
let region_emb = match llm.embed(vec![region.content.clone()]).await {
|
||||
// Retrieve on the finding's intent + the code, not the region alone: two
|
||||
// findings in one file share overlapping windows and otherwise embed alike,
|
||||
// collapsing onto the same controls. The finding's title/description carry
|
||||
// the discriminating signal (e.g. "brute-force protection" vs "weak hash").
|
||||
// The raw `region` still goes to the judge for snippet grounding.
|
||||
let query = format!(
|
||||
"{}\n{}\n\n{}",
|
||||
finding.title, finding.description, region.content
|
||||
);
|
||||
let query_emb = match llm.embed(vec![query]).await {
|
||||
Ok(mut embs) => match embs.pop() {
|
||||
Some(v) => v,
|
||||
None => continue,
|
||||
},
|
||||
Err(e) => {
|
||||
tracing::warn!(error = %e, "region embed failed; skipping finding");
|
||||
tracing::warn!(error = %e, "query embed failed; skipping finding");
|
||||
continue;
|
||||
}
|
||||
};
|
||||
@@ -203,7 +257,7 @@ pub async fn semantic_stamp_findings(
|
||||
.check(
|
||||
&index,
|
||||
®ion,
|
||||
®ion_emb,
|
||||
&query_emb,
|
||||
SEMANTIC_TOP_K,
|
||||
&finding.repo_id,
|
||||
)
|
||||
|
||||
@@ -22,18 +22,20 @@ impl<J: ControlJudge> SemanticControlChecker<J> {
|
||||
Self { judge }
|
||||
}
|
||||
|
||||
/// Map a code region to the controls it violates. `region_embedding` is the
|
||||
/// region's embedding (the caller computes it via the LLM); the top-`k`
|
||||
/// nearest controls in `index` are judged and grounded.
|
||||
/// Map a code region to the controls it violates. `query_embedding` is the
|
||||
/// caller-supplied retrieval embedding — typically the finding's intent
|
||||
/// (title/description) plus the region, so retrieval keys on what the finding
|
||||
/// is *about*, not just the ambient code. The top-`k` nearest controls in
|
||||
/// `index` are then judged against the raw `region` and grounded.
|
||||
pub async fn check(
|
||||
&self,
|
||||
index: &ControlIndex,
|
||||
region: &CandidateRegion,
|
||||
region_embedding: &[f64],
|
||||
query_embedding: &[f64],
|
||||
k: usize,
|
||||
repo_id: &str,
|
||||
) -> Vec<Finding> {
|
||||
let candidates = index.nearest(region_embedding, k);
|
||||
let candidates = index.nearest(query_embedding, k);
|
||||
let mut findings = Vec::new();
|
||||
for spec in &candidates {
|
||||
let verdict = self.judge.judge(spec, region).await;
|
||||
|
||||
@@ -0,0 +1,258 @@
|
||||
//! Surface retrieval for absence-based controls.
|
||||
//!
|
||||
//! Some CRA controls are violated by an *absence* — no rate limiting on login, no
|
||||
//! security logging, no signature check on an update — so there's no offending
|
||||
//! pattern for semgrep to match. Instead we deterministically locate the code
|
||||
//! *surface* the control governs (a login route, a logging setup, update/download
|
||||
//! code) by identifier/route terms, then hand each surface region to the grounded
|
||||
//! judge, which decides whether the control is satisfied there. The resulting
|
||||
//! finding grounds to the surface snippet, so nothing fabricated survives.
|
||||
//!
|
||||
//! Retrieval is intentionally cheap and bounded: keyword match + a fixed window,
|
||||
//! capped per control to keep the downstream LLM cost predictable.
|
||||
|
||||
use std::path::Path;
|
||||
|
||||
use compliance_core::control_check::CandidateRegion;
|
||||
|
||||
/// An absence-based control and the case-insensitive terms that mark the code
|
||||
/// surface it governs.
|
||||
pub struct Surface {
|
||||
pub control_id: &'static str,
|
||||
pub terms: &'static [&'static str],
|
||||
}
|
||||
|
||||
/// The absence-based CRA controls we retrieve surfaces for — the grounded half of
|
||||
/// the hybrid coverage (the pattern-expressible half is custom semgrep rules).
|
||||
pub const SURFACES: &[Surface] = &[
|
||||
Surface {
|
||||
control_id: "cra-ai-6", // Integritaetspruefung
|
||||
terms: &[
|
||||
"checksum",
|
||||
"sha256",
|
||||
"signature",
|
||||
"hmac",
|
||||
"integrity",
|
||||
"verify",
|
||||
],
|
||||
},
|
||||
Surface {
|
||||
control_id: "cra-ai-11", // Brute-Force-Schutz
|
||||
terms: &[
|
||||
"login",
|
||||
"signin",
|
||||
"authenticate",
|
||||
"/auth",
|
||||
"password",
|
||||
"ratelimit",
|
||||
],
|
||||
},
|
||||
Surface {
|
||||
control_id: "cra-ai-12", // Rollenbasierte Autorisierung (RBAC)
|
||||
terms: &[
|
||||
"authorize",
|
||||
"permission",
|
||||
"role",
|
||||
"rbac",
|
||||
"require_role",
|
||||
"has_role",
|
||||
],
|
||||
},
|
||||
Surface {
|
||||
control_id: "cra-ai-24", // Security-Logging
|
||||
terms: &["login", "authorize", "permission", "role", "admin", "audit"],
|
||||
},
|
||||
Surface {
|
||||
control_id: "cra-ai-27", // Log-Integritaet und -Aufbewahrung
|
||||
terms: &["logging", "logger", "getlogger", "audit_log"],
|
||||
},
|
||||
Surface {
|
||||
control_id: "cra-ai-28", // Sichere Update-Mechanismen
|
||||
terms: &["update", "upgrade", "download", "firmware"],
|
||||
},
|
||||
Surface {
|
||||
control_id: "cra-ai-29", // Update-Authentizitaet
|
||||
terms: &["update", "signature", "verify", "pubkey", "certificate"],
|
||||
},
|
||||
Surface {
|
||||
control_id: "cra-ai-30", // Update-Integritaet
|
||||
terms: &["update", "checksum", "digest", "integrity", "verify"],
|
||||
},
|
||||
];
|
||||
|
||||
/// Source file extensions worth reading (skip binaries/assets/lockfiles).
|
||||
const CODE_EXTS: &[&str] = &[
|
||||
"py", "js", "ts", "tsx", "jsx", "go", "java", "rb", "php", "rs", "cs", "kt",
|
||||
];
|
||||
/// Directories never worth walking.
|
||||
const SKIP_DIRS: &[&str] = &[
|
||||
".git",
|
||||
"node_modules",
|
||||
"target",
|
||||
"vendor",
|
||||
".venv",
|
||||
"__pycache__",
|
||||
"dist",
|
||||
"build",
|
||||
];
|
||||
/// Lines of context on each side of a hit.
|
||||
const WINDOW: usize = 6;
|
||||
/// Cap on regions per control, to bound downstream LLM calls.
|
||||
const MAX_REGIONS_PER_CONTROL: usize = 8;
|
||||
/// Skip files larger than this (generated/minified).
|
||||
const MAX_FILE_BYTES: u64 = 512 * 1024;
|
||||
|
||||
/// Deterministically retrieve up to [`MAX_REGIONS_PER_CONTROL`] code regions in
|
||||
/// `repo_path` whose lines mention any of `terms`. Hits close together within a
|
||||
/// file are merged into one region; results are capped to bound LLM cost.
|
||||
pub fn retrieve(repo_path: &Path, terms: &[&str]) -> Vec<CandidateRegion> {
|
||||
let lowered: Vec<String> = terms.iter().map(|t| t.to_lowercase()).collect();
|
||||
let mut regions = Vec::new();
|
||||
for entry in walk(repo_path) {
|
||||
if regions.len() >= MAX_REGIONS_PER_CONTROL {
|
||||
break;
|
||||
}
|
||||
let path = entry.path();
|
||||
if !has_code_ext(path) {
|
||||
continue;
|
||||
}
|
||||
let Ok(meta) = entry.metadata() else { continue };
|
||||
if !meta.is_file() || meta.len() > MAX_FILE_BYTES {
|
||||
continue;
|
||||
}
|
||||
let Ok(content) = std::fs::read_to_string(path) else {
|
||||
continue;
|
||||
};
|
||||
let rel = path
|
||||
.strip_prefix(repo_path)
|
||||
.unwrap_or(path)
|
||||
.to_string_lossy()
|
||||
.to_string();
|
||||
let lines: Vec<&str> = content.lines().collect();
|
||||
let hits: Vec<usize> = lines
|
||||
.iter()
|
||||
.enumerate()
|
||||
.filter(|(_, line)| {
|
||||
let ll = line.to_lowercase();
|
||||
lowered.iter().any(|t| ll.contains(t.as_str()))
|
||||
})
|
||||
.map(|(i, _)| i)
|
||||
.collect();
|
||||
for center in merge_centers(&hits) {
|
||||
if regions.len() >= MAX_REGIONS_PER_CONTROL {
|
||||
break;
|
||||
}
|
||||
let start = center.saturating_sub(WINDOW);
|
||||
let end = (center + WINDOW + 1).min(lines.len());
|
||||
regions.push(CandidateRegion {
|
||||
file: rel.clone(),
|
||||
start_line: (start as u32) + 1,
|
||||
content: lines[start..end].join("\n"),
|
||||
});
|
||||
}
|
||||
}
|
||||
regions
|
||||
}
|
||||
|
||||
/// Collapse ascending hit indices that fall within one window into a single
|
||||
/// representative center, so overlapping regions aren't judged repeatedly.
|
||||
fn merge_centers(hits: &[usize]) -> Vec<usize> {
|
||||
let mut out: Vec<usize> = Vec::new();
|
||||
for &h in hits {
|
||||
match out.last() {
|
||||
Some(&last) if h.saturating_sub(last) <= WINDOW => {}
|
||||
_ => out.push(h),
|
||||
}
|
||||
}
|
||||
out
|
||||
}
|
||||
|
||||
fn has_code_ext(path: &Path) -> bool {
|
||||
path.extension()
|
||||
.and_then(|e| e.to_str())
|
||||
.is_some_and(|e| CODE_EXTS.contains(&e))
|
||||
}
|
||||
|
||||
fn walk(root: &Path) -> Vec<walkdir::DirEntry> {
|
||||
walkdir::WalkDir::new(root)
|
||||
.into_iter()
|
||||
.filter_entry(|e| {
|
||||
let name = e.file_name().to_string_lossy();
|
||||
!SKIP_DIRS.contains(&name.as_ref())
|
||||
})
|
||||
.filter_map(|e| e.ok())
|
||||
.collect()
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
#[allow(clippy::unwrap_used)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
fn write(dir: &Path, rel: &str, body: &str) {
|
||||
let p = dir.join(rel);
|
||||
if let Some(parent) = p.parent() {
|
||||
std::fs::create_dir_all(parent).unwrap();
|
||||
}
|
||||
std::fs::write(p, body).unwrap();
|
||||
}
|
||||
|
||||
fn terms_for(control_id: &str) -> &'static [&'static str] {
|
||||
SURFACES
|
||||
.iter()
|
||||
.find(|s| s.control_id == control_id)
|
||||
.unwrap()
|
||||
.terms
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn surfaces_cover_the_absence_based_controls() {
|
||||
assert_eq!(SURFACES.len(), 8);
|
||||
for id in [
|
||||
"cra-ai-6",
|
||||
"cra-ai-11",
|
||||
"cra-ai-12",
|
||||
"cra-ai-24",
|
||||
"cra-ai-27",
|
||||
"cra-ai-28",
|
||||
"cra-ai-29",
|
||||
"cra-ai-30",
|
||||
] {
|
||||
assert!(SURFACES.iter().any(|s| s.control_id == id), "{id} missing");
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn retrieves_matching_region_with_context() {
|
||||
let dir = std::env::temp_dir().join(format!("surface-{}", uuid::Uuid::new_v4()));
|
||||
std::fs::create_dir_all(&dir).unwrap();
|
||||
write(
|
||||
&dir,
|
||||
"app/auth.py",
|
||||
"import x\n\n\n\n\n\n\ndef login(u, p):\n return check(u, p)\n",
|
||||
);
|
||||
let regions = retrieve(&dir, terms_for("cra-ai-11"));
|
||||
assert_eq!(regions.len(), 1);
|
||||
assert!(regions[0].content.contains("def login"));
|
||||
assert_eq!(regions[0].file, "app/auth.py");
|
||||
let _ = std::fs::remove_dir_all(&dir);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn skips_non_code_and_vendored() {
|
||||
let dir = std::env::temp_dir().join(format!("surface-{}", uuid::Uuid::new_v4()));
|
||||
std::fs::create_dir_all(&dir).unwrap();
|
||||
write(&dir, "README.md", "login and password and audit\n"); // not code ext
|
||||
write(&dir, "node_modules/pkg/index.js", "function login() {}\n"); // vendored
|
||||
assert!(retrieve(&dir, terms_for("cra-ai-11")).is_empty());
|
||||
let _ = std::fs::remove_dir_all(&dir);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn merges_adjacent_hits_into_one_region() {
|
||||
// Two hits one line apart collapse to a single center/region.
|
||||
assert_eq!(merge_centers(&[10, 11, 30]), vec![10, 30]);
|
||||
assert_eq!(merge_centers(&[]), Vec::<usize>::new());
|
||||
assert_eq!(merge_centers(&[5]), vec![5]);
|
||||
}
|
||||
}
|
||||
@@ -22,6 +22,11 @@ struct EmbeddingData {
|
||||
index: usize,
|
||||
}
|
||||
|
||||
/// Max inputs per embedding request. The bge/OpenAI-like backends cap the input
|
||||
/// array (bge-multilingual-gemma2 rejects >25 with "batch size overflow"), so we
|
||||
/// chunk larger corpora — a whole control catalog (~1.8k) would otherwise 500.
|
||||
const EMBED_BATCH_SIZE: usize = 16;
|
||||
|
||||
// ── Embedding implementation ───────────────────────────────────
|
||||
|
||||
impl LlmClient {
|
||||
@@ -29,8 +34,21 @@ impl LlmClient {
|
||||
&self.embed_model
|
||||
}
|
||||
|
||||
/// Generate embeddings for a batch of texts
|
||||
/// Generate embeddings for a batch of texts, chunking into backend-sized
|
||||
/// requests and preserving input order across chunks.
|
||||
pub async fn embed(&self, texts: Vec<String>) -> Result<Vec<Vec<f64>>, AgentError> {
|
||||
if texts.is_empty() {
|
||||
return Ok(Vec::new());
|
||||
}
|
||||
let mut out = Vec::with_capacity(texts.len());
|
||||
for chunk in texts.chunks(EMBED_BATCH_SIZE) {
|
||||
out.extend(self.embed_batch(chunk.to_vec()).await?);
|
||||
}
|
||||
Ok(out)
|
||||
}
|
||||
|
||||
/// Embed one backend-sized batch (≤ [`EMBED_BATCH_SIZE`]) in a single request.
|
||||
async fn embed_batch(&self, texts: Vec<String>) -> Result<Vec<Vec<f64>>, AgentError> {
|
||||
let url = format!("{}/v1/embeddings", self.base_url.trim_end_matches('/'));
|
||||
|
||||
let request_body = EmbeddingRequest {
|
||||
@@ -72,3 +90,33 @@ impl LlmClient {
|
||||
Ok(data.into_iter().map(|d| d.embedding).collect())
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
use secrecy::SecretString;
|
||||
|
||||
fn client() -> LlmClient {
|
||||
LlmClient::new(
|
||||
"http://unused".into(),
|
||||
SecretString::from(String::new()),
|
||||
"m".into(),
|
||||
"e".into(),
|
||||
)
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn empty_input_makes_no_request() {
|
||||
// Must short-circuit before any HTTP call (base_url is unroutable).
|
||||
let out = client().embed(Vec::new()).await.unwrap();
|
||||
assert!(out.is_empty());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn batch_size_is_within_backend_cap() {
|
||||
assert!(
|
||||
EMBED_BATCH_SIZE <= 25,
|
||||
"must stay under the bge 25-input cap"
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -252,6 +252,31 @@ impl PipelineOrchestrator {
|
||||
}
|
||||
}
|
||||
|
||||
// Stage 5d: grounded surface checks — the absence-based controls (no
|
||||
// rate limiting, no security logging, no update-signature check) have no
|
||||
// syntactic pattern to match, so we retrieve the code surface each governs
|
||||
// and let the grounded judge decide whether it holds, producing net-new
|
||||
// findings already tagged + grounded. Gated (default off): absence
|
||||
// detection is the least deterministic path, kept off until tuned live.
|
||||
if self.config.breakpilot.grounded_control_checks {
|
||||
self.update_phase(scan_run_id, "grounded_control_checks")
|
||||
.await;
|
||||
let grounded = crate::controls::grounded_surface_findings(
|
||||
&self.config,
|
||||
self.llm.clone(),
|
||||
&repo_path,
|
||||
&repo_id,
|
||||
)
|
||||
.await;
|
||||
if !grounded.is_empty() {
|
||||
tracing::info!(
|
||||
"[{repo_id}] Grounded surface checks raised {} control findings",
|
||||
grounded.len()
|
||||
);
|
||||
all_findings.extend(grounded);
|
||||
}
|
||||
}
|
||||
|
||||
// Dedup against existing findings and insert new ones
|
||||
let mut new_count = 0u32;
|
||||
let mut new_findings: Vec<Finding> = Vec::new();
|
||||
|
||||
@@ -0,0 +1,145 @@
|
||||
//! C5 live verification — the semantic master-controls path end to end against the
|
||||
//! deployed api-dev catalog. Ignored (hits api-dev + LiteLLM). Run explicitly:
|
||||
//!
|
||||
//! set -a; . ./.env; set +a
|
||||
//! BREAKPILOT_BASE_URL=https://api-dev.breakpilot.ai \
|
||||
//! cargo test -p compliance-agent --test c5_semantic_live -- --ignored --nocapture
|
||||
//!
|
||||
//! Pulls the live master-controls catalog, embeds the corpus (chunked), then for a
|
||||
//! couple of real vulnerable findings retrieves the nearest master controls and
|
||||
//! grounded-judges them, stamping master-control refs.
|
||||
|
||||
mod common;
|
||||
|
||||
use std::sync::Arc;
|
||||
|
||||
use compliance_agent::llm::LlmClient;
|
||||
use compliance_core::config::BreakpilotConfig;
|
||||
use compliance_core::models::finding::{Finding, Severity};
|
||||
use compliance_core::models::scan::ScanType;
|
||||
use secrecy::SecretString;
|
||||
|
||||
fn env(k: &str) -> String {
|
||||
std::env::var(k).unwrap_or_else(|_| panic!("env {k} must be set for the live C5 test"))
|
||||
}
|
||||
|
||||
fn mk_finding(file: &str, line: u32, title: &str) -> Finding {
|
||||
let mut f = Finding::new(
|
||||
"repo-c5".into(),
|
||||
format!("{file}:{line}"),
|
||||
"semgrep".into(),
|
||||
ScanType::Sast,
|
||||
title.into(),
|
||||
title.into(),
|
||||
Severity::High,
|
||||
);
|
||||
f.file_path = Some(file.into());
|
||||
f.line_number = Some(line);
|
||||
f
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
#[ignore = "live: requires deployed api-dev master-controls (fetch+parse only, no LLM)"]
|
||||
async fn c5_ingest_master_controls_catalog() {
|
||||
use compliance_agent::controls::OscalControlsProvider;
|
||||
|
||||
let provider = OscalControlsProvider::new(
|
||||
reqwest::Client::new(),
|
||||
env("BREAKPILOT_BASE_URL"),
|
||||
None,
|
||||
std::env::temp_dir().join("c5-ingest-snap"),
|
||||
);
|
||||
let doc = provider
|
||||
.load_master_controls()
|
||||
.await
|
||||
.expect("pull + parse master-controls catalog");
|
||||
let controls = doc.to_controls();
|
||||
println!(
|
||||
"\n=== C5 ingest: {} master controls parsed ===",
|
||||
controls.len()
|
||||
);
|
||||
for c in controls.iter().take(4) {
|
||||
let text: String = c.text.chars().take(90).collect();
|
||||
println!(" {} | {} | {}", c.id, c.title, text);
|
||||
}
|
||||
assert!(
|
||||
!controls.is_empty(),
|
||||
"expected a non-empty master-control corpus"
|
||||
);
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
#[ignore = "live: requires deployed api-dev master-controls + LiteLLM"]
|
||||
async fn c5_semantic_stamps_master_control_refs() {
|
||||
let llm = Arc::new(LlmClient::new(
|
||||
env("LITELLM_URL"),
|
||||
SecretString::from(env("LITELLM_API_KEY")),
|
||||
env("LITELLM_MODEL"),
|
||||
env("LITELLM_EMBED_MODEL"),
|
||||
));
|
||||
|
||||
let mut config = common::dev_config("mongodb://unused".into(), "c5".into());
|
||||
let snapshot = std::env::temp_dir().join("c5-oscal-snap");
|
||||
config.breakpilot = BreakpilotConfig {
|
||||
base_url: Some(env("BREAKPILOT_BASE_URL")),
|
||||
token: None,
|
||||
snapshot_dir: snapshot.to_string_lossy().into_owned(),
|
||||
semantic_mapping: true,
|
||||
grounded_control_checks: false,
|
||||
};
|
||||
|
||||
// Fixture repo with recognizable code-checkable surfaces.
|
||||
let repo = std::env::temp_dir().join("c5-fixture-repo");
|
||||
let _ = std::fs::remove_dir_all(&repo);
|
||||
std::fs::create_dir_all(repo.join("app")).expect("mkdir");
|
||||
std::fs::write(
|
||||
repo.join("app/auth.py"),
|
||||
concat!(
|
||||
"import hashlib\n",
|
||||
"\n",
|
||||
"def store_password(user, password):\n",
|
||||
" # weak, unsalted password hashing\n",
|
||||
" digest = hashlib.md5(password.encode()).hexdigest()\n",
|
||||
" db.save(user, digest)\n",
|
||||
"\n",
|
||||
"@app.route('/login', methods=['POST'])\n",
|
||||
"def login():\n",
|
||||
" u = request.form['username']\n",
|
||||
" p = request.form['password']\n",
|
||||
" return 'ok' if check(u, p) else ('bad', 401)\n",
|
||||
),
|
||||
)
|
||||
.expect("write fixture");
|
||||
|
||||
let mut findings = vec![
|
||||
mk_finding("app/auth.py", 5, "Weak password hash (md5, unsalted)"),
|
||||
mk_finding(
|
||||
"app/auth.py",
|
||||
9,
|
||||
"Login endpoint without brute-force protection",
|
||||
),
|
||||
];
|
||||
|
||||
let tagged =
|
||||
compliance_agent::controls::semantic_stamp_findings(&config, llm, &repo, &mut findings)
|
||||
.await;
|
||||
|
||||
println!("\n=== C5 semantic master-controls stamping ===");
|
||||
for f in &findings {
|
||||
println!(
|
||||
" {:50} {}:{:?} -> {:?}",
|
||||
f.title,
|
||||
f.file_path.as_deref().unwrap_or(""),
|
||||
f.line_number,
|
||||
f.control_refs
|
||||
);
|
||||
}
|
||||
println!("findings that gained >=1 master-control ref: {tagged}");
|
||||
let _ = std::fs::remove_dir_all(&repo);
|
||||
|
||||
// Live corpus — assert only that the path runs and stamps at least one ref.
|
||||
assert!(
|
||||
tagged >= 1,
|
||||
"expected at least one finding to gain a master-control ref"
|
||||
);
|
||||
}
|
||||
@@ -80,6 +80,11 @@ pub struct BreakpilotConfig {
|
||||
/// scale path and stays gated until verified live against a deployed
|
||||
/// master-controls catalog.
|
||||
pub semantic_mapping: bool,
|
||||
/// Enable the **grounded surface** pass for absence-based controls (retrieve
|
||||
/// the code surface a control governs, judge whether it holds). Off by
|
||||
/// default: absence detection is the least deterministic path and stays gated
|
||||
/// until tuned against live scans.
|
||||
pub grounded_control_checks: bool,
|
||||
}
|
||||
|
||||
impl Default for BreakpilotConfig {
|
||||
@@ -89,6 +94,7 @@ impl Default for BreakpilotConfig {
|
||||
token: None,
|
||||
snapshot_dir: "/data/compliance-scanner/oscal".to_string(),
|
||||
semantic_mapping: false,
|
||||
grounded_control_checks: false,
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -25,35 +25,35 @@
|
||||
"control": "cra-ai-2",
|
||||
"title": "Minimale Angriffsflaeche",
|
||||
"scans": [],
|
||||
"note": "code-checkable but no off-the-shelf tool digs it out — author a detector (custom semgrep rule / check)",
|
||||
"status": "needs_tooling"
|
||||
"note": "design property (minimal attack surface) — not derivable from local code patterns; architecture/threat-model review",
|
||||
"status": "not_code_checkable"
|
||||
},
|
||||
{
|
||||
"control": "cra-ai-3",
|
||||
"title": "Sichere Systemarchitektur",
|
||||
"scans": [],
|
||||
"note": "code-checkable but no off-the-shelf tool digs it out — author a detector (custom semgrep rule / check)",
|
||||
"status": "needs_tooling"
|
||||
"note": "design property (secure system architecture) — architecture review, not statically code-checkable",
|
||||
"status": "not_code_checkable"
|
||||
},
|
||||
{
|
||||
"control": "cra-ai-4",
|
||||
"title": "Least-Privilege-Prinzip",
|
||||
"scans": [],
|
||||
"note": "code-checkable but no off-the-shelf tool digs it out — author a detector (custom semgrep rule / check)",
|
||||
"status": "needs_tooling"
|
||||
"note": "design property (least-privilege) — deployment/IAM & architecture review, not a local code pattern",
|
||||
"status": "not_code_checkable"
|
||||
},
|
||||
{
|
||||
"control": "cra-ai-5",
|
||||
"title": "Manipulationsschutz",
|
||||
"scans": [],
|
||||
"note": "code-checkable but no off-the-shelf tool digs it out — author a detector (custom semgrep rule / check)",
|
||||
"status": "needs_tooling"
|
||||
"note": "design property (tamper protection) — hardware/runtime & operational control, not statically code-checkable",
|
||||
"status": "not_code_checkable"
|
||||
},
|
||||
{
|
||||
"control": "cra-ai-6",
|
||||
"title": "Integritaetspruefung",
|
||||
"scans": [],
|
||||
"note": "code-checkable but no off-the-shelf tool digs it out — author a detector (custom semgrep rule / check)",
|
||||
"note": "absence-based — no syntactic pattern; covered by the grounded surface check (retrieve surface + LLM judge), gated (BREAKPILOT_GROUNDED_CHECKS) pending live tuning",
|
||||
"status": "needs_tooling"
|
||||
},
|
||||
{
|
||||
@@ -139,14 +139,14 @@
|
||||
"control": "cra-ai-11",
|
||||
"title": "Brute-Force-Schutz",
|
||||
"scans": [],
|
||||
"note": "code-checkable but no off-the-shelf tool digs it out — author a detector (custom semgrep rule / check)",
|
||||
"note": "absence-based — no syntactic pattern; covered by the grounded surface check (retrieve surface + LLM judge), gated (BREAKPILOT_GROUNDED_CHECKS) pending live tuning",
|
||||
"status": "needs_tooling"
|
||||
},
|
||||
{
|
||||
"control": "cra-ai-12",
|
||||
"title": "Rollenbasierte Autorisierung",
|
||||
"scans": [],
|
||||
"note": "code-checkable but no off-the-shelf tool digs it out — author a detector (custom semgrep rule / check)",
|
||||
"note": "absence-based — no syntactic pattern; covered by the grounded surface check (retrieve surface + LLM judge), gated (BREAKPILOT_GROUNDED_CHECKS) pending live tuning",
|
||||
"status": "needs_tooling"
|
||||
},
|
||||
{
|
||||
@@ -308,7 +308,7 @@
|
||||
"control": "cra-ai-24",
|
||||
"title": "Security-Logging",
|
||||
"scans": [],
|
||||
"note": "code-checkable but no off-the-shelf tool digs it out — author a detector (custom semgrep rule / check)",
|
||||
"note": "absence-based — no syntactic pattern; covered by the grounded surface check (retrieve surface + LLM judge), gated (BREAKPILOT_GROUNDED_CHECKS) pending live tuning",
|
||||
"status": "needs_tooling"
|
||||
},
|
||||
{
|
||||
@@ -329,28 +329,28 @@
|
||||
"control": "cra-ai-27",
|
||||
"title": "Log-Integritaet und -Aufbewahrung",
|
||||
"scans": [],
|
||||
"note": "code-checkable but no off-the-shelf tool digs it out — author a detector (custom semgrep rule / check)",
|
||||
"note": "absence-based — no syntactic pattern; covered by the grounded surface check (retrieve surface + LLM judge), gated (BREAKPILOT_GROUNDED_CHECKS) pending live tuning",
|
||||
"status": "needs_tooling"
|
||||
},
|
||||
{
|
||||
"control": "cra-ai-28",
|
||||
"title": "Sichere Update-Mechanismen",
|
||||
"scans": [],
|
||||
"note": "code-checkable but no off-the-shelf tool digs it out — author a detector (custom semgrep rule / check)",
|
||||
"note": "absence-based — no syntactic pattern; covered by the grounded surface check (retrieve surface + LLM judge), gated (BREAKPILOT_GROUNDED_CHECKS) pending live tuning",
|
||||
"status": "needs_tooling"
|
||||
},
|
||||
{
|
||||
"control": "cra-ai-29",
|
||||
"title": "Update-Authentizitaet",
|
||||
"scans": [],
|
||||
"note": "code-checkable but no off-the-shelf tool digs it out — author a detector (custom semgrep rule / check)",
|
||||
"note": "absence-based — no syntactic pattern; covered by the grounded surface check (retrieve surface + LLM judge), gated (BREAKPILOT_GROUNDED_CHECKS) pending live tuning",
|
||||
"status": "needs_tooling"
|
||||
},
|
||||
{
|
||||
"control": "cra-ai-30",
|
||||
"title": "Update-Integritaet",
|
||||
"scans": [],
|
||||
"note": "code-checkable but no off-the-shelf tool digs it out — author a detector (custom semgrep rule / check)",
|
||||
"note": "absence-based — no syntactic pattern; covered by the grounded surface check (retrieve surface + LLM judge), gated (BREAKPILOT_GROUNDED_CHECKS) pending live tuning",
|
||||
"status": "needs_tooling"
|
||||
},
|
||||
{
|
||||
|
||||
@@ -214,6 +214,27 @@ mod tests {
|
||||
assert!(hits.iter().any(|c| c.control == "cra-ai-1"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn coverage_reflects_the_b_track_split() {
|
||||
let s = ControlMap::cra().unwrap().summary();
|
||||
// 9 already tool-covered + B1's 4 custom-semgrep controls.
|
||||
assert_eq!(s.covered, 13);
|
||||
// The 8 grounded surface controls stay needs_tooling until live-tuned.
|
||||
assert_eq!(s.needs_tooling, 8);
|
||||
// B3 marked the 4 pure-architectural controls not code-checkable.
|
||||
assert_eq!(s.not_code_checkable, 19);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn architectural_controls_are_not_code_checkable() {
|
||||
let map = ControlMap::cra().unwrap();
|
||||
for id in ["cra-ai-2", "cra-ai-3", "cra-ai-4", "cra-ai-5"] {
|
||||
let c = map.coverage(id).unwrap();
|
||||
assert_eq!(c.status, Coverage::NotCodeCheckable, "{id}");
|
||||
assert!(c.scans.is_empty(), "{id} should carry no scan bindings");
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn custom_rule_controls_do_not_bind_by_broad_cwe() {
|
||||
let map = ControlMap::cra().unwrap();
|
||||
|
||||
Reference in New Issue
Block a user