Compare commits

..
Author SHA1 Message Date
Sharang ParnerkarandClaude Opus 4.8 6ae5d9a07f fix(orchestrator): run semantic control mapping on PLC findings
CI / Check (pull_request) Successful in 5m40s
CI / Detect Changes (pull_request) Skipped
CI / Deploy Agent (pull_request) Skipped
CI / Deploy Dashboard (pull_request) Skipped
CI / Deploy Docs (pull_request) Skipped
CI / Deploy MCP (pull_request) Skipped
CI / Check (push) Skipped
run_plc_scan is a separate path from run_pipeline and never called the
control-mapping passes, so IEC 61131-3 (pump_station.st etc.) findings were
persisted with empty control_refs even with mapping enabled. PLC findings carry
file_path/line/cwe, so the semantic pass now runs per source (its region is read
under that source's working path) and stamps master-control refs. LUT + grounded
passes are code-pattern/CRA-specific and don't apply to control logic, so only the
semantic pass runs on the PLC path.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-22 15:09:48 +02:00
@@ -625,7 +625,6 @@ impl PipelineOrchestrator {
);
let mut new_count = 0u32;
let mut refreshed_count = 0u32;
for mut finding in all_findings {
finding.scan_run_id = Some(scan_run_id.to_string());
if self
@@ -637,27 +636,8 @@ impl PipelineOrchestrator {
{
self.db.findings().insert_one(&finding).await?;
new_count += 1;
} else if !finding.control_refs.is_empty() {
// Re-scan refresh: mirror run_pipeline — persist newly-computed
// control_refs onto a PLC finding first seen before the semantic
// pass ran. The insert path alone never would, so without this a
// PLC re-scan can only pick up mappings via a delete + re-add.
self.db
.findings()
.update_one(
doc! { "fingerprint": &finding.fingerprint },
doc! { "$set": { "control_refs": finding.control_refs.clone() } },
)
.await?;
refreshed_count += 1;
}
}
if refreshed_count > 0 {
tracing::info!(
target_id,
"Refreshed control_refs on {refreshed_count} existing PLC findings"
);
}
if !all_sbom.is_empty() {
if let Err(e) = self