Repository navigation
feat(reporting): propose SARIF transfers through the engagement sandbox - #911
Draft
ChazyTheBest wants to merge 2 commits into
Draft
ChazyTheBest wants to merge 2 commits into
ChazyTheBest wants to merge 2 commits into
Conversation
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Design proposal: use the engagement sandbox transfer protocol for SARIF files, rather than assuming that paths in the agent process address the sandbox filesystem. Resolve the graph partition explicitly so this proposal is independently reviewable.
Draft for issue/design discussion: full merge qualification remains incomplete.
Changes
Intent
docs/adr/proposals/2026-10-10-sandbox-sarif-io.mdBlast radius
Tick the row that best matches this change. No branch rule enforces
this — it sets how much scrutiny you owe the diff and whether to wait
for a review. See
docs/adr/0012-retire-codeowners-merge-gate.md.
.semgrep/**. Reaches every OSS user on the next release: request a review and wait for it.Diff budget
Per QUALITY_BAR §Hard limits: ≤ 400 runtime-code lines, ≤ 10 files, 1 logical concern.
docs/**,tests/**,.github/**,.semgrep/**are excluded.large-diff-approvedfrom@PurpleCHOImsbecause:End-to-end verification
[INFERENCE] A deployment with separate agent and sandbox filesystems can make process-local SARIF paths address the wrong filesystem. Current source uses process-local reads/writes; no live deployment failure is claimed. Exact scope/byte checks passed for composite graph partitions, CLI /workspace, config mismatch rejection, UTF-8 and the import size budget. Live transfer, tool-schema injection, Neo4j import/export and report regeneration remain unverified.
python3 -B testlab/upstream-prs/verify-reporting-runtime.py (scope/UTF-8): passed. Exact selected scope/byte functions and actual upstream label validator; remote transport/import/export integration remains unverifiedHonest gap: no live application stack or remote service was activated. Exact-current Python/Next/Vitest dependencies are not installed in this preparation checkout; retained same-client tooling was used for the focused checks above.
make quality,make smoke, a current full build, real browser/PTY/provider/Neo4j/sandbox integration and all changed failure paths have not been verified. The full merge checklists are intentionally left unticked.Required. One paragraph naming the exact commands you ran on your
machine and the exact behavior you observed. "Tested locally," "all
tests pass," and "should work" are not verification statements — they
are reasons to close the PR. See
QUALITY_BAR §Wired end-to-end.
If you genuinely could not run a part of the change locally, say so
explicitly here and name what you did instead.
Testing
Observed focused-check output:
Outstanding qualification:
No live sandbox/Neo4j import or report regeneration was executed.
Tool schema injection, transfer error handling, public typing and launcher/web workspace compatibility still require qualification.
A client-side size check after download does not bound transport allocation; server-side guards remain a separate design review.
make qualitypasses (Python + CLI + Web)make smokesucceeds (clean local build + OSS-style up + health checks)pytest tests/passes (run this if you toucheddocker-compose.ymlortests/)Every new/changed test was watched to fail without the change and pass with it
Every new/changed code path was executed on my machine, not just unit-tested in isolation
Manual testing (describe):
Quality Bar self-check
Confirm — by ticking — that you have personally verified each item
against your diff. These are conditions of merge per
QUALITY_BAR.md and
CONTRIBUTING_AGENT.md, regardless of
whether AI assistance was used.
except Exception: pass, no bareexcept, no bare# type: ignore/# noqa, no_ = call(), noprint(in production code, no mutable defaults, no wildcard imports, noTODOwithout issue link, noraise NotImplementedErrorin a delivered feature, nopytest.mark.skip/xfailwithout linked issue, no mocked-system-under-test, no# pragma: no coverfor coverage chasing).if x is not None:the types already prove, no helper-used-once, no speculative**kwargs, nodata/result/itemplaceholder names, no docstrings restating the signature, no em-dash salad, no "leverages X to robustly handle Y").AI-assisted contribution attestation
By opening this PR, you confirm — whether or not AI assistance was
used — that you followed CONTRIBUTING_AGENT.md
and meet the QUALITY_BAR.md:
EngagementContext, OPSEC skills, semgrep rules, compose isolation,
capability / PID / memory limits) without a linked ADR.
diff is not raw model output.
No checkbox is required for this section. The bar applies whether or
not you disclose tool use; this section exists so the expectation is
visible at the point of contribution.
Related Issues
Related to #910. Draft; merge conditions remain open.