Skip to content

feat(reporting): propose SARIF transfers through the engagement sandbox - #911

Draft
ChazyTheBest wants to merge 2 commits into
BitterSecurity:mainfrom
ChazyTheBest:contrib/sarif-sandbox-io
Draft

ChazyTheBest wants to merge 2 commits into
BitterSecurity:mainfrom
ChazyTheBest:contrib/sarif-sandbox-io

Conversation

@ChazyTheBest

Copy link
Copy Markdown

Summary

Design proposal: use the engagement sandbox transfer protocol for SARIF files, rather than assuming that paths in the agent process address the sandbox filesystem. Resolve the graph partition explicitly so this proposal is independently reviewable.

Draft for issue/design discussion: full merge qualification remains incomplete.

Changes

  • Download SARIF through the existing configured backend and feed decoded bounded bytes to the current adapter.
  • Upload rendered SARIF through that backend; document injected scope and transport assumptions in a proposed ADR.

Intent

  • Issue / ADR this satisfies: propose SARIF transfers through the engagement sandbox #910 · docs/adr/proposals/2026-10-10-sandbox-sarif-io.md
  • Anti-goal (one thing this PR could have done but deliberately does not): Other scanner formats and transport-level allocation limits are outside this proposal.

Blast radius

Tick the row that best matches this change. No branch rule enforces
this — it sets how much scrutiny you owe the diff and whether to wait
for a review. See
docs/adr/0012-retire-codeowners-merge-gate.md.

  • Tier-auto — tests, internal refactors, non-policy docs, lockfile-only dep bumps.
  • Tier-delegate — agent prompts, skill bodies, middleware internals, web/CLI features.
  • Tier-supply-chain — CI/workflows, package manifests and lockfiles, install script, compose / Dockerfiles, plugin contracts, .semgrep/**. Reaches every OSS user on the next release: request a review and wait for it.
    • If ticked, paste a Why this touches a supply-chain surface paragraph below, and confirm the PR changes that surface and nothing else:

Diff budget

Per QUALITY_BAR §Hard limits: ≤ 400 runtime-code lines, ≤ 10 files, 1 logical concern. docs/**, tests/**, .github/**, .semgrep/** are excluded.

  • My diff fits the budget. 156 conservative changed runtime/test lines; 5 files.
  • Or I am requesting large-diff-approved from @PurpleCHOIms because:

End-to-end verification

[INFERENCE] A deployment with separate agent and sandbox filesystems can make process-local SARIF paths address the wrong filesystem. Current source uses process-local reads/writes; no live deployment failure is claimed. Exact scope/byte checks passed for composite graph partitions, CLI /workspace, config mismatch rejection, UTF-8 and the import size budget. Live transfer, tool-schema injection, Neo4j import/export and report regeneration remain unverified.

  • python3 -B testlab/upstream-prs/verify-reporting-runtime.py (scope/UTF-8): passed. Exact selected scope/byte functions and actual upstream label validator; remote transport/import/export integration remains unverified

Honest gap: no live application stack or remote service was activated. Exact-current Python/Next/Vitest dependencies are not installed in this preparation checkout; retained same-client tooling was used for the focused checks above. make quality, make smoke, a current full build, real browser/PTY/provider/Neo4j/sandbox integration and all changed failure paths have not been verified. The full merge checklists are intentionally left unticked.

Required. One paragraph naming the exact commands you ran on your
machine and the exact behavior you observed. "Tested locally," "all
tests pass," and "should work" are not verification statements — they
are reasons to close the PR. See
QUALITY_BAR §Wired end-to-end.
If you genuinely could not run a part of the change locally, say so
explicitly here and name what you did instead.

Testing

Observed focused-check output:

Verified: composite graph partition, launcher root, config mismatch rejection, strict UTF-8, import budget

Outstanding qualification:

  • No live sandbox/Neo4j import or report regeneration was executed.

  • Tool schema injection, transfer error handling, public typing and launcher/web workspace compatibility still require qualification.

  • A client-side size check after download does not bound transport allocation; server-side guards remain a separate design review.

  • make quality passes (Python + CLI + Web)

  • make smoke succeeds (clean local build + OSS-style up + health checks)

  • pytest tests/ passes (run this if you touched docker-compose.yml or tests/)

  • Every new/changed test was watched to fail without the change and pass with it

  • Every new/changed code path was executed on my machine, not just unit-tested in isolation

  • Manual testing (describe):

Quality Bar self-check

Confirm — by ticking — that you have personally verified each item
against your diff. These are conditions of merge per
QUALITY_BAR.md and
CONTRIBUTING_AGENT.md, regardless of
whether AI assistance was used.

  • No banned pattern from QUALITY_BAR §Banned patterns appears in the diff (no except Exception: pass, no bare except, no bare # type: ignore / # noqa, no _ = call(), no print( in production code, no mutable defaults, no wildcard imports, no TODO without issue link, no raise NotImplementedError in a delivered feature, no pytest.mark.skip / xfail without linked issue, no mocked-system-under-test, no # pragma: no cover for coverage chasing).
  • No AI-slop signature from QUALITY_BAR §AI-slop signatures survives (no defensive if x is not None: the types already prove, no helper-used-once, no speculative **kwargs, no data/result/item placeholder names, no docstrings restating the signature, no em-dash salad, no "leverages X to robustly handle Y").
  • Every changed line traces to the stated intent. No drive-by formatting, renaming, or reordering.
  • Every public function I added/changed has explicit type annotations including return type, and every raised exception is a named class.
  • I would merge this PR if a stranger opened it.
  • If I were tired and reviewing this at the end of a long day, I would still merge it.

AI-assisted contribution attestation

By opening this PR, you confirm — whether or not AI assistance was
used — that you followed CONTRIBUTING_AGENT.md
and meet the QUALITY_BAR.md:

  • You read the diff in full and can defend every line on demand.
  • You actually ran the verification you ticked above.
  • You did not bundle unrelated work.
  • You did not weaken offensive-security guard rails (RoE, SafeCommand,
    EngagementContext, OPSEC skills, semgrep rules, compose isolation,
    capability / PID / memory limits) without a linked ADR.
  • You materially edited any AI-generated output before pushing — the
    diff is not raw model output.

No checkbox is required for this section. The bar applies whether or
not you disclose tool use; this section exists so the expectation is
visible at the point of contribution.

Related Issues

Related to #910. Draft; merge conditions remain open.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant