Skip to content

Commit 8db4fbd

Browse files
authored
fix: remove hardcoded capability and evidence gates (#90)
* fix: remove hardcoded capability and evidence gates * fix: reduce duplicated admission plumbing * fix: centralize capability set assembly
1 parent d6aea6d commit 8db4fbd

36 files changed

Lines changed: 868 additions & 1100 deletions

‎docs/cyberbattlesim-researcher-command.md‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -19,6 +19,14 @@ raes-adapters inspect --backend cyberbattlesim-chain
1919
pinned native source is available and byte-verified, along with the qualified
2020
source commit and supported RAES profiles.
2121

22+
Native `validate`, `run --mode smoke`, and `run --mode study` are currently
23+
fail-closed for the selected task. Its attacker-action-log and
24+
availability-series requirements cannot be verified at artifact-field and
25+
data-quality granularity by the pinned RAES contract. These commands exit `3`
26+
before runtime planning, native import, output reservation, or simulator
27+
effects. Issue #86 owns the CyberBattleSim capture/manifest remediation; the
28+
authored task is not weakened in the interim.
29+
2230
The native simulator remains separately installed because upstream publishes no
2331
selected index or release artifact. Build or acquire the wheel from commit
2432
`854d6966607fb68645651f55b0f97221bd293e0d`, verify the complete identity
Lines changed: 122 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,122 @@
1+
# Capability and evidence-claim integrity guardrails
2+
3+
GitHub issue #84 is the authority for this repository-wide correction. This
4+
note fixes the claim boundaries every adapter, shared helper, command, and
5+
conformance lane must respect. It defines no new RAES contract, capability,
6+
evidence type, status vocabulary, or implementation plan.
7+
8+
## Keep four claims distinct
9+
10+
An authored task requirement, a backend capability declaration, a captured
11+
run artifact, and a post-run satisfaction claim are different facts with
12+
different owners:
13+
14+
- `ExperimentTaskModel` owns what evidence the author requires. A requirement
15+
is demand, not proof that an adapter can capture it.
16+
- The published RAES `BackendManifest` and capability models own what the
17+
selected production target advertises. A capability is admissible only when
18+
its production component and capture path are executable; a constraint,
19+
source-ledger row, injected driver, or planned feature is not a substitute.
20+
- `ExperimentEvidenceRecordModel`, `ExperimentDerivedMeasureModel`, and
21+
`ExperimentArtifactRefModel` describe what one run actually emitted. A file
22+
containing an evaluator summary is not an action log, availability series,
23+
host-compromise series, or reward-component record merely because all of
24+
them concern the same episode.
25+
- `validate_experiment_run_against_task()` owns the task/run satisfaction join.
26+
Conformance, qualification, source admission, cleanup, or a successful run
27+
cannot bypass that join or manufacture its inputs.
28+
29+
The pinned RAES contract validates a semantic `satisfies_refs` entry by
30+
reference identity. `ExperimentEvidenceSatisfactionReferenceModel` cannot
31+
express required-field coverage or the availability, redaction, withholding,
32+
or loss status of those fields. Therefore a generic authored evidence concept
33+
must not be placed in `satisfies_refs` until the applicable published RAES
34+
contract can express and validate the complete artifact-and-field witness.
35+
Current researcher tasks that require such a concept must fail closed even if
36+
that makes an adapter or example temporarily non-runnable. An exact authored
37+
artifact identity remains admissible only where the existing RAES validator
38+
can verify its identity and any authored digest/path constraints directly.
39+
40+
## Canonical incumbents
41+
42+
| Concern | Canonical owner and required use |
43+
| --- | --- |
44+
| Manifest and capability shape | RAES `BackendManifest`, `BackendCapabilitySet`, component capability models, `backend_manifest_payload()`, capability-admission helpers, and `RuntimeTarget` presence/signature validation. Do not add an adapter capability schema or infer support from component existence alone. |
45+
| Runtime admission | `RuntimeManager.plan()`, public target components, `ApplyResult`, snapshot-transition validation, participant admission/history validation, evaluator result validation, and cleanup receipt validation. Every affirmative production claim must survive its applicable public execution path. |
46+
| Experiment evidence | RAES capture-spec, evidence-record, derived-measure, artifact, run, and task models plus `_experiment_evidence.py` and `_researcher_support.py` for mechanics only. Backend-local code owns source projection; shared helpers must not assign semantic evidence identities. |
47+
| Task/run joins | `validate_experiment_run_against_task()` and `validate_experiment_study_against_tasks_and_runs()`. Do not copy their join logic or predeclare a positive result in `_BackendAdapter`, a manifest constraint, or a pack file. |
48+
| Manifest conformance | `run_conformance_probe()`, canonical RAES report projection/writer, and executable adapter-local probes. `affirmative_capability_pointers()` is inventory only; a static pointer-to-reference table and one broad pass flag are not proof that each leaf was exercised. |
49+
| Source truth | Backend qualification records, source admission, scenario/source ledgers, and loss disclosures. These establish provenance and bounded source facts; they do not satisfy per-run capture requirements. |
50+
| Failures and disclosure | RAES `Diagnostic`/`DiagnosticModel`, `diagnostic_model()`, `ApplyResult`, stable command exit codes, and `base.redaction`. Missing, unavailable, withheld, redacted, lossy, unsupported, and failed must remain distinct non-success dispositions. |
51+
| Persistence | `atomic_write_json_artifact()`, the RAES conformance report writer, exclusive confined output roots, and inventory-last sealing. Runtime state remains behind RAES runtime/control-plane ownership; no evidence registry, cache, or adapter store is introduced. |
52+
| Verification | Existing repository tests, clean-installed distribution probes, the single nox graph, and the `PR Gate`. Negative tests must exercise every registered adapter and shared command path, not a hand-maintained subset that silently omits the next adapter. |
53+
54+
Backend manifests may contain declarative values, but those values are not
55+
self-authenticating. Shared constructors such as standard evaluator,
56+
orchestrator, or cleanup capability builders may factor shape only after the
57+
caller supplies truth established by the production path. They must not grant
58+
support merely because several gym-style adapters are expected to share it.
59+
Likewise, reporting every PrimAITE capability as an open conformance gap does
60+
not make its affirmative production manifest truthful; an inadmissible adapter
61+
is allowed to break.
62+
63+
## Validation and security path
64+
65+
| Layer the design passes | Required treatment |
66+
| --- | --- |
67+
| Authentication and authorization | The current researcher command is local and adds no auth surface. Participant authority still comes from exact manifest/selection/configuration joins and public participant admission. Any later network surface must use the RAES strict-default control-plane security, verified identity, role/target authorization, request limits, denial audit, and redacted exception handling; adapters do not add endpoints. |
68+
| Secrets and environment bindings | No claim path reads credentials, a secret store, `.env`, or ambient configuration. Do not add token options or environment-selected capability/evidence overrides. Native credentials, action details, observations, rewards, argv, environment maps, and source paths never enter portable evidence or diagnostics. |
69+
| Static input and config shape | Reuse closed `argparse` choices, per-backend required/foreign argument checks, pack digest validation, confined child resolution, duplicate-key-rejecting JSON loading, RAES SDL parsing, closed contract models, participant joins, target config normalizers, and selected-source admission. No arbitrary import, driver, profile, schema, or capture map is caller-selectable. |
70+
| Runtime validators | Preserve manifest/component checks, capability admission, plan/resource/dependency validation, `ApplyResult` shape, snapshot transitions, participant action/result/history joins, evaluator/proposition checks, and cleanup verification. A native transition with an unverifiable projection is failure, not partial evidence satisfaction. |
71+
| OS and process exposure | Keep relative confined outputs, exclusive mode-0700 creation, atomic publication, no shell interpolation or runtime download, clean-install isolation, cleared `PYTHONPATH`, `PYTHONSAFEPATH=1`, and discarded native stdout/stderr. Do not put evidence payloads, credentials, or native paths in argv or filenames. |
72+
| Error envelopes and observability | Reuse bounded `_CommandFailure` messages, RAES diagnostics, canonical report projection, and default-deny redaction. Logs and terminal output may carry safe identities, pointers, counts, and dispositions only. Never serialize exception text, rejected values, native output, object representations, or tracebacks. |
73+
| Artifact publication | Validate RAES models and task/run joins before sealing success; write the final inventory last. A checksum proves byte identity, not semantic completeness or safety. Failure, cleanup failure, or an unsatisfied requirement cannot be published with a successful disposition. |
74+
75+
## Extension seam
76+
77+
The extension seam is the existing backend strategy boundary, parameterized by
78+
the live `BackendManifest`, the authored `ExperimentTaskModel`, and the actual
79+
validated evidence records/artifact bytes from that run. A future published
80+
RAES satisfaction contract may be consumed there without changing authored
81+
task semantics or adding a repository schema. Until that owner can validate
82+
field-level witnesses and negative data-quality states, the seam returns no
83+
semantic satisfaction claim and lets the canonical task/run validator reject
84+
the run.
85+
86+
A future adapter registers with the existing command/target strategy and is
87+
automatically included by repository-wide claim-integrity tests. It must not
88+
require editing a global evidence allowlist, standard capability grant, copied
89+
schema, or backend-name conditional.
90+
91+
## Gotchas and anti-patterns
92+
93+
- Do not retain `evidence_satisfies_refs`, a backend-name evidence allowlist,
94+
unconditional `supports_* = True`, or a test-only/injected-driver bypass.
95+
- Do not promote a source-ledger reference, capability pointer, conformance
96+
evidence id, capture-spec declaration, content checksum, or evidence-record
97+
existence into per-run satisfaction.
98+
- Do not let an evaluator summary satisfy an action/observation/time-series
99+
requirement when those records and required fields were not emitted.
100+
- Do not treat missing, unavailable, redacted, withheld, lossy, unknown,
101+
unsupported, partial, or unverified as aliases for satisfied.
102+
- Do not define a local field-witness DTO, evidence status enum, validator,
103+
exception hierarchy, manifest extension, profile, registry, or persistence
104+
service to work around a missing RAES contract.
105+
- Do not make positive tests depend only on current adapters. Mutation and
106+
negative cases must catch a new manifest leaf, a new adapter registration,
107+
an omitted artifact, missing required content, a negative data-quality state,
108+
and a static reference reintroduced through any shared path.
109+
110+
## Non-goals and boundaries
111+
112+
Issue #84 does not implement missing action logs, availability or compromise
113+
series, reward-component capture, source qualification, deterministic replay,
114+
scientific equivalence, or new researcher backends. It does not rewrite
115+
authored task semantics merely to keep current examples runnable.
116+
117+
It also does not add or change a RAES schema, capability vocabulary, evidence
118+
type, status model, validator, profile, diagnostic envelope, controller, store,
119+
HTTP surface, console script, distribution, lockfile, or workflow. If a
120+
published RAES contract cannot express and verify the required claim, the
121+
repository records the gap by failing closed rather than creating local
122+
authority.

‎docs/decisions/cyberbattlesim-conformance-guardrails.md‎

Lines changed: 7 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -74,14 +74,12 @@ off as a copied fixture family. The published realization harness is used only
7474
for realization-envelope questions it actually models; it is not a generic hook
7575
for unrelated source-protocol assertions.
7676

77-
Every affirmative manifest capability must join to passing executable evidence.
78-
Derive the capability addresses from `backend_manifest_payload()` at runtime and
79-
join them to stable adapter-probe evidence references. The join may be a small
80-
module-local test/probe inventory, but it is not portable authority: it carries
81-
only manifest JSON pointers and evidence references, contains no copied
82-
capability values or expected manifest payload, and fails closed when a newly
83-
declared affirmative capability has no passing evidence. Negative declarations
84-
and limitations must also be exercised so absence is not mistaken for support.
77+
Every affirmative manifest capability is derived from
78+
`backend_manifest_payload()` at runtime and retained as unresolved inventory.
79+
There is no module-local pointer-to-reference join: a broad conformance pass,
80+
source validation, or adapter probe cannot certify each leaf. Negative
81+
declarations and limitations must also be exercised so absence is not mistaken
82+
for support.
8583
Where RAES already provides `evidence_refs`, `limitation_refs`, claim
8684
`limitations`, or `explicit_non_claims`, reuse those fields rather than creating
8785
adapter equivalents.
@@ -98,7 +96,7 @@ constructed `RuntimeTarget` with an injected deterministic driver to run the
9896
published profile/fixtures and bounded local probes. It must cover manifest and
9997
source/profile identity, all four surfaces on success and failure, reset and
10098
stream dispositions, action/observation/evaluator separation, terminal
101-
semantics, cleanup, capability-to-evidence closure, and portable serialization.
99+
semantics, cleanup, unresolved capability inventory, and portable serialization.
102100
It must not import the native simulator or depend on network, user-home state,
103101
or an editable checkout.
104102

‎docs/decisions/cyberbattlesim-qualification-guardrails.md‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -106,7 +106,8 @@ native-readiness plan must extend this same isolated source-native run instead
106106
of stopping at the upstream smoke. For issue #28, that means running the
107107
adapter conformance path with the real `CyberBattleSimDriver`, serializing the
108108
result through `backend_conformance_report_payload()`, collecting
109-
`cyberbattlesim_source_protocol_diagnostics()` and manifest capability evidence,
109+
`cyberbattlesim_source_protocol_diagnostics()` and unresolved manifest
110+
capability inventory,
110111
and checking the emitted RAES payloads remain bounded and free of native action
111112
ids, observations, reward vectors, object representations, paths, environments,
112113
tracebacks, and hidden state. This is adapter-readiness evidence in this repo;

‎docs/decisions/cyborg-conformance-guardrails.md‎

Lines changed: 20 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -86,22 +86,21 @@ construction.
8686
| Packaging and CI | The single `pyproject.toml`/`uv.lock`, `_verification_envs()`, `_tests()`, `_distributions()`, `probe_installed_identity.py`, the existing CI workflow and `PR Gate`, strict docs/policy gates, and canonical `nox -s verify`. Extend these paths; do not create a second lock, workflow, or unenforced verification graph. |
8787

8888
The CyberBattleSim conformance module is the closest repository precedent for
89-
canonical report projection, manifest-derived evidence closure, RAES
90-
diagnostics, weakness references, and hostile-value tests. Reuse its composition
91-
pattern, not its source protocol, action model, seed semantics, cleanup claims,
92-
capability inventory, or backend-specific helper module.
89+
canonical report projection, RAES diagnostics, weakness references, and
90+
hostile-value tests. Reuse its composition pattern, not its source protocol,
91+
action model, seed semantics, cleanup claims, capability inventory, or
92+
backend-specific helper module.
9393

94-
## Local probes, capability evidence, and leakage
94+
## Local probes, capability inventory, and leakage
9595

9696
Derive affirmative capability JSON pointers from the live
97-
`backend_manifest_payload()` and join them to stable references from probes that
98-
actually passed. A small module-local pointer-to-evidence requirement map is a
99-
closure check, not capability authority: it contains no copied capability
100-
values, fails when a new affirmative surface has no evidence, and does not turn
101-
constraints or component names into capabilities. Exercise negative and
102-
unsupported declarations as well, especially replay, autonomous execution,
103-
bounded concurrency, execution control, accounts, ACLs, generated artifacts,
104-
persistent volumes, and cleanup when undeclared.
97+
`backend_manifest_payload()` as unresolved inventory only. A broad published
98+
conformance disposition, source-ledger validation, or adapter-local probe does
99+
not prove every capability leaf, so there is no pointer-to-evidence requirement
100+
map or positive join. Exercise negative and unsupported declarations as well,
101+
especially replay, autonomous execution, bounded concurrency, execution
102+
control, accounts, ACLs, generated artifacts, persistent volumes, and cleanup
103+
when undeclared.
105104

106105
Weaknesses are machine-resolvable references derived from qualification
107106
`admission.limitations`, `known_defects`, and the selected loss disclosures.
@@ -225,11 +224,12 @@ does not rewrite, append, or locally reclassify that case.
225224
The executable adapter-local probes separately construct a supported switch/VM
226225
topology with a hostile injected native handle, validate the source selection
227226
and every declared runtime surface, verify cleanup, and inspect actual portable
228-
projections. Capability evidence requires all three independent references:
229-
the bounded published conformance disposition, validated source-ledger evidence,
230-
and passing adapter-runtime diagnostics. A future RAES release that publishes a
231-
constructive list-domain or equivalent governed witness seam can replace this
232-
unsupported case without a local schema or profile.
227+
projections. The bounded published conformance disposition, validated
228+
source-ledger evidence, and passing adapter-runtime diagnostics remain three
229+
independent facts; their conjunction is not per-leaf capability evidence. A
230+
future RAES release that publishes a constructive list-domain or equivalent
231+
governed witness seam can replace this unsupported case without a local schema
232+
or profile.
233233

234234
The checked-in full tier remains hermetic at ordered seeds `(3, 153)` and keeps
235235
`native_conformance=false`; the existing qualified-source reproducer owns native
@@ -247,8 +247,8 @@ registry, or environment binding.
247247
A new qualified selection may add source resources, evidence bindings, seeds,
248248
or a native harness without changing the RAES profile corpus, report type,
249249
diagnostic model, control-plane persistence, or cross-simulator base API. A new
250-
affirmative manifest claim automatically creates an evidence-closure gap until
251-
a passing probe reference is joined to its derived pointer.
250+
affirmative manifest claim automatically remains an unresolved inventory gap
251+
until a published contract can verify the owning production path.
252252

253253
## Gotchas and anti-patterns
254254

0 commit comments

Comments
 (0)