Skip to content

Agent pack: structured query verbs, drop GQL skills and --with-commands - #102

Merged
sshaaf merged 18 commits into
mainfrom
199_update
Oct 2, 2026
Merged

sshaaf merged 18 commits into
mainfrom
199_update

Conversation

@sshaaf

@sshaaf sshaaf commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

Summary

Agent pack / structured query (earlier on branch)

  • Prefer mmap structured verbs (find / callers / relations / inventory / status / rules run) for agent workflows; remove GQL from skills and the agent pack.
  • Drop rgctl install --with-commands (skills + optional --with-policy only; install JSON schema_version 3).
  • Migration search primitives: annotation find, import-prefix inventory, session status, Kantra rules run; related skill / encyclopedia / website updates.
  • Constrained discover limits, ingest hot-path / spill / tracker work, and release tooling.

OpenSpec: OSV deps → declarative taint → reachability / OpenVEX

End-to-end agent path:

vuln triage → deps check → find/callers --package → blast-radius --classify-boundary
  → taint --sink … --source external → vuln analyze → OpenVEX

1. add-osv-deps-supply-chain

  • rgctl vuln triage --osv — parse via osv 0.3 schema crate
  • rgctl deps check --osv — manifests + opt-in --include-jars / --include-node-modules
  • Version engines: Maven (incl. -rhlw-), Cargo, npm, Go
  • Verdicts: not_affected | affected_candidate
  • CoolStore fixtures (jackson / xalan); skill workflows/vuln.md; json-api §18

2. add-declarative-taint-rules (#16)

  • TaintRuleSet loads YAML packs, compiles once per language, first-match-wins
  • Tier‑1 packs under crates/rgctl-analysis/rules/taint/ — hardcoded detect_*_patterns removed
  • CWE catalog YAML; default_cwe_patterns() reads it
  • --taint-rules PATH + .rgctl/taint-rules.d/ (built-in < project < CLI); with_overlays for OSV sinks
  • Taint remains opt-in (--with-taint)

3. add-vuln-reachability-vex

  • Package resolver (Maven/npm/Cargo/Go/PyPI + stubs; xalan table; runtime_bundled)
  • find / callers --package + bundled_presence honesty; callers --methods
  • Boundary catalogs (Java/Jakarta + Python); blast-radius --classify-boundary
  • rgctl taint --sink … --source external (CFG required; declarative overlays)
  • rgctl vuln analyze --osv … → OpenVEX (openvex crate)
  • CoolStore A/B release smoke + extended vuln workflow

Live CoolStore validation (before → after)

Probe Before (3 OpenSpecs) After
P1 dep match 🔧 Python zipfile workaround ✅ NATIVE
P2 namespace resolve 🔧 manual gav-namespace-map.json ✅ NATIVE
P4 facade callers ⚠️ partial ✅ NATIVE
P6 taint ⚠️ partial (manual file+line+variable) ✅ NATIVE
Gate PASS 4/6 PASS 7/7
  • rgctl vuln analyze → OpenVEX in 46ms for both scenarios
  • Every probe: ✅ NATIVE

Validated verdicts

  • Xalan: not_affected / component_not_present — 2-phase fast exit
  • Jackson (bundled JAR at 2.13.5): not_affected / vulnerable_code_not_in_execute_path — 5-phase full pipeline; sink-first taint confirmed no external→readValue path

Known follow-ups (not blocking)

  1. discover --with-cfg --with-taint needed for PDG-backed taint confidence (cfg_available=false today)
  2. Xalan’s JDK-bundled path (javax.xml.transform.*) not yet surfaced in find --package resolution output

Test plan

  • CoolStore live gate PASS 7/7 (native probes; OpenVEX ~46ms)
  • cargo test -p rgctl-security --lib
  • cargo test -p rgctl-analysis --lib taint boundary
  • cargo test -p rgctl-agent-pack-codegen
  • cargo build --release --bin rgctl
  • cargo test --release --test osv_deps_release_smoke -- --ignored --nocapture
  • cargo test --release --test taint_rules_release_smoke -- --ignored --nocapture
  • cargo test --release --test vuln_reachability_release_smoke -- --ignored --nocapture (needs example/coolstore)
  • Spot-check: vuln triage / deps check / vuln analyze --include-jars lib on CoolStore; taint --help; no new rgctl-vuln skill dirs

sshaaf added 18 commits October 1, 2026 19:10
    2. Worker prep — line offsets + BLAKE3 + bloom on extract workers (SymbolPass1Prep)
    3. Tracker mapping — accumulated at commit_node; skips full mmap scan/sort
    4. CodeIndex off by default — no code_index.json (was 1.1 GB); code_hash still on nodes
    5. Spill sort runs 256 MiB (was 64 MiB)

Signed-off-by: Shaaf Syed <474256+sshaaf@users.noreply.github.com>
  • Hash reuse — workers set FileExtraction.file_hash; stream → PipelineStats →
    index_files_with_mapping(..., Some(hashes)) (no 71k re-read)
  • Empty tracker — detect_changes marks all as added without hashing (still non-empty so stale
    snapshots aren’t reused)
  • Spill — reusable scratch + bincode::serialize_into
  • Pass-1 batch — begin_file_batch / get_mut on tracker keys

Signed-off-by: Shaaf Syed <474256+sshaaf@users.noreply.github.com>
    ✔ active_tracker_ids Vec push; flush in end_file_batch

Signed-off-by: Shaaf Syed <474256+sshaaf@users.noreply.github.com>
Signed-off-by: Shaaf Syed <474256+sshaaf@users.noreply.github.com>
Signed-off-by: Shaaf Syed <474256+sshaaf@users.noreply.github.com>
Signed-off-by: Shaaf Syed <474256+sshaaf@users.noreply.github.com>
Signed-off-by: Shaaf Syed <474256+sshaaf@users.noreply.github.com>
Signed-off-by: Shaaf Syed <474256+sshaaf@users.noreply.github.com>
  • inventory --by import-prefix
  • rgctl status (digest, nodes/edges, kantra findings hint)
  • rgctl resources (persistence / weblogic / jboss / web / beans)
  • rgctl rules run <DIR> (--target, --index-only, --catalog)
  • Skills + encyclopedia migration probe recipe

Signed-off-by: Shaaf Syed <474256+sshaaf@users.noreply.github.com>
Signed-off-by: Shaaf Syed <474256+sshaaf@users.noreply.github.com>
Signed-off-by: Shaaf Syed <474256+sshaaf@users.noreply.github.com>
Signed-off-by: Shaaf Syed <474256+sshaaf@users.noreply.github.com>
Signed-off-by: Shaaf Syed <474256+sshaaf@users.noreply.github.com>
  • rgctl deps check --osv — manifests + opt-in --include-jars / --include-node-modules
  • Version engines: Maven (incl. -rhlw-), Cargo, npm, Go
  • Skill workflow vuln + docs/json-api.md §18

Signed-off-by: Shaaf Syed <474256+sshaaf@users.noreply.github.com>
… first-match-wins apply

  • Packs: all Tier‑1 languages under crates/rgctl-analysis/rules/taint/ — hardcoded detect_*_patterns removed
  • CWE: default_cwe_patterns() reads cwe-catalog.yaml
  • CLI: --taint-rules PATH + .rgctl/taint-rules.d/ (built-in < project < CLI); with_overlays for OSV sinks
  • Verified: unit + language taint integration + release smoke green; openspec validate clean

Signed-off-by: Shaaf Syed <474256+sshaaf@users.noreply.github.com>
…s; table for xalan; runtime_bundled

  • --package / --methods on find / callers + bundled_presence honesty
  • Boundary catalogs (Java/Jakarta + Python) + blast-radius --classify-boundary
  • rgctl taint --sink … --source external (CFG required; declarative overlays)
  • rgctl vuln analyze --osv … → OpenVEX (openvex crate)
  • Skill vuln workflow + json-api §18; CoolStore A/B release smoke green

Signed-off-by: Shaaf Syed <474256+sshaaf@users.noreply.github.com>
Signed-off-by: Shaaf Syed <474256+sshaaf@users.noreply.github.com>
  • Adds javax.xml.transform and com.sun.org.apache.xalan.internal
  • Sets runtime_bundled: true with a JAXP honesty note
  • Covered by xalan_includes_jdk_jaxp_aliases; vuln skill honesty updated

Signed-off-by: Shaaf Syed <474256+sshaaf@users.noreply.github.com>
@sshaaf
sshaaf merged commit 9de5fcb into main Oct 2, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant