Skip to content

Prove attack-path ingestion and search bounds - #218

Draft
sodejm wants to merge 2 commits into
mainfrom
codex/issue-199-attack-path-bounds
Draft

sodejm wants to merge 2 commits into
mainfrom
codex/issue-199-attack-path-bounds

Conversation

@sodejm

@sodejm sodejm commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

Summary

Attack-path ingestion and search had configured limits without acceptance proof at each boundary. This change verifies file, aggregate, record, JSONL, and nesting ceilings, fixes empty-container depth accounting in the shared evidence canonicalizer, and adds a dense graph that proves deterministic stopping, ranking, runtime, and memory bounds.

Closes #199.

Acceptance criteria

  • Below, exact, and above-limit inputs cover file bytes, cumulative file bytes, file count, records, JSONL line bytes, and nesting depth. Rejected cumulative inputs leave the accepted budget unchanged.
  • Empty and populated containers obey the same depth limit in canonical and decoder paths. The portable evidence bundle and its manifest match the shared SDK.
  • A dense 61-node, 588-edge fixture has 248,832 possible complete routes and stops at 600 expansions with repeatable counters and ranking.
  • The search-only test enforces a five-second runtime ceiling and a 5,115,904-byte memory ceiling derived from the graph and expansion budget.
  • Documentation explains inclusive ingestion ceilings, cumulative accounting, container depth, and the difference between algorithmic counters and measured resources.
  • Worker isolation, live network execution, and claims of production-scale performance remain outside this change.

Evidence

  • Full plugin suite passed: 84 tests. Root evidence-contract suite passed: 26 tests. Independent review reproduced both suites and the portable bundle generator check on the final integrated head.
  • Full make check passed on the branch integrated with current main.
  • Whole-repository Ruff and git diff --check passed after integration with main.
  • Independent Codex review found no actionable findings on final integrated head ca5bff2c24246b284df8281bfad4fd0993888b5f, based on ba2e8c9fd8d4163d7c94a1d01a76fcb426f708db.
  • All 17 hosted checks passed on ca5bff2c24246b284df8281bfad4fd0993888b5f, including Linux/macOS/Windows smoke, Python 3.11/3.13 validation, Windows SOC, issue coverage, secret/dependency scans and CodeQL.

Impact review

  • Tests: boundary and dense-search acceptance coverage uses fixed local fixtures and includes repeatability assertions.
  • Documentation: updates the attack-path README with the accepted limits and measurement scope.
  • Architecture/migrations: corrects shared container-depth accounting and regenerates the portable evidence bundle; no schema or dependency changes.
  • Security/privacy/abuse: empty nested containers can no longer bypass the depth ceiling. All fixtures are synthetic and local.
  • Operations/rollback: callers that exceeded the intended depth ceiling with empty containers now receive rejection. Rollback would restore that bypass and remove the regression coverage.

Risks and residual uncertainty

The runtime and memory checks cover a deterministic local search fixture, excluding fixture construction. They are regression ceilings rather than a general production benchmark. Hosted operating-system checks remain separate evidence.

sodejm added 2 commits October 5, 2026 21:49
…k-path-bounds

# Conflicts:
#	plugins/detection-hunting/attack-path-workbench/attackpath/_runtime/source-manifest.json

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Prove Attack Path ingestion and graph-search bounds

1 participant