Repository navigation
feat(report): annotate static findings with structured source roles - #811
Open
optimization2026 wants to merge 1 commit into
Open
optimization2026 wants to merge 1 commit into
optimization2026 wants to merge 1 commit into
Conversation
Add bounded, occurrence-level source-role annotations to reports while preserving existing findings and risk scoring. Refs NVIDIA#130. Follow-up to NVIDIA#211. Signed-off-by: AISOP.dev <noreply@AISOP.dev>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Add bounded, report-only source-role annotations for static findings in supported local AISOP/AISP JSON files.
This is a conservative first increment of Phase 2 in #130, building on the phase-1 discovery and summaries in #211. It does not implement Phase 3 or close the broader issue.
The practical improvement is occurrence-level context: when identical text appears in an executable step and a constraint, each reported occurrence receives its own structural role and JSON Pointer rather than borrowing the representative occurrence's context.
Implementation
evidence.structured_source_roleto occurrence-specific display copies, after baseline suppression, risk calculation and finding compaction.risk_polarityremainsunknown;role_confidenceisnull, not an uncalibrated probability.No new production dependency, workflow execution, resource traversal or filesystem reopening is introduced.
Safety and scope boundaries
Canonical findings, fingerprints, original severities, detection confidence, suppression decisions and risk results are not enriched or downgraded. The MCP response's embedded report carries annotations; its canonical findings array remains unchanged.
Precise mapping requires an admitted local
.aisop.jsonsource, matching raw/text caches, scanner-owned static origin and exact original columns. Transitive provenance, normalized or reconstructed views, missing columns and ambiguous ownership remain unknown. Suppressed findings are not annotated.A structural
constraintlabel is not proof that a policy was enforced or that the text is benign. Non-reserved function fields remain executable steps even when namedhard_denyorexample.This is source-location context, not protocol certification, runtime conformance or a demonstrated reduction in false positives.
Validation
Submitted change on the updated base
Windows, Python 3.12.9, with an independent installed environment and verified imports from the submission checkout.
Base:
a0d489e67f847aeedb5e6d471adfbbafc9e15670.src/andtests/.The selected regression files cover reporting, deduplication, suppression, finding models, phase-1 structured summaries, shared source-location helpers and static-runner filtering.
Commands for the selected test groups
python -m pytest -q -ra -m "not integration and not provider" \ tests/unit/test_structured_source.py \ tests/unit/test_structured_role_report.py \ tests/nodes/test_structured_role_reporting.pypython -m pytest -q -ra -m "not integration and not provider" \ tests/nodes/test_report.py \ tests/nodes/test_deduplicate.py \ tests/unit/test_suppression.py \ tests/test_models.py \ tests/nodes/analyzers/test_structured_skill_roles.py \ tests/nodes/analyzers/test_common.py \ tests/nodes/analyzers/test_static_runner_filtering.pyThese are targeted checks, not the complete upstream CI suite. The existing
test_static_runner_prepared_context.pywas not included in this clean-checkout selection.Earlier evidence, kept separate by revision
On the original base,
3c8e4b958fda9602e0044885f766be0e49f03585, the same final eight feature files passed 6/6 separate static-only native-directory acceptance cases: graph invocation, the in-process CLI application and MCPrun_scan, each with JSON and SARIF output.The synthetic directory had no
SKILL.mdsidecar. The checks verified both P1 occurrence roles and original source ranges, source digests, report structure, and canonical-finding isolation where exposed. This did not test the console launcher or MCP transport. These six cases were not rerun after the base update.An earlier, pre-budget-fix candidate completed a broader regular Windows run with 10,693 passed and 16 failed. Eleven non-release failures were reproduced on the clean original baseline with matching classified outcomes. Five release-test failures remain unvalidated under safe Windows fake-CLI isolation. These failures are not treated as passes.
The complete upstream CI suite has not passed locally, and no current-candidate full-suite or complete cross-platform result is claimed.
Change boundary
Eight files only: two existing production files, two new production modules, three test files and one documentation file.
No changes to dependency manifests, lockfiles, release tooling, CI workflows or existing upstream tests. Local diagnostic scripts and test-compatibility patches are not part of this PR.
Refs #130. Follow-up to #211.