Repository navigation
Conversation
doublewhy
force-pushed
the
88-primaite-evidence-capture-inventory
branch
from
October 9, 2026 11:01
e70404e to
2be12b6
Compare
doublewhy
force-pushed
the
88-primaite-evidence-capture-inventory
branch
from
October 9, 2026 14:43
2be12b6 to
fade521
Compare
Add a static inventory of the NASim SDL and task evidence requirements, their native availability at NetworkAttackSimulator 7c732bc, the capture chain at dev 0272949, the equivalence data needs, and a spec-only regression-fixture design, plus its Decisions nav entry. Docs only, as the 2026-08-13 hold on #87 permits: no contract, schema, manifest, runtime, package, CLI, ledger, or test change. Refs #87
doublewhy
force-pushed
the
88-primaite-evidence-capture-inventory
branch
from
October 9, 2026 14:51
fade521 to
b588bdf
Compare
Add a static inventory of the CAGE-2 SDL and task evidence requirements, their native availability at cage-challenge-2 26ce1c1, the capture chain at dev 0272949 (researcher and reproduce paths), the equivalence data needs, and a spec-only regression-fixture design, plus its Decisions nav entry. Docs only, as the 2026-08-13 hold on #85 permits: no contract, schema, manifest, runtime, package, CLI, ledger, or test change. Refs #85
doublewhy
force-pushed
the
88-primaite-evidence-capture-inventory
branch
from
October 9, 2026 14:53
b588bdf to
2687951
Compare
Add a static inventory of the CyberBattleChain SDL and task evidence requirements, their native availability at CyberBattleSim 854d696, the capture chain at dev 0272949 (including the baseline reproduction's mediated lane), the equivalence data needs, and a spec-only regression-fixture design, plus its Decisions nav entry. The RNG inventory covers every generator that the CredentialCacheExploiter run path seeds or draws from. The gym-environment and gym-action-space seeds that the driver reports as applied drive no draw on that path. Every explore draw comes from the action space's union_np_random, which takes OS entropy at construction, is reached by no seed call, and is not listed by the spec controls, ledger rows 24-25, or loss-unbound-random-streams. Per-step reward is classed withheld under the task's source-private boundary. Docs only, as the 2026-08-13 hold on #86 permits: no contract, schema, manifest, runtime, package, CLI, ledger, or test change. Refs #86
Add a static inventory of the PrimAITE data_manipulation SDL and task evidence requirements, their native availability at PrimAITE v4.0.0 (9861798), the capture chain at dev 0272949, the equivalence data needs, and a spec-only regression-fixture design, plus its Decisions nav entry. Docs only, as the 2026-08-13 hold on #88 permits: no contract, schema, manifest, runtime, package, CLI, ledger, or test change. Refs #88
doublewhy
force-pushed
the
88-primaite-evidence-capture-inventory
branch
from
October 9, 2026 15:10
2687951 to
3d3f0c3
Compare
doublewhy
marked this pull request as ready for review
October 9, 2026 15:39
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds
docs/decisions/primaite-evidence-capture-inventory.md, the static inventory and regression-fixture design that the 2026-08-13 hold on #88 permits, plus one Decisions nav line inmkdocs.yml. It follows the format set by #98 (NASim). Atdev0272949the page records:blue-action-log,data-integrity-series,service-availability-series, the five task metrics, and the observation requirements, each with file and line. PrimAITE has no packaged example, so the scenario and experiment files are the only copies;v4.0.0(9861798) and its class, citing the existingmapping/source-ledger.jsonlrows and loss disclosures;PrimaiteGymEnv, marked present, partly present, or missing;Findings worth a look, all recorded as facts without changing anything:
dev. PrimAITE is not in the researcher CLI registry, and the live driver refuses in-process construction. The participant runtime rejects a BLUE action as unrepresentable, before source mutation, when the driver reportsrepresentable=False; the default testFakeDriverdoes that on every step, and the evaluator withholds the reward. A driver that reports a representable step reaches an accepted path that only unit tests exercise: it records an observation envelope per accepted action and attachesevidence.primaite.blue-actionwhen the observation boundary lists that ref. The ref is not the SDL'sblue-action-log.info["agent_actions"], and the database file'shealth_statusis in the simulation state. So is each service'soperating_state, which gates whether the service can perform actions, beside a separate health signal,health_state_actual; the page records both as R3 candidates for fix(primaite): reconcile SDL evidence requirements, simulator capture, and backend manifest #88. The ledger keeps the info dict and native action ids source-private.RewardFunction.updatekeeps only the weighted total, not each component's value. The BLUE total can still be recomputed from the file-health state and the two GREEN agents' rewards, which PrimAITE writes, withheld, into each GREEN history item'sreward.The hold on #88 remains in force. The naming decision, OpenRAE/rae#1023, is still open; the other resume condition, OpenRAE/rae#1112, closed on 2026-09-07.
Stacking
All four inventory PRs add one line to the same
mkdocs.ymlnav list, so they are stacked. This branch contains #98's commitd89aa60(NASim, Refs #87), #99's commitac496e5(CybORG, Refs #85), and #100's commitcf4a7c8(CyberBattleSim, Refs #86), followed by its own commit3d3f0c3; review only3d3f0c3. Merge #98, #99, and #100 first, and this branch will then be rebased ontodev.CI note
SonarCloud fails before any analysis. The scanner's JRE metadata request to
api.sonarcloud.ioreturnsHTTP 403 Forbidden, and the error says to checkSONAR_TOKEN(CI run 37949738253, SonarCloud job). PR Gate then fails, because it requires SonarCloud to succeed on same-repository PRs. The same 403 occurs ondev0272949in workflow_dispatch run 37919671796; the last passing SonarCloud job ondevwas in run 32215409423 on 2026-08-19. Every other job passes at3d3f0c3: Fast checks, Policy, Tool tests, Typecheck, Tests, Distributions, Docs, CodeQL, Lint PR title, and GitGuardian.Requirement UIDs
Related Issues
Refs #88
ADR Impact
adr-index.yamlis untouched.Changes
docs/decisions/primaite-evidence-capture-inventory.md(new): the inventory and fixture design. Source references are GitHub links pinned to adapters0272949, PrimAITE9861798, and RAESv3.3.0(fb8a23a), because the Read the Docs site returns 404.mkdocs.yml: one nav entry under Decisions, after the PrimAITE conformance-composition guardrails.mapping/ledgers are cited, not edited.Test Plan
All commands ran in the worktree at head
3d3f0c3on 2026-10-09.uv tool run --from 'nox[uv]==2026.4.10' nox -f noxfile.py -s docs: the strict MkDocs build passed. The rendered page has 6 tables and 100 GitHub links (95 pinned to a commit, plus 5 issue and pull-request links), and no reference-style link is left unresolved.nox -s hygiene,nox -s lint, andnox -s tool-tests(same invocation): passed;tool-testsran 53 tests.nox -s policy -- --skip-requirement --base-rev origin/dev: repo policy, ADR immutability, project services, and identity policy OK; requirement governance skipped, as CI does for a branch name without a UID.uv buildat this head and atorigin/dev: the wheels are byte-identical (SHA-256068871d1866b944cf65a695f5c49c1a6c8705b334aea565a54b19819d341ebc6), and the 193 sdist members are identical in names and bytes.9861798through the GitHub API. The four listed inqualification.jsonsource_files(environment.py,game.py,probabilistic_agent.py,data_manipulation.yaml) matched their recorded SHA-256. The other six (interface.py,rewards.py,file_system_item_abc.py,software.py,service.py,database_service.py) are not in that list and were read at the commit. No native PrimAITE episode was run.typecheck,tests, anddistributions. The PR adds fourdocs/decisions/*-evidence-capture-inventory.mdpages and fourmkdocs.ymlnav lines. No test or type-checked module reads them, and of the gates only the docs, hygiene, policy, and tool-tests runs above readmkdocs.yml. CI runs all three.Ground Control Checks
Traceability
Checklist
CHANGELOG.mdedit.Documentation
New decision record listed in the MkDocs Decisions nav.