Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -30,5 +30,8 @@ htmlcov/
# Local MCP server registration (machine-specific paths)
.mcp.json

# Local Codex workspace configuration
.codex/

# Ground Control local operational cache (per-run sonar-watch state)
.gc/sonar/
230 changes: 230 additions & 0 deletions docs/decisions/cyborg-cage2-source-ledger-guardrails.md

Large diffs are not rendered by default.

1 change: 1 addition & 0 deletions docs/index.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,7 @@ semantic and protocol authority.
- [Contribution guide](https://github.com/RAESystem/adapters/blob/dev/CONTRIBUTING.md)
- [Architecture decisions](decisions/adrs/README.md)
- [CybORG/CAGE-2 runtime qualification guardrails](decisions/cyborg-cage2-runtime-qualification-guardrails.md)
- [CybORG/CAGE-2 source-ledger guardrails](decisions/cyborg-cage2-source-ledger-guardrails.md)
- [CyberBattleSim qualification guardrails](decisions/cyberbattlesim-qualification-guardrails.md)
- [CyberBattleSim scenario and source-ledger guardrails](decisions/cyberbattlesim-scenario-ledger-guardrails.md)
- [Project services](maintainers/project-services.md)
Expand Down
1 change: 1 addition & 0 deletions mkdocs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,7 @@ nav:
- Overview: decisions/adrs/README.md
- Template: decisions/adrs/TEMPLATE.md
- CybORG/CAGE-2 runtime qualification guardrails: decisions/cyborg-cage2-runtime-qualification-guardrails.md
- CybORG/CAGE-2 source-ledger guardrails: decisions/cyborg-cage2-source-ledger-guardrails.md
- CyberBattleSim qualification guardrails: decisions/cyberbattlesim-qualification-guardrails.md
- CyberBattleSim scenario and source-ledger guardrails: decisions/cyberbattlesim-scenario-ledger-guardrails.md
- ADR 003 — Single distribution and Trusted Publishing: decisions/adrs/adr-003-single-distribution-and-trusted-publishing.md
Expand Down
36 changes: 26 additions & 10 deletions src/raes_adapters/cyborg/mapping/README.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,9 @@
# CAGE-2 → RAES mapping ledger

**Authored under REP-003 (RAES issue for the CAGE-2 scenario + mapping).** This
directory is a placeholder standup under REP-002.
This backend-local evidence bridges the source closure qualified by issue #12
to the published RAES surfaces that can carry each CAGE-2 fact. It does not
author an SDL scenario or experiment, implement a backend, change the
qualification's `not-admissible` result, or establish equivalence.

Per RAES ADR-069 §2 and `docs/decisions/cage-2-replication-design.md`, the
mapping from upstream CAGE-2/CybORG source facts to portable RAES artifacts is a
Expand All @@ -10,13 +12,27 @@ mapping from upstream CAGE-2/CybORG source facts to portable RAES artifacts is a
## Files

- `cage2-source-ledger.jsonl` — one JSON object per source fact. Each row records
`source_id`, `source_repo`, `source_version`, `source_path`, `source_selector`,
optional `source_digest`, `cage_fact_type`, `raes_target`, `mapping_rule`,
`loss_disclosure`, and `verification` (see the design record for field
definitions). Empty until REP-003.
a unique id, source family, fact facet, qualified repository/commit/path/digest,
verifiable selector, disposition, mapping rule, and verification. A mapped or
partially mapped fact cites a published schema-bundle id plus JSON pointer.
Qualification-owned legal evidence uses a `qualification.json` pointer rather
than pretending it is RAES semantics.
- `cage2-loss-disclosures.md` — narrative loss disclosures for source facts RAES
cannot carry exactly. A disclosed gap weakens the replication claim; it is
never backfilled with raw CybORG logs or prose-only evidence.
cannot carry exactly. Each disclosure has a machine-parsed set of weakened
ADR-069 equivalence tiers that must exactly match its ledger rows.

Every upstream source fact must be mapped, explicitly declared out of scope, or
loss-disclosed. No claim may rest on CI success or a single cumulative score.
The module-local validator enforces both completeness axes from the accepted
design: source families (Scenario2/images, actions, observations, rewards,
wrappers, agents, evaluation, and provenance/licensing) and semantic facets
(topology through derived measures plus licensing/attribution). It rejects
malformed or open-ended rows, duplicate ids, coverage gaps, unclassified facts,
source-profile/digest drift, unresolved published targets, selector failures,
and missing/orphan/mismatched loss disclosures. The qualification reproducer
also checks every selector against a detached checkout without importing or
executing upstream code.

Every fact is `mapped`, `out-of-scope`, or `loss-disclosed`. Native state,
observations, hidden truth, action ids, reward vectors, object representations,
raw logs, environment data, and tracebacks remain outside portable artifacts.
No claim may rest on a green validator, CI success, native-log similarity, or a
single cumulative score.
71 changes: 64 additions & 7 deletions src/raes_adapters/cyborg/mapping/cage2-loss-disclosures.md
Original file line number Diff line number Diff line change
@@ -1,11 +1,68 @@
# CAGE-2 → RAES loss disclosures

**Authored under REP-003.** Placeholder standup under REP-002.
These disclosures accompany the source selection
`cage2-cyborg-2.1-source-26ce1c1`. Each heading is a stable ledger reference;
the machine-readable tier line binds the precise ADR-069 claim tiers weakened.
A disclosure permits a bounded claim with the stated weakness. It does not
upgrade the qualification's `not-admissible` decision or establish any
equivalence tier.

Each entry below records an upstream CAGE-2/CybORG source fact that the RAES
mapping cannot carry exactly, the reason, and the effect on the replication
claim (RAES ADR-069 §2, §7). A disclosed gap weakens or fails the relevant
equivalence tier explicitly; it is not filled by raw simulator logs,
fixture-local assertions, or prose-only evidence.
## loss-scenario-user3-port-mismatch

_No disclosures yet — the mapping ledger is authored under REP-003._
**Equivalence tiers weakened:** authored-source, state/observation

The pinned `linux_user_host_image1.yaml` uses local port 3389 for the User3
SQL-injection path, while the maintained successor documents 3390. The ledger
preserves the selected bytes and flags the conflict. A later authored scenario
must choose and justify one value; it cannot claim exact source and
state/observation equivalence for both.

## loss-native-observation-boundary

**Equivalence tiers weakened:** contract, state/observation

CybORG exposes mutable native observation and true-state dictionaries,
simulator enums, process/session records, and wrapper arrays. RAES can carry
bounded visibility projections, observation references, redaction policy, and
evidence references, but those native values and representations are
deliberately not portable. Exact native-payload identity is therefore not a
permitted contract or state/observation claim.

## loss-remove-success-misreport

**Equivalence tiers weakened:** state/observation, outcome/evaluation

The selected `Remove` implementation initializes a successful observation even
when no suspicious process is removed. The mapping records the intended
defensive action and retains the defect; it does not silently reinterpret the
native success flag as an observed state transition or successful outcome.

## loss-wrapper-cutoff-semantics

**Equivalence tiers weakened:** execution-control

`ChallengeWrapper.max_steps` forces its legacy `done` flag when the wrapper
counter reaches the bound. That cutoff is distinct from a source terminal
condition, evaluator trial length, Gym truncation, participant action count,
and cleanup. Until an experiment contract binds those facts separately, an
exact execution-control claim is not permitted.

## loss-evaluation-seed-unbound

**Equivalence tiers weakened:** execution-control, outcome/evaluation

The pinned evaluator does not bind simulator, Python, NumPy, Gym action-space,
or blue-policy random streams. The qualification smoke's seed 3 is a different
two-step source-native probe and cannot fill this gap. Evaluation results
therefore cannot support deterministic execution-control or reproducible
outcome/evaluation claims.

## loss-blue-policy-artifact-unbound

**Equivalence tiers weakened:** authored-source, execution-control, outcome/evaluation

The evaluator instantiates `BlueLoadAgent` without an immutable trained model
artifact. Its fallback creates a fresh PPO policy against Scenario1b, not the
selected Scenario2 evaluation condition. The blue implementation, model bytes,
training provenance, and stochastic state are unbound, so policy-dependent
source, execution, and outcome claims remain unsupported.
Loading
Loading