Skip to content
Merged

Dev #545

Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
159 commits
Select commit Hold shift + click to select a range
6958fed
fix: consolidate runtime validation helpers
Brad-Edwards Jun 6, 2026
b462808
Add participant runtime lifecycle contracts
Brad-Edwards Jun 6, 2026
b270a53
Fix SonarCloud findings (cycle 1)
Brad-Edwards Jun 6, 2026
913be3a
Fix SonarCloud findings (cycle 2)
Brad-Edwards Jun 6, 2026
89a349d
Remove runtime secret-name value omission
Brad-Edwards Jun 6, 2026
526ae02
Merge pull request #475 from Brad-Edwards/471-runtime-secret-fixtures
Brad-Edwards Jun 6, 2026
b36046c
Merge origin/dev into 442-validation-doc-adr-cleanup
Brad-Edwards Jun 7, 2026
bfab7e1
Merge pull request #472 from Brad-Edwards/442-validation-doc-adr-cleanup
Brad-Edwards Jun 7, 2026
1578f32
Merge branch 'dev' into 193-run-306-lifecycle
Brad-Edwards Jun 7, 2026
a9c8ea6
Merge pull request #474 from Brad-Edwards/193-run-306-lifecycle
Brad-Edwards Jun 7, 2026
e7d28b0
Register gap remediation overlay skill
Brad-Edwards Jun 7, 2026
ee74846
Merge pull request #477 from Brad-Edwards/445-gap-remediation-overlay
Brad-Edwards Jun 7, 2026
e782722
Add structured datastore mapping manifests
Brad-Edwards Jun 7, 2026
adf63e5
Add datastore cardinality fields
Brad-Edwards Jun 7, 2026
e40e4bd
Merge remote-tracking branch 'origin/dev' into 468-dsl-132-datastore-…
Brad-Edwards Jun 7, 2026
579038d
Merge remote-tracking branch 'origin/dev' into 469-dsl-132-index-mapping
Brad-Edwards Jun 7, 2026
b3c7609
Add DSL-141 datastore-node engine provenance and listener topology
Brad-Edwards Jun 7, 2026
6bf02f6
Merge pull request #480 from Brad-Edwards/470-DSL-141-node-provenance
Brad-Edwards Jun 8, 2026
b4eebae
Merge remote-tracking branch 'origin/dev' into 469-dsl-132-index-mapping
Brad-Edwards Jun 8, 2026
b5d72ee
Merge remote-tracking branch 'origin/dev' into 468-dsl-132-datastore-…
Brad-Edwards Jun 8, 2026
0a7b791
Merge pull request #478 from Brad-Edwards/469-dsl-132-index-mapping
Brad-Edwards Jun 8, 2026
b65728f
Merge remote-tracking branch 'origin/dev' into 468-dsl-132-datastore-…
Brad-Edwards Jun 8, 2026
ac5279a
Merge pull request #479 from Brad-Edwards/468-dsl-132-datastore-cardi…
Brad-Edwards Jun 9, 2026
a0ee353
Add ADR amendment policy (ADR-059) and acceptance-content pin gate
Brad-Edwards Jun 10, 2026
8c58ab5
Merge pull request #510 from Brad-Edwards/481-adr-amendment-policy
Brad-Edwards Jun 10, 2026
93cb593
Harden participant-semantics lineage with missing primary theory
Brad-Edwards Jun 11, 2026
6c0d2d7
Fix participant-runtime spec defects and lineage attribution
Brad-Edwards Jun 11, 2026
5d130d4
Correct SEM-214/SEM-215 coverage row and time-semantics waves
Brad-Edwards Jun 11, 2026
62163b2
Supplement remediation: ADR-054 attribution fix and changelog fragments
Brad-Edwards Jun 11, 2026
5df5469
Add participant backend-contract design: ADR-060, spec section, resea…
Brad-Edwards Jun 11, 2026
20120e4
Publish participant backend-contract schema family and API-407 manife…
Brad-Edwards Jun 11, 2026
c9a7187
Fix review findings: context-view provenance and view-scope binding
Brad-Edwards Jun 11, 2026
d0387a2
Make API-408 view scope binding structural via projected nested types
Brad-Edwards Jun 11, 2026
faf142c
Bind nested recorded-record scope recursively in history views
Brad-Edwards Jun 11, 2026
b0aa82b
Merge pull request #515 from Brad-Edwards/76-API-406-participant-back…
Brad-Edwards Jun 12, 2026
2b77b83
Tighten ADR corpus hygiene
Brad-Edwards Jun 12, 2026
c5f12bd
Merge pull request #517 from Brad-Edwards/482-adr-corpus-hygiene
Brad-Edwards Jun 12, 2026
07df441
Add FM classification assurance gate
Brad-Edwards Jun 13, 2026
0eb4ce7
Merge pull request #518 from Brad-Edwards/483-fm-classification-gate
Brad-Edwards Jun 13, 2026
1250236
Fix inventory capture secret boundary
Brad-Edwards Jun 13, 2026
6cbd8bc
Merge remote-tracking branch 'origin/dev' into 516-capture-no-redact
Brad-Edwards Jun 13, 2026
2242055
Accept participant ADR dependency chain
Brad-Edwards Jun 13, 2026
26e5abb
Merge pull request #519 from Brad-Edwards/516-capture-no-redact
Brad-Edwards Jun 13, 2026
8a54416
Record ADR acceptance amendments
Brad-Edwards Jun 13, 2026
5e08fab
Merge branch 'dev' into 484-resolve-adr-statuses
Brad-Edwards Jun 13, 2026
cee0543
Merge pull request #520 from Brad-Edwards/484-resolve-adr-statuses
Brad-Edwards Jun 13, 2026
8e72c99
Add semantic invariant regression tests
Brad-Edwards Jun 13, 2026
4ff6d2b
Add assurance fulfillment gate for classified formal subsystems
Brad-Edwards Jun 13, 2026
58738aa
Merge pull request #522 from Brad-Edwards/488-composition-window-fixt…
Brad-Edwards Jun 13, 2026
7b0fa87
Merge branch 'dev' into 485-assurance-fulfillment-gate
Brad-Edwards Jun 13, 2026
798566e
Add participant semantics invariant oracle
Brad-Edwards Jun 13, 2026
dbd1242
Merge remote-tracking branch 'origin/dev' into 487-participant-invari…
Brad-Edwards Jun 13, 2026
c65775f
Add participant runtime invariant oracle
Brad-Edwards Jun 13, 2026
5419ae2
Merge remote-tracking branch 'origin/dev' into 486-runtime-invariant-…
Brad-Edwards Jun 13, 2026
647ccf9
Merge pull request #525 from Brad-Edwards/486-runtime-invariant-oracle
Brad-Edwards Jun 13, 2026
bc1fcbe
Merge branch 'dev' into 485-assurance-fulfillment-gate
Brad-Edwards Jun 13, 2026
47993c1
Merge pull request #523 from Brad-Edwards/485-assurance-fulfillment-gate
Brad-Edwards Jun 13, 2026
eeb94f8
Merge branch 'dev' into 487-participant-invariant-oracle
Brad-Edwards Jun 13, 2026
520a4f4
Merge pull request #524 from Brad-Edwards/487-participant-invariant-o…
Brad-Edwards Jun 13, 2026
c54925f
Point SonarCloud config at brad-edwards personal org
Brad-Edwards Jun 13, 2026
447d935
Merge branch 'dev' into sonar-personal-org-rebind
Brad-Edwards Jun 13, 2026
0043fda
Wait on SonarCloud quality gate in CI (#527)
Brad-Edwards Jun 13, 2026
5954f77
Merge remote-tracking branch 'origin/sonar-personal-org-rebind' into …
Brad-Edwards Jun 13, 2026
14aae7d
Merge pull request #526 from Brad-Edwards/sonar-personal-org-rebind
Brad-Edwards Jun 14, 2026
c79b750
Add episodes concept authority family
Brad-Edwards Jun 14, 2026
842f524
Add explicitness classifier semantics
Brad-Edwards Jun 14, 2026
4eb9604
Add runtime profile guard invariant lint
Brad-Edwards Jun 14, 2026
99c95b7
Merge pull request #528 from Brad-Edwards/492-episodes-family
Brad-Edwards Jun 14, 2026
9a36005
Merge branch 'dev' into 503-runtime-profile-guards
Brad-Edwards Jun 14, 2026
766becc
Fix SonarCloud findings (cycle 1)
Brad-Edwards Jun 14, 2026
0ab6906
Add schema publication compatibility gates
Brad-Edwards Jun 14, 2026
e624dea
Fix verify contract argument filtering
Brad-Edwards Jun 14, 2026
7e337d1
Merge remote-tracking branch 'origin/dev' into 489-sem-218-classifier
Brad-Edwards Jun 14, 2026
26a22da
Merge pull request #529 from Brad-Edwards/489-sem-218-classifier
Brad-Edwards Jun 14, 2026
8091052
Merge branch 'dev' into 497-schema-version-gate
Brad-Edwards Jun 14, 2026
8b0eea9
Merge branch 'dev' into 503-runtime-profile-guards
Brad-Edwards Jun 14, 2026
7ccda79
Merge pull request #531 from Brad-Edwards/497-schema-version-gate
Brad-Edwards Jun 14, 2026
170bf8f
Merge branch 'dev' into 503-runtime-profile-guards
Brad-Edwards Jun 14, 2026
3d11e8a
Merge pull request #530 from Brad-Edwards/503-runtime-profile-guards
Brad-Edwards Jun 14, 2026
33ded61
Add runtime-inventory concept family and node runtime reference model
Brad-Edwards Jun 14, 2026
0aa4096
Merge branch 'dev' into 493-GOV-918-runtime-inventory
Brad-Edwards Jun 14, 2026
c24d364
Merge pull request #532 from Brad-Edwards/493-GOV-918-runtime-inventory
Brad-Edwards Jun 14, 2026
eee28c0
Add SEM-218 typed compiler emission and planner realization-support gate
Brad-Edwards Jun 14, 2026
a2b6676
Define "surface" normatively and classify agent-guidance authority
Brad-Edwards Jun 14, 2026
502b3e7
Fix SonarCloud findings (cycle 1)
Brad-Edwards Jun 14, 2026
5e77a5d
Flip published-schema authority direction per ADR-009 §7
Brad-Edwards Jun 14, 2026
5386ff5
Merge pull request #534 from Brad-Edwards/494-surface-authority
Brad-Edwards Jun 14, 2026
006c245
Merge branch 'dev' into 499-flip-schema-authority
Brad-Edwards Jun 14, 2026
dcb17cc
Merge pull request #535 from Brad-Edwards/499-flip-schema-authority
Brad-Edwards Jun 14, 2026
9b4b28a
Verify test integration in semantic-coverage gate (#504)
Brad-Edwards Jun 14, 2026
d162bbc
Add UCO alignment evidence contract (uco-alignment-v1)
Brad-Edwards Jun 14, 2026
312ec62
Merge branch 'dev' into 504-coverage-gate-integration
Brad-Edwards Jun 14, 2026
5044349
Merge pull request #536 from Brad-Edwards/504-coverage-gate-integration
Brad-Edwards Jun 14, 2026
61889bd
Merge remote-tracking branch 'origin/dev' into 495-uco-alignment-mapping
Brad-Edwards Jun 14, 2026
022e754
Record uco-alignment-v1 schema publication ledger entry
Brad-Edwards Jun 14, 2026
83971e1
Merge branch 'dev' into 490-ASR-519-realization-gate
Brad-Edwards Jun 14, 2026
38f925f
Merge pull request #533 from Brad-Edwards/490-ASR-519-realization-gate
Brad-Edwards Jun 14, 2026
37d2cad
Merge branch 'dev' into 495-uco-alignment-mapping
Brad-Edwards Jun 14, 2026
9cbb600
Merge pull request #538 from Brad-Edwards/495-uco-alignment-mapping
Brad-Edwards Jun 14, 2026
220d5ee
Author the SDL prose specification under specs/sdl/ (CT-6)
Brad-Edwards Jun 14, 2026
fef4064
Mark SDL-registration real-repo test as integration
Brad-Edwards Jun 14, 2026
39b608b
Merge branch 'dev' into 498-sdl-prose-spec
Brad-Edwards Jun 14, 2026
792c207
Merge pull request #540 from Brad-Edwards/498-sdl-prose-spec
Brad-Edwards Jun 14, 2026
0fe78e3
Differentiate instantiated-scenario schema from authoring-input
Brad-Edwards Jun 14, 2026
fdd26d0
Fix SonarCloud findings (cycle 1)
Brad-Edwards Jun 14, 2026
9a0a8b2
Ship contract corpus as package data and add a versioned release line
Brad-Edwards Jun 14, 2026
a1d9128
Merge remote-tracking branch 'origin/dev' into 537-ship-contract-corpus
Brad-Edwards Jun 14, 2026
07ae6f3
Route merged uco-alignment corpus loaders through the importlib.resou…
Brad-Edwards Jun 14, 2026
f66f7d2
Fix SonarCloud findings (cycle 1)
Brad-Edwards Jun 14, 2026
bd81333
Merge branch 'dev' into 500-instantiated-schema-constraints
Brad-Edwards Jun 14, 2026
3dd1bf0
Merge pull request #542 from Brad-Edwards/500-instantiated-schema-con…
Brad-Edwards Jun 14, 2026
7cb20f7
added: concept-authority catalog governance gate (ADR-062)
Brad-Edwards Jun 14, 2026
cb95539
Merge branch 'dev' into 537-ship-contract-corpus
Brad-Edwards Jun 14, 2026
8c0ddd8
Merge pull request #543 from Brad-Edwards/537-ship-contract-corpus
Brad-Edwards Jun 14, 2026
b8c21d9
Merge branch 'main' into dev
Brad-Edwards Jun 14, 2026
448e2a0
Merge branch 'dev' into 496-GOV-918-concept-auth-gate
Brad-Edwards Jun 14, 2026
05068f5
Merge pull request #544 from Brad-Edwards/496-GOV-918-concept-auth-gate
Brad-Edwards Jun 14, 2026
fa8786e
Validate worked examples against published JSON Schema (CT-4)
Brad-Edwards Jun 15, 2026
19b1150
Add changelog fragment for example schema-conformance tests (#501)
Brad-Edwards Jun 15, 2026
1201c33
Merge branch 'dev' into 501-ASR-504-validate-examples
Brad-Edwards Jun 15, 2026
44f636d
Merge pull request #546 from Brad-Edwards/501-ASR-504-validate-examples
Brad-Edwards Jun 15, 2026
86b1ea0
Add determinism witness for SDL parse/instantiate/compile pipeline
Brad-Edwards Jun 15, 2026
b390fd5
Add changelog fragment for determinism witness (#506)
Brad-Edwards Jun 15, 2026
38789b1
Specify SDL error-vs-advisory boundary normatively (review IMP-3)
Brad-Edwards Jun 15, 2026
214045d
Realize SEM-218 runtime non-approximation gate and snapshot provenanc…
Brad-Edwards Jun 15, 2026
a3a9318
Merge branch 'dev' into 506-determinism-witness
Brad-Edwards Jun 15, 2026
2f72809
Merge pull request #547 from Brad-Edwards/506-determinism-witness
Brad-Edwards Jun 15, 2026
5c62305
Merge branch 'dev' into 505-error-advisory-boundary
Brad-Edwards Jun 15, 2026
930c39b
Merge pull request #548 from Brad-Edwards/505-error-advisory-boundary
Brad-Edwards Jun 15, 2026
41ebcdf
Fix SonarCloud findings (cycle 1)
Brad-Edwards Jun 15, 2026
e05f4d0
Fix SonarCloud findings (cycle 2)
Brad-Edwards Jun 15, 2026
7848633
Tighten citation hygiene across SDL lineage and precedent docs
Brad-Edwards Jun 15, 2026
ab2db50
Add related-work comparison positioning ACES against precedent systems
Brad-Edwards Jun 15, 2026
517e4c3
Merge branch 'dev' into 491-ASR-519-realization-gate
Brad-Edwards Jun 15, 2026
87564e6
Merge pull request #549 from Brad-Edwards/491-ASR-519-realization-gate
Brad-Edwards Jun 15, 2026
7024618
Add backend conformance proof tests with seeded violations
Brad-Edwards Jun 15, 2026
67f229a
Merge branch 'dev' into 508-related-work-comparison
Brad-Edwards Jun 15, 2026
0fe9f1f
Merge pull request #552 from Brad-Edwards/508-related-work-comparison
Brad-Edwards Jun 15, 2026
c732d7a
Merge branch 'dev' into 502-ASR-502-conformance-proof
Brad-Edwards Jun 15, 2026
c3d492b
Merge pull request #553 from Brad-Edwards/502-ASR-502-conformance-proof
Brad-Edwards Jun 15, 2026
5ac9a00
Merge branch 'dev' into 509-citation-hygiene-batch
Brad-Edwards Jun 15, 2026
0059d03
Merge pull request #550 from Brad-Edwards/509-citation-hygiene-batch
Brad-Edwards Jun 15, 2026
c380206
Make local import lockfile resolved_source checkout-independent
Brad-Edwards Jun 15, 2026
6d3b87d
Merge branch 'dev' into 551-portable-import-lock
Brad-Edwards Jun 15, 2026
24e384b
Backfill schema-publication ledger entries for participant contract f…
Brad-Edwards Jun 15, 2026
15b7121
Merge pull request #554 from Brad-Edwards/551-portable-import-lock
Brad-Edwards Jun 15, 2026
b957b72
Merge branch 'dev' into fix-schema-ledger-backfill
Brad-Edwards Jun 15, 2026
27c2fb0
Merge pull request #555 from Brad-Edwards/fix-schema-ledger-backfill
Brad-Edwards Jun 15, 2026
a55b649
Bump 5 Python dependencies to clear moderate Dependabot advisories
Brad-Edwards Jun 15, 2026
6858d74
Split aces_sdl.validator into a per-seam mixin package
Brad-Edwards Jun 15, 2026
6f92de5
Reduce SemanticValidator complexity flagged by SonarCloud
Brad-Edwards Jun 15, 2026
fe9ef08
Merge pull request #557 from Brad-Edwards/42-split-validator
Brad-Edwards Jun 15, 2026
a6e9c7b
Merge branch 'dev' into chore-dependabot-security-bumps
Brad-Edwards Jun 17, 2026
8cbd442
Merge pull request #556 from Brad-Edwards/chore-dependabot-security-b…
Brad-Edwards Jun 18, 2026
b875ee6
test: trim tautological self-checks from participant spec-oracle suites
Brad-Edwards Jun 18, 2026
1f754d5
Split oversized source files and cut two functions' complexity (Sonar…
Brad-Edwards Jun 18, 2026
c91c71f
Merge pull request #559 from Brad-Edwards/558-trim-spec-oracle-tautol…
Brad-Edwards Jun 20, 2026
1230172
Merge branch 'dev' into fix-sonar-modularity-545
Brad-Edwards Jun 20, 2026
25e4b26
Merge pull request #560 from Brad-Edwards/fix-sonar-modularity-545
Brad-Edwards Jun 20, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
42 changes: 30 additions & 12 deletions .claude/skills/aces-asset-inventory-capture/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -20,8 +20,12 @@ For Docker/Compose/container-image captures, start by copying
`scripts/capture-container-evidence-template.sh` and
`scripts/normalize-syft-cyclonedx.jq` into the target bundle as runnable capture
resources, then tailor the copied script for asset-specific source paths,
filesystem manifests, and redaction names. Keep every evidence-affecting
normalization in the script or a referenced jq file.
filesystem manifests, and any explicit operator/out-of-scenario withholding
rules. Set `CAPTURE_BOUNDARY=scenario-target` only after confirming the script
is pointed at participant-discoverable target state, and set
`OPERATOR_SECRET_NAME_REGEX` only for material classified outside that boundary.
Keep every evidence-affecting normalization in the script or a referenced jq
file.

## Inputs

Expand All @@ -47,10 +51,10 @@ Produce a bundle that validates with the current APTL reference ledger tooling:
- `capture-evidence.sh` or equivalent committed capture commands, derived from
the template for Docker/Compose assets when applicable;
- `mapping-ledger.yaml` using the current reference ledger schema;
- `evidence/` with raw or redacted evidence files;
- `evidence/` with source evidence files;
- `evidence/capture-limits.txt` with one first-class limit for every skipped
required step, declined useful-optional step, contamination boundary, or
redaction that changes what was captured;
operator/out-of-scenario withholding that changes what was captured;
- `evidence/captured-at-utc.txt`;
- `evidence/evidence-sha256sums.txt` covering committed evidence files.

Expand Down Expand Up @@ -117,13 +121,26 @@ No `needs_gap_triage` row may remain at review time.
intact and separate filesystem provenance is captured or the omission is
recorded in `capture-limits.txt`.

5. Hash and redact before committing.

Follow ADR-029 redaction discipline. Do not place credentials, bearer
tokens, private keys, generated service secrets, cookies, session ids, or
operator-only values in evidence, logs, argv, tracebacks, issue comments, or
`mapping-ledger.yaml`. Participant-visible fixture secrets may be retained
only through the repo-approved secret-fixture classification.
5. Preserve scenario-target secrets and withhold only operator material.

Follow ADR-057 as the inventory boundary. Scenario-target secrets are
capture facts and must not be redacted from source inventory bundles when a
participant or in-range agent could discover them. This includes passwords,
hashes, private keys, tokens, generated range secrets, service config
secrets, and security product state required to realize or inspect the
target. The Wazuh/OpenSearch Security `internal_users.yml` bcrypt hashes
from APTL #341 are the canonical example: preserve them unredacted in the
source evidence bundle because they are target configuration facts.

Operator/out-of-scenario secrets remain outside the inventory boundary.
Host SSH keys, cloud or CI tokens, maintainer credentials, local
control-plane secrets, workstation secrets, and accidental adjacent
environment material must not be captured as scenario facts. Exclude them
or record a first-class `capture-limits.txt` entry describing the withheld
scope. ADR-029 still governs operator-secret handling in logs, argv,
tracebacks, issue comments, and other non-evidence surfaces.
Sanitized/public exports are separate derived views; do not replace source
evidence with `<REDACTED>` placeholders as the default safety mechanism.

6. Build the ledger fact-by-fact.

Expand Down Expand Up @@ -200,7 +217,8 @@ Before returning:
- every evidence file is referenced from `mapping-ledger.yaml`;
- `capture-limits.txt` records skipped methodology steps as first-class
limits;
- no raw secrets or operator-only values are committed;
- scenario-target secrets are preserved as source capture facts, while
operator/out-of-scenario material is excluded or recorded as a capture limit;
- `aptl aces-inventory validate <asset-dir>` passes;
- `aptl aces-inventory gaps <asset-dir>` has no unresolved
`needs_gap_triage`;
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,8 @@ CONTAINER="${CONTAINER:-}"
COMPOSE_FILE="${COMPOSE_FILE:-$ROOT/docker-compose.yml}"
COMPOSE_SERVICE="${COMPOSE_SERVICE:-}"
COMPOSE_PROFILES="${COMPOSE_PROFILES:-}"
SECRET_NAME_REGEX="${SECRET_NAME_REGEX:-(token|secret|password|credential|cookie|session|private_key|api_key|jwt|flag_key)}"
CAPTURE_BOUNDARY="${CAPTURE_BOUNDARY:-}"
OPERATOR_SECRET_NAME_REGEX="${OPERATOR_SECRET_NAME_REGEX:-}"

TRIVY_IMAGE="${TRIVY_IMAGE:-aquasec/trivy@sha256:be1190afcb28352bfddc4ddeb71470835d16462af68d310f9f4bca710961a41e}"
SYFT_IMAGE="${SYFT_IMAGE:-anchore/syft@sha256:86fde6445b483d902fe011dd9f68c4987dd94e07da1e9edc004e3c2422650de6}"
Expand All @@ -26,12 +27,25 @@ require() {
}
}

require_capture_boundary() {
if [[ "$CAPTURE_BOUNDARY" != "scenario-target" ]]; then
printf '%s\n' \
"Set CAPTURE_BOUNDARY=scenario-target after confirming this capture is scoped to participant-discoverable target state." \
"Use OPERATOR_SECRET_NAME_REGEX only for operator/out-of-scenario material that must be withheld." >&2
exit 2
fi
}

record_limit() {
printf -- '- %s\n' "$*" >> "$OUT/capture-limits.txt"
}

redact_text_stream() {
awk -v secret_re="$SECRET_NAME_REGEX" '
if [[ -z "$OPERATOR_SECRET_NAME_REGEX" ]]; then
cat
return
fi
awk -v secret_re="$OPERATOR_SECRET_NAME_REGEX" '
{
for (i = 1; i <= NF; i++) {
token = $i
Expand All @@ -57,7 +71,7 @@ redact_text_stream() {

redact_env_jq='
def redact_env($secret_re):
if contains("=") then
if (($secret_re | length) > 0) and contains("=") then
capture("^(?<name>[^=]+)=(?<value>.*)$") as $m
| if ($m.name | test($secret_re; "i")) then
"\($m.name)=<REDACTED-\($m.name | gsub("_"; "-"))>"
Expand All @@ -69,29 +83,41 @@ redact_env_jq='
end;

def redact_sensitive_keys($secret_re):
walk(
if type == "object" then
with_entries(
if (.key | test($secret_re; "i")) then
.value = "<REDACTED>"
else
.
end
)
else
.
end
);
if ($secret_re | length) == 0 then
.
else
walk(
if type == "object" then
with_entries(
if (.key | test($secret_re; "i")) then
.value = "<REDACTED>"
else
.
end
)
else
.
end
)
end;
'

require docker
require jq
require sha256sum
require_capture_boundary

mkdir -p "$OUT"
: > "$OUT/capture-limits.txt"
date -u +"%Y-%m-%dT%H:%M:%SZ" > "$OUT/captured-at-utc.txt"

# With CAPTURE_BOUNDARY=scenario-target, this template preserves scenario-target values by default.
# Configure OPERATOR_SECRET_NAME_REGEX only after classifying a value as
# operator/out-of-scenario material rather than target evidence.
if [[ -n "$OPERATOR_SECRET_NAME_REGEX" ]]; then
record_limit "Operator/out-of-scenario values matching OPERATOR_SECRET_NAME_REGEX were withheld by the capture template; ledger must describe the boundary and evidence impact"
fi

docker version --format json | jq . > "$OUT/docker-version.json"
if compose_version="$(docker compose version --format json 2>/dev/null)"; then
printf '%s\n' "$compose_version" | jq . > "$OUT/docker-compose-version.json"
Expand All @@ -106,7 +132,7 @@ if [[ -n "$COMPOSE_SERVICE" && -f "$COMPOSE_FILE" ]]; then
docker compose -f "$COMPOSE_FILE" config --format json
fi | jq \
--arg service "$COMPOSE_SERVICE" \
--arg secret_re "$SECRET_NAME_REGEX" '
--arg secret_re "$OPERATOR_SECRET_NAME_REGEX" '
if ((.services // {}) | has($service) | not) then
error("compose service not found: " + $service)
else
Expand All @@ -115,7 +141,7 @@ if [[ -n "$COMPOSE_SERVICE" && -f "$COMPOSE_FILE" ]]; then
| .environment = (
(.environment // {})
| with_entries(
if (.key | test($secret_re; "i")) then
if (($secret_re | length) > 0 and (.key | test($secret_re; "i"))) then
.value = ("<REDACTED-" + (.key | gsub("_"; "-")) + ">")
else
.
Expand All @@ -129,7 +155,7 @@ fi

if [[ -n "$CONTAINER" ]]; then
docker inspect "$CONTAINER" \
| jq --arg secret_re "$SECRET_NAME_REGEX" \
| jq --arg secret_re "$OPERATOR_SECRET_NAME_REGEX" \
"$redact_env_jq
.[].Config.Env |= ((. // []) | map(redact_env(\$secret_re)))
| redact_sensitive_keys(\$secret_re)" \
Expand Down Expand Up @@ -162,7 +188,7 @@ else
fi

docker image inspect "$IMAGE" \
| jq --arg secret_re "$SECRET_NAME_REGEX" "$redact_env_jq redact_sensitive_keys(\$secret_re)" \
| jq --arg secret_re "$OPERATOR_SECRET_NAME_REGEX" "$redact_env_jq redact_sensitive_keys(\$secret_re)" \
> "$OUT/docker-inspect.image.json"
docker history --no-trunc "$IMAGE" | redact_text_stream > "$OUT/docker-history.image.txt"

Expand Down
8 changes: 8 additions & 0 deletions .codex
Original file line number Diff line number Diff line change
Expand Up @@ -33,3 +33,11 @@ such as `GOV-918`.
- For Claude Code, use
`.claude/skills/aces-asset-inventory-capture/SKILL.md`. This server also
links it at `~/.claude/skills/aces-asset-inventory-capture`.
- For Codex, use `.codex-skills/aces-gap-remediation-implement/SKILL.md`
when remediating ACES/APTL gaps found by the asset-inventory methodology.
This server also links it at
`~/.codex/skills/aces-gap-remediation-implement`.
- For Claude Code, use
`.claude/skills/aces-gap-remediation-implement/SKILL.md` for the same
overlay. This server also links it at
`~/.claude/skills/aces-gap-remediation-implement`.
42 changes: 30 additions & 12 deletions .codex-skills/aces-asset-inventory-capture/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -20,8 +20,12 @@ For Docker/Compose/container-image captures, start by copying
`scripts/capture-container-evidence-template.sh` and
`scripts/normalize-syft-cyclonedx.jq` into the target bundle as runnable capture
resources, then tailor the copied script for asset-specific source paths,
filesystem manifests, and redaction names. Keep every evidence-affecting
normalization in the script or a referenced jq file.
filesystem manifests, and any explicit operator/out-of-scenario withholding
rules. Set `CAPTURE_BOUNDARY=scenario-target` only after confirming the script
is pointed at participant-discoverable target state, and set
`OPERATOR_SECRET_NAME_REGEX` only for material classified outside that boundary.
Keep every evidence-affecting normalization in the script or a referenced jq
file.

## Inputs

Expand All @@ -47,10 +51,10 @@ Produce a bundle that validates with the current APTL reference ledger tooling:
- `capture-evidence.sh` or equivalent committed capture commands, derived from
the template for Docker/Compose assets when applicable;
- `mapping-ledger.yaml` using the current reference ledger schema;
- `evidence/` with raw or redacted evidence files;
- `evidence/` with source evidence files;
- `evidence/capture-limits.txt` with one first-class limit for every skipped
required step, declined useful-optional step, contamination boundary, or
redaction that changes what was captured;
operator/out-of-scenario withholding that changes what was captured;
- `evidence/captured-at-utc.txt`;
- `evidence/evidence-sha256sums.txt` covering committed evidence files.

Expand Down Expand Up @@ -117,13 +121,26 @@ No `needs_gap_triage` row may remain at review time.
intact and separate filesystem provenance is captured or the omission is
recorded in `capture-limits.txt`.

5. Hash and redact before committing.

Follow ADR-029 redaction discipline. Do not place credentials, bearer
tokens, private keys, generated service secrets, cookies, session ids, or
operator-only values in evidence, logs, argv, tracebacks, issue comments, or
`mapping-ledger.yaml`. Participant-visible fixture secrets may be retained
only through the repo-approved secret-fixture classification.
5. Preserve scenario-target secrets and withhold only operator material.

Follow ADR-057 as the inventory boundary. Scenario-target secrets are
capture facts and must not be redacted from source inventory bundles when a
participant or in-range agent could discover them. This includes passwords,
hashes, private keys, tokens, generated range secrets, service config
secrets, and security product state required to realize or inspect the
target. The Wazuh/OpenSearch Security `internal_users.yml` bcrypt hashes
from APTL #341 are the canonical example: preserve them unredacted in the
source evidence bundle because they are target configuration facts.

Operator/out-of-scenario secrets remain outside the inventory boundary.
Host SSH keys, cloud or CI tokens, maintainer credentials, local
control-plane secrets, workstation secrets, and accidental adjacent
environment material must not be captured as scenario facts. Exclude them
or record a first-class `capture-limits.txt` entry describing the withheld
scope. ADR-029 still governs operator-secret handling in logs, argv,
tracebacks, issue comments, and other non-evidence surfaces.
Sanitized/public exports are separate derived views; do not replace source
evidence with `<REDACTED>` placeholders as the default safety mechanism.

6. Build the ledger fact-by-fact.

Expand Down Expand Up @@ -200,7 +217,8 @@ Before returning:
- every evidence file is referenced from `mapping-ledger.yaml`;
- `capture-limits.txt` records skipped methodology steps as first-class
limits;
- no raw secrets or operator-only values are committed;
- scenario-target secrets are preserved as source capture facts, while
operator/out-of-scenario material is excluded or recorded as a capture limit;
- `aptl aces-inventory validate <asset-dir>` passes;
- `aptl aces-inventory gaps <asset-dir>` has no unresolved
`needs_gap_triage`;
Expand Down
Loading
Loading