-
Notifications
You must be signed in to change notification settings - Fork 2.5k
Add AGENTS.md so the threat model is discoverable by agents #5126
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,43 @@ | ||
| # Agent guidance | ||
|
|
||
| This file is read by automated agents (security scanners, code analyzers, | ||
| AI assistants) operating on this repository. It points them at the | ||
| human-authored references they should consult before producing output. | ||
|
|
||
| ## Security | ||
|
|
||
| Security model: [SECURITY.md](./SECURITY.md), which links to the project's | ||
| threat model at | ||
| [site/_docs/security_threat_model.md](./site/_docs/security_threat_model.md). | ||
|
|
||
| Calcite is an embedded SQL framework, not a server. It opens no socket and | ||
| has no authentication or authorization of its own; the host application | ||
| owns transport, identity, and schema scoping. Read the threat model before | ||
| reporting anything — it is explicit about what it does and does not treat | ||
| as a vulnerability. | ||
|
|
||
| Two rules carry most of the triage weight: | ||
|
|
||
| - **Surprising vs unsurprising class loading.** A class named through a | ||
| Calcite SPI position — `schemaFactory`, `parserFactory`, `typeSystem`, | ||
| `metaTableFactory`, `metaColumnFactory`, `tableFactory`, function | ||
| classes, `dataSource`, `jdbcDriver`, `model` — is loaded only through | ||
| that SPI, gated by `Class.forName(name, false, loader)` plus an | ||
| `isAssignableFrom` check. A class that does not implement the SPI for | ||
| its position is never instantiated by name. SQL may name SPI classes, | ||
| but only SPI implementations run, and only through their SPI. | ||
| - **Pushed-down SQL.** The SQL Calcite generates and sends to a backend | ||
| the operator configured is *not* a vulnerability — the query author can | ||
| already reach that endpoint through the visible schemas. A pushdown bug | ||
| that reads *beyond* the configured schemas is P4 and *is* one. | ||
|
|
||
| Explicitly not vulnerabilities (see the model's "Not a vulnerability" | ||
| section): the os-adapter running OS commands, the file/CSV/JSON adapters | ||
| reading paths they were configured with, anything requiring a changed | ||
| system property or classpath, a third-party driver's behaviour past the | ||
| connection boundary, and cross-tenant reads that follow from the embedder | ||
| exposing several principals' schemas on one connection. | ||
|
|
||
| The model also lists what belongs to the host rather than the library — | ||
| transport and identity, schema scoping, adapter selection, the classpath, | ||
| and whatever a `model` points at — under "Downstream responsibilities". | ||
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This gets injected to every context of every agent. It bloats context with zero gain. There's no sense in providing excessive security-related stuff. It should be referenced instead.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Correct. I am not even sure why it ended up here eventually (long time ago and I had about 100 of similar PRs :( and most of them were bare minimum and linking to SECURITY.md for more details.
This is a bit of the problem with Agentically generated PRs that things like that can slip - especially when you do a lot of those in a short time (learning for me as well to pay more attention).
Thanks @vlsi for updating it.