Skip to content

crosswalks: refresh cfgaudit to v1.12.0 (61 rules onto 27 classes) - #193

Open
predictor2718 wants to merge 1 commit into
aveproject:mainfrom
predictor2718:crosswalk-cfgaudit-1.12.0
Open

crosswalks: refresh cfgaudit to v1.12.0 (61 rules onto 27 classes)#193
predictor2718 wants to merge 1 commit into
aveproject:mainfrom
predictor2718:crosswalk-cfgaudit-1.12.0

Conversation

@predictor2718

Copy link
Copy Markdown
Contributor

The merged crosswalk was generated 2026-08-05, so it predates AVE-2026-00071, 00072, 00073 and 00076. Six rules those records cover were still sitting in the unmapped column.

53 rules onto 23 classes → 61 onto 27.

New mappings:

Rule Class
CFG082 AVE-2026-00071 container daemon redirected off-host
CFG018 AVE-2026-00072 bind-all with no auth step
CFG005, CFG046, CFG071, CFG099 AVE-2026-00073 endpoint redirect via a static config value
CFG094 AVE-2026-00076 steering an approval classifier
CFG098 AVE-2026-00062 unpinned dependency (marketplace archive with no sha256)

Also here:

  • Both sides now carry a commit, so every stated count can be re-derived. This clears the record-count warning validate_crosswalks.py emits for this file. The cfgaudit tree read is two commits past the v1.12.0 tag; the delta is stated in the file, and rules mapped at the tag itself is 60, not 61.
  • Three v1.12.0 rules are left unmapped on purpose (CFG100, CFG101, CFG102), listed under config_surfaces_beyond_ave with reasons instead of being fitted to a near-miss class.
  • AVE-2026-00077 added as a gap. cfgaudit reads MCP launch config, not the manifest a running server returns, so the two declarations that record correlates are never both in view.
  • The sandbox-weakening surface is expanded with the settled field list, since that was the reason it was on hold. Full detail in Taxonomy gaps identified by cfgaudit crosswalk (credit: predictor2718) #68.

python3 scripts/validate_crosswalks.py passes.

The merged version was generated 2026-08-05, so it predates AVE-2026-00071,
00072, 00073 and 00076. Six rules those records cover were still unmapped.

Now 61 rules onto 27 classes. Both sides pinned by commit, which clears the
record-count warning from validate_crosswalks.py.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant