Repository navigation
fix(ocsf): emit schema-conformant OCSF events and honest downgrades - #4288
zanetworker wants to merge 1 commit into
Conversation
ddf7841 to
56390e5
Compare
56390e5 to
78621e8
Compare
|
/ok to test 78621e8 |
|
Label |
johntmyers
left a comment
There was a problem hiding this comment.
gator-agent
PR Review Status
The independent review found no blocking defects in the OCSF conformance and schema downgrade changes. @zanetworker, I checked your note about top-level container: it is present in the base, remains an acknowledged design question, and the downgrade preserves its data under unmapped.
Current-head testing has started with test:e2e and test:windows. Trivy and Helm are green; Branch Checks, E2E, and both Windows lanes are pending. The E2E Label Help bot requests Re-run all jobs, but the identified run still has an active first attempt.
Action required: rerun Branch E2E Checks after the active attempt finishes. Gator has operator authorization and the narrow sandbox permission to perform that rerun in a subsequent cycle.
Blocking findings: None.
Carried findings: None.
Gator metadata
- Validation: Focused OCSF correctness fixes for linked issues #4283 and #4284; operator requested review and relevant tests.
- Docs: Fern documentation updates describe OS identity, mixed-version JSONL, downgrade preservation, gateway configuration, and the kept-native metric.
- Checks: DCO, OpenShell / Helm Lint, and OpenShell / Trivy Changes pass; Branch Checks and both Windows MSVC PR lint and test lanes are pending on the reviewed head.
- E2E: test:e2e applied; current-head mirror verified; Branch E2E Checks run 37657018590 attempt 1 is active. Bot-required rerun remains outstanding. Relevant E2E coverage includes the new Podman JSONL conformance test.
- Head SHA:
78621e8bb1fb9af4c91f9cf8dd5c3ebffc62b963 - Base SHA:
3fc93e28273fe304db634e6d5e9a52d57200389e - Merge base SHA:
834b79a8c2351370e7c6c363423f5be18d440256 - Patch ID:
33dfd9e90bc20c4d4b8493efc716d9a8d3c32edb - Gator payload:
11 - Review mode:
initial - Previous reviewed SHA: none
- Review budget exhausted: no
- Maintainer decision required: no
- Next state:
gator:blocked - Blocked reason:
test_dispatch_required
Author Follow-Up NudgeThis PR has been in @zanetworker, please make the vendored OCSF schemas available to the relocated Podman E2E test and push an update. The rootless Podman run fails in @NVIDIA/openshell-maintainers, both Windows lanes also need a gate resolution: Clippy reports Gator metadata
|
Native events failed the official OCSF 1.8.0 validator: device.os lacked type_id, HTTP Activity emitted is_src_dst_assignment_known, sandbox Process Activity events had no actor, connection_info lacked direction_id, and SSH Activity events named no endpoint. Schema tests missed these because they checked only top-level, non-profile attributes. The 1.1 and 1.3 downgrade stripped three fields by name and relabelled events that did not conform. Add OS type and connection direction enums, require an actor on Process Activity and an endpoint on SSH Activity at compile time, name the supervisor's SSH server and domain endpoints with fields every version accepts, and make schema validation recurse into nested objects, reject undefined attributes, and honour declared profiles. Make the downgrade schema-driven from definitions generated from the vendored official 1.1.0 and 1.3.0 schemas: undefined attributes move under unmapped.downgraded_attributes, unsupported profiles are dropped, and an event is labelled with the target only when every requirement holds. Otherwise it stays at native 1.8.0 and is counted by the gateway metric openshell_ocsf_log_kept_native_total and a supervisor warning. Keep it fixed with a Podman e2e test that validates the supervisor's real JSONL, schemas compiled into test binaries so archived runs need no source files, a production-like fallback context for producer tests, a vendored-version guard, and documented schema update steps. Top-level container stays unchanged pending a decision on NVIDIA#4283. Closes NVIDIA#4283 Closes NVIDIA#4284 Signed-off-by: Adel Zaalouk <azaalouk@redhat.com>
|
Fixed in @johntmyers could you take a look, and |
78621e8 to
aae1747
Compare
|
/ok to test aae1747 |
johntmyers
left a comment
There was a problem hiding this comment.
gator-agent
PR Review Status
Thanks @zanetworker (Adel Zaalouk), I checked your update about relocating the archived test: the loader now reads compiled-in schemas, and all 112 vendored schemas are included. That addresses the build-machine path dependency. Your note about the earlier Windows Clippy failures also holds: ssh.rs is unchanged by this PR.
The independent follow-up review found one new Windows regression in the drift test. It generates platform-native paths while the committed table uses forward slashes. The inline finding covers both the failing comparison and regeneration.
Action required: normalize the generated schema paths to forward slashes and verify the focused drift test on Windows.
Blocking findings:
GATOR-aae17474-01: Windows path separators break the new embedded-schema drift check and regeneration.
Carried findings: None. The prior schema-relocation obligation is addressed by the loader change; current-head E2E will verify it in CI.
I posted /ok to test for the full current head. Branch Checks, Helm, E2E, and Windows workflows are queued or running. The existing test:e2e and test:windows labels remain appropriate. Gator stays in review while the author fixes the path normalization.
Gator metadata
- Validation: Focused OCSF correctness changes for linked issues #4283 and #4284; continuing the previously validated PR.
- Docs: Existing Fern updates cover the user-visible changes; schema README documents embedding and regeneration.
- Checks: DCO passes; current-head Branch Checks and Helm workflows are active, Windows is queued. Trivy is not yet confirmed green.
- E2E: Current-head Branch E2E Checks run 38081852521 is active. The older bot-required rerun instruction referred to the previous head; no current-head rerun instruction was present when checked.
- Head SHA:
aae17474233af3ddd272f43557a01a7cf0c7f677 - Base SHA:
eeba0e7954c0fb4d8e9e2e29d1bfa68e290eb8b3 - Merge base SHA:
834b79a8c2351370e7c6c363423f5be18d440256 - Patch ID:
892df22a6665f52060e783e6810464d88dae8f16 - Gator payload:
11 - Review mode:
follow_up - Previous reviewed SHA:
78621e8bb1fb9af4c91f9cf8dd5c3ebffc62b963 - Review budget exhausted: no
- Maintainer decision required: no
- Next state:
gator:in-review
| let relative = path | ||
| .strip_prefix(root) | ||
| .unwrap() | ||
| .to_string_lossy() |
There was a problem hiding this comment.
gator-agent
Warning — GATOR-aae17474-01 · Normalize embedded schema paths on Windows
Summary: Both Windows workspace test lanes run this new drift check. Native relative paths contain backslashes, so the generated table differs from the committed forward-slash table and the check fails. Regenerating on Windows also inserts unescaped backslashes into Rust string literals.
Fix: Normalize relative schema paths to forward slashes before storing and interpolating them. Keep the drift check enabled on Windows.
Verify: On native Windows, run cargo test -p openshell-ocsf embedded_schemas_match_vendored_files. It should pass without changing embedded.rs; regeneration should produce the same table on Windows and Unix.
Agent context
- Location:
crates/openshell-ocsf/src/validation/schema.rs:266 - This follow-up introduces the test and generator; the previous head had neither. The comparison and regeneration share this path conversion.
- Reviewed statically; native Windows execution was not available in this sandbox.
Summary
OCSF events from OpenShell failed the official OCSF validator, natively at 1.8.0 and after the 1.1 or 1.3 downgrade. The vendored-schema tests did not notice because they checked only top-level, non-profile attributes, and the downgrade stripped three fields by name before relabelling
metadata.version.This makes native events from every builder pass
https://schema.ocsf.io/api/1.8.0/validate(apart from top-levelcontainer, open on #4283), and makes the downgrade schema-driven: an event is labelled 1.1 or 1.3 only when it validates against that version, otherwise it stays unchanged at 1.8.0 and is counted. No placeholder data is ever inserted.Related Issue
Closes #4283
Closes #4284
Changes
Native OCSF 1.8 (#4283):
device.oscarries the requiredtype_idandtype(Linux 200, Windows 100, macOS 300) through a newOsTypeIdenum.is_src_dst_assignment_known, which no OCSF version defines on that class.ProcessActivityBuilderrequires an acting process beforebuild()(type-state, like the HTTP and Network builders). Sandbox process events name theopenshell-sandboxlauncher with its real pid.connection_infocarries the requireddirection_idanddirection, defaulting to Unknown.SshActivityBuilderrequires a source or destination endpoint beforebuild(). All eight SSH events had none; they now name the supervisor's SSH server asdst_endpoint(svc_name: "ssh"and the listen socket path inname), using newEndpointnameandsvc_namefields.Endpoint::from_domainand the policy DNS endpoint also sethostname, the endpoint name OCSF 1.1 and 1.3 accept.validate_required_fieldsrecurses into nested objects, rejects undefined attributes, enforces profile attributes only when declared, and uses the event'smetadata.version. New testevery_builder_emits_schema_conformant_events. The HTTP and Networkcompile_faildoctests now fail only for the reason they claim.Keeping it fixed:
ocsf_jsonl_conformance(Podman CI set) enables JSONL with a 1.1 target, generates denied traffic, copies the supervisor's JSONL withpodman cp, and validates every record against the version it claims. It covers production call sites rather than builders, and found the SSH endpoint gap. The e2e crate takesopenshell-ocsf(withtest-support) as a dev-dependency so both suites share one validator.test-support, the fallbackEventContextcarries a sandbox identity, so producer tests emitcontainerand device fields as production does. Top-levelcontaineris the single named exception in the validator, linked to bug(ocsf): native OCSF 1.8 events fail the official schema validator #4283.schemas/ocsf/README.mddocuments every vendored version, the update and regeneration steps, a native version bump checklist, and validation with the official OCSF server.vendored_schemas_cover_the_native_version_and_every_targetfails when a version is not vendored.Schema downgrade (#4284):
format/downgrade.rscompares each event against the target version's class and object definitions, recursively. Undefined attributes (for examplelaunch_type,is_alert,state,is_src_dst_assignment_known,ai_model) move underunmapped.downgraded_attributes; unsupported profiles are dropped; requirements andat_least_oneconstraints are checked. ReturnsDowngradeOutcomeinstead ofbool.metadata.versionis written in full (1.1.0, not1.1).format/downgrade_defs.rsis generated from vendored official 1.1.0 and 1.3.0 schemas;downgrade_definitions_match_vendored_schemasfails on drift andUPDATE_OCSF_DOWNGRADE_DEFS=1regenerates it.openshell_ocsf_log_kept_native_total{class_uid,target}. The supervisor tallies kept-native records and its settings poll loop logs a warning with the count and latest reason when the tally grows.device.os.type_id, the new metric, and the gatewayschema_versionrow.User-visible: downgraded files can contain both target-version and 1.8.0 records (route by
metadata.version);metadata.versionreads1.1.0rather than1.1; HTTP events dropis_src_dst_assignment_known; endpoints gainhostname.Deferred: top-level
containeris undefined in every OCSF version but identifies the affected sandbox on gateway events (#4283). Many Detection Finding, Network and SSH events lackaction_idorsrc_endpointand so stay native for 1.1 targets; adding that data needs a per-call-site decision. The SIGTERM-failure Process Activity event still uses theProcess::new("unknown", 0)fallback.Testing
e2e/with-podman-gateway.sh, supervisor and sandbox images built from this branch) withocsf_schema_version=1.1and denied DNS, transparent TCP and SSH activity. Of 21 supervisor JSONL records, all 9 labelled 1.1.0 return no errors from the official 1.1.0 validator; the other 12 stayed at 1.8.0 for missingsrc_endpoint(9), a Unix-socket SSH session (2) or missingaction_id(1). The supervisor logged the kept-native warning on unchanged polls.OPENSHELL_E2E_PODMAN_TEST=ocsf_jsonl_conformance mise run e2e:podmanpasses. It failed before the SSH fix with"SSH Activity" 1.8.0 "SSH connection accepted on supervisor Unix socket": Missing at_least_one field from [dst_endpoint, src_endpoint].ocsf/ocsf-serverbuilt from source, schemas compiled withocsf-schema-compiler1.1.1, one instance each for 1.1.0, 1.3.0 and 1.8.0) returns no errors for the real supervisor records, every builder's native and downgraded events, and the new SSH endpoint shape. It does not enforceat_least_oneconstraints, which is why the e2e test uses the vendored-schema validator.container(every class failed before ondevice.os.type_id), and downgraded to 1.1.0 and 1.3.0 every event validates against the version it claims (18/18).cargo test -p openshell-ocsf(172 unit, integration and doc tests);cargo test --libforopenshell-server(2028),openshell-supervisor(154),openshell-supervisor-network(1471),openshell-supervisor-process(105),openshell-sandbox;cargo check -p openshell-driver-mxc --testscargo clippy --workspace --all-targets -- -D warnings,cargo fmt --all --checkproxy::tests::mediated_connect_keeps_workload_bytes_read_with_the_synthesized_headeris load-sensitive: under full CPU saturation it fails 10/10 on bothmainand this branch, and passes in normal runs on both.Checklist