Add java-security: eight Java rules as one policy, picked per rule - #95
Merged
Merged
Conversation
Moves the Java security engine from open-coder-ai/chock-java-security into the catalog as one policy folder, base/java-security/. All eight rules ship together and an adopter chooses per rule in .chock/security.json (allow|deny|ask, silence denies), so a ninth rule is a version bump of this policy rather than a ninth folder. The selection file carries verdicts only; a pattern or severity in it is refused at the next commit. The guard, implementations/java-security-pre-commit.py, is a hook.script on [commit] in the shape no-a11y-regression established: it reads the staged revision through the vendored engine beside it and refuses on a deny, on an ask with no terminal, on an unreadable selection, and on any failure inside the engine. The write-path doors (tool use, turn end) arrive through the engine's `kind: script` gate once the catalog adopts a release carrying it. skills/configure-java-security/ is the pick-and-choose door: the guided page, walked in the agent's own panel, whose submit becomes the selection file. Its embedded contract is checked against the shipped rules. tools/check_java_security.py runs 52 cases ported from the engine's suite -- every rule's trigger and its correct sibling -- plus the commit path in a throwaway repository, in CI. tools/gen_policy_docs.py now classifies through tools/mechanism.py, so a commit-time script policy's page says it enforces instead of "no mechanism" (no-a11y-regression's page changes too). docs/figures/make_enforcement.py reads only the registry's policy records, since a skills: section carries no enforces label. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: Claude <noreply@anthropic.com>
jothimani-rajendran
marked this pull request as ready for review
September 22, 2026 13:42
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
base/java-security/, new. The Java security engine from open-coder-ai/chock-java-security, moved into the catalog as one policy folder carrying all eight rules (MyBatis${}interpolation, unescaped template output, Jackson default typing / XStream without an allowlist, wildcard CORS origin with credentials, wildcard actuator exposure, unverified JWT parse, request-chosen file path,ObjectInputStreamover request bytes). An adopter picks and chooses per rule in.chock/security.json(allow|deny|ask; a rule the file does not name denies), never per policy folder, so a ninth rule is a version bump here rather than a ninth folder. The file carries verdicts only: a pattern, severity or path in it is refused at the next commit.What an adopter sees:
implementations/java-security-pre-commit.py(ahook.scripton[commit], the shapeno-a11y-regressionestablished) reads the staged revision through the vendored engine beside it and refuses on a deny, on anaskwith no terminal, on an unreadable selection, and on any failure inside the engine. No path in it allows what it never judged. Ceilingenforced-at-commit, as the registry and the regenerated policy page now say.skills/configure-java-security/, the guided page walked in the agent's own panel (as an Artifact with adbstore where the client can publish one), whose submit becomes the selection file. Its embedded contract is checked against the shipped rules in CI.kind: scriptgate, feat(gate): add a script kind that runs a policy's own program chock#154, once this catalog adopts a release carrying it; the eval cases are written in the staged-files shape that gate will replay, and until thentools/check_java_security.pyruns every one of them against the shipped guard.Also in this PR, because the policy exposed them:
tools/gen_policy_docs.pyclassifies throughtools/mechanism.pyinstead of its own gate/guard/text copy, so a commit-time script policy's page says it enforces at commit instead of "There is no mechanism".docs/no-a11y-regression/README.mdchanges accordingly (it was understating itself the same way).docs/figures/make_enforcement.pyreads only the registry'spolicies:records; the newskills:section has noenforceslabel and aborted the render.python tools/check_java_security.py, beside the two a11y checks.Definition of done
chock checkclean (this repo: 0 errors; the staged adopter with every published policy and the skill: 0 errors, 0 warnings beyond the pre-existing INDEX budget notice and INT-3's verb suggestion forconfigure-java-security)chock check --only evalsgreen (this repo and the staged adopter: 409 pass, 202 skipped)chock sync --repo . --checkclean;chock syncadded the skill to.agents/policies/INDEX.mdand.chock/registry.jsonpython tools/gen_policy_docs.py --checkandpython tools/check_readme.pypass (42 policies, 20 enforced, 22 advisory);check_registry,check_console,check_workflows,check_effects(11 guard-shipping policies incl. this one),gen_coverage_matrix --check, brand assets--check, figures regenerated without drift,chock plugin build --checkfor all three trees, adoption transcriptdocs/java-security/adoption.mdreproducesenforced-at-commitfrom a script that exits non-zero; the write path is stated as not yet reachedevals/suite.yaml, each rule with its trigger and its correct sibling; none has an executable form on this engine (ahook.scriptis not replayed by the eval runner), sotools/check_java_security.pyexecutes 52 ported cases plus the commit path and the setup page, 83 checks, in CIIf this touches
implementations/implementations/java-security-pre-commit.py(14 lines, the entry point) andimplementations/chock_security/(the engine:decision.py,engine.py,selection.py,pack.py,flow.py,rules/*.py,frontends/precommit.py,data/java.json). Standard library only; no network, no secrets, no eval/exec; it reads git and the selection file and writes nothing (check_effects.pyobserved that).Known residuals, stated rather than left to be found:
configure-java-securitydoes not start with a verb it recognises. Kept: the id is what a person says when they want it.chock-security setup apply, the plugin form's CLI; in the catalog the skill's procedure writes the selection file directly and says so. The page is otherwise byte-identical to the plugin's, with an agent-neutral contract.🤖 Generated with Claude Code
Generated by Claude Code