Repository navigation
FEAT: Attack analytics SDK - #3059
Merged
Roman Lutz (romanlutz) merged 13 commits intoOct 11, 2026
Merged
Roman Lutz (romanlutz) merged 13 commits into
Roman Lutz (romanlutz) merged 13 commits into
Conversation
Interpret saved outcome counts through an async SDK with shared loop-bound admission, cooperative cancellation, and deterministic cleanup. Match bounded Unicode profile aggregation to the complete SQL fallback, with exact drilldowns, focused compatibility coverage, and SDK lifecycle documentation. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Preserve cancellation when admission races with a slot grant on Python 3.11. Release unscheduled operation capacity and close rejected coroutines, keep shutdown retryable, and log failures that race with caller cancellation. Add deterministic lifecycle regressions and verify raw-result analytics remains distinct from scenario-unit statistics and explicit result-role policy. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Expose decided-only and all-outcome success rates through one calculator and shared model. Keep raw saved-result selection distinct from scenario latest-unit selection while reusing count validation, rates, shares, and percentage formatting. Preserve legacy defaults and carry both rates through scenario progress and JSON projections. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Reject contradictory scenario totals and outcome breakdowns, including mutated inputs at aggregation boundaries. Expose an explicit read-only success_rate_decided alias in shared statistics and JSON. Add typed include_outcome_statistics opt-ins to maintained result and async technique analytics while preserving the six-field default and existing deprecation schedules. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Richard Lundeen (richlundeen)
approved these changes
Oct 10, 2026
github-merge-queue
Bot
removed this pull request from the merge queue due to failed status checks
Oct 11, 2026
github-merge-queue
Bot
removed this pull request from the merge queue due to failed status checks
Oct 11, 2026
github-merge-queue
Bot
removed this pull request from the merge queue due to failed status checks
Oct 11, 2026
github-merge-queue
Bot
removed this pull request from the merge queue due to failed status checks
Oct 11, 2026
github-merge-queue
Bot
removed this pull request from the merge queue due to failed status checks
Oct 11, 2026
github-merge-queue
Bot
removed this pull request from the merge queue due to failed status checks
Oct 11, 2026
github-merge-queue
Bot
removed this pull request from the merge queue due to failed status checks
Oct 11, 2026
github-merge-queue
Bot
removed this pull request from the merge queue due to failed status checks
Oct 11, 2026
github-merge-queue
Bot
removed this pull request from the merge queue due to failed status checks
Oct 11, 2026
github-merge-queue
Bot
removed this pull request from the merge queue due to failed status checks
Oct 11, 2026
github-merge-queue
Bot
removed this pull request from the merge queue due to failed status checks
Oct 11, 2026
github-merge-queue
Bot
removed this pull request from the merge queue due to failed status checks
Oct 11, 2026
github-merge-queue
Bot
removed this pull request from the merge queue due to failed status checks
Oct 11, 2026
github-merge-queue
Bot
removed this pull request from the merge queue due to failed status checks
Oct 11, 2026
github-merge-queue
Bot
removed this pull request from the merge queue due to failed status checks
Oct 11, 2026
github-merge-queue
Bot
removed this pull request from the merge queue due to failed status checks
Oct 11, 2026
Use explicit finite test budgets for native SQLite semantic checks instead of requiring loaded CI runners to meet the SDK's one-second quick-query safeguard. Preserve admission capacities, production deadlines, and every semantic assertion. Add event-driven tests of the unchanged default execution budgets and capacity retention through timeout cleanup. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Update the required base to 1ba8bcd while preserving the analytics SDK and deterministic CI regression fix. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Include the decoding scorer identity and opt-in WebSocket tracing base updates that landed during validation. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Update the required base to dc8510a while preserving the analytics SDK and deterministic deadline tests. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Include upstream SDK test isolation and plagiarism normalization through 0a5abbf, preserving the analytics changes. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Update the required base to 1bf811f while preserving the analytics changes and deterministic deadline tests. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Part 3 of the CoPyRIT attack-results analytics roadmap, following the merged contracts (#2742) and storage (#2792). This makes saved-result analytics available to Python callers without introducing analytics REST endpoints or the GUI explorer.
AttackResultAnalytics.query_async,results_async, andfacets_async, plusclose_asyncand an async context manager. Reports include a coherent initial lightweight result page; subsequent pages and facets do not recalculate reports or hydrate conversations, scores, or media.str.lowersemantics, deduplicated memberships, typed missing/no-converter values, stable labels, and parity with the complete SQL fallback. Overflow falls back without sampling or partial totals. Exact appended drill-down predicates preserve existing filters and the 16-predicate/500-value budget.compute_outcome_statistics/combine_outcome_statistics. Both expose decided-onlysuccess_rate_decidedand all-outcomesuccess_rate_all;success_rateremains compatible. Raw analytics still counts every saved result ID, while scenario statistics still selects the latest attempt per execution unit. Historical retry/error counts remain separate from selected outcome counts.include_outcome_statistics=Trueto the maintainedanalyze_resultsandcompute_technique_stats_asyncAPIs while retaining the original six-fieldAttackStatsdefaults. Scenario progress and JSON output carry the shared statistics; existing displayed percentages and deprecation schedules remain unchanged.The shared-calculation follow-up builds on #2820 and preserves the explicit result roles from #2997 without silently excluding any role. Existing lazy exports and import boundaries are retained. Requests are snapshotted and revalidated before admission. There is no persistent result cache or in-flight coalescing.
No schema/migration changes, shared/live database access, History selection changes, new endpoints, frontend changes, or backend lifecycle wiring. REST/History integration, the HTTP performance gate, and the explorer remain roadmap parts 4 and 5. The profile caps bound transferred profiles and SDK work, not SQL scans or peak network bytes.
Tests and Documentation
Added SDK, execution-lifetime, SQL/profile parity, shared-outcome, consistency/serialization, and compatibility coverage. Regressions include all outcomes and empty denominators, exact drill-down boundaries, Unicode and legacy converter metadata, profile caps/overflow, request snapshots, independent native async sessions, task-start failures, Python 3.11 admission-cancellation races, and deterministic shutdown. Scenario/backend/JSON parity and maintained-versus-deprecated API behavior are also covered.
Updated the Python analytics guide, framework responsibilities, and documentation navigation. The guide explains both denominator policies, resource ownership, compatibility, and the limitations of the bounded profile path.
Current head, Windows / Python 3.14.4:
Result: 620 passed.
uv run --no-sync ty check pyrit: passed.uv run --no-sync python -m build_scripts.validate_docs: passed, including 165 navigation references and the orphaned-file check.git --no-pager diff --check: passed.Additional cross-version and broader compatibility evidence
Python 3.11.15, using a temporary uv-managed environment inside this worktree:
Result: 369 passed, with an existing third-party
confusablesinvalid-escape warning. The temporary environment was removed afterward.The broader Python 3.14.4 compatibility run included scenario services/routes, adaptive selectors, output formats, and lazy imports:
Result: 1,062 passed; one scenario alias-import subprocess hit its existing 30-second timeout. That unchanged test and the new technique lazy-export test both passed in isolation:
Result: 2 passed in 9.31 seconds. No test timeout or import guard was weakened.
Full-repository, live Azure SQL, and HTTP/100,000-row performance validation were not run. SQLite coverage uses isolated test databases. Weighted SDK profile coverage is not a production latency claim.
JupyText was not run: this changeset adds Markdown documentation, not paired Python/notebook examples.