Repository navigation
Add pdr diff - #64
Merged
Merged
Add pdr diff#64
Conversation
qstriage pdr diff BEFORE AFTER verifies both PDR documents and compares them record by record. A document that fails verification stops the command with exit code 1 and no comparison. Records are matched by record_id. The fields of decision and observed_state are compared. Provenance is compared item by item: input file, policy pack, algorithm registry, QSTriage version and PDR format. When more than one item differs, the report states that a decision change cannot be attributed to one of them. When the two documents have different pdr_version values, fields present in only one of them are listed as format differences, not as changes. The Markdown report, the default, gives the result in plain sentences first: how many decisions changed, what differs between the two runs, and for each changed record the action, algorithm status, human-review requirement and reason codes, followed by a table of every changed field. Text taken from the documents is escaped. --format json gives the same content with hashes. Exit code 0 means a comparison was produced, 1 a read, verification or write failure, 2 an invalid option. --output never replaces an existing file without --overwrite and never writes over an input.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
qstriage pdr diff BEFORE AFTER [--format markdown|json] [--output FILE] [--overwrite]the command prints which one and exits 1 without a comparison.
record_id;decisionandobserved_statefieldsare compared.
source_hash), policy pack(
policy_pack_hash), algorithm registry (registry_hash), QSTriageversion (
engine.version), PDR format (pdr_version). When more than onediffers, the report states that a decision change cannot be attributed to
one of them. No cause is inferred.
pdr_versionvalues, fields present in only onedocument are listed as format differences, not as changes.
Report layout (Markdown, default)
both files.
codes, per asset.
separately.
The report shows what the records contain and does not recommend actions.
Text taken from the documents is escaped with the same helpers as the
Markdown report.
--format jsoncarries the same content with document,policy-pack and registry hashes.
Exit codes
0: comparison produced (the JSON field
changedstates whether anythingchanged). 1: read, verification or write failure. 2: invalid option.
Verification
attribution, 0.2 to 0.3 and 0.3 to 0.2 format differences, added and
removed records, tampered document refused, duplicate
record_idrefused, Markdown escaping of untrusted names, JSON content, CLI exit
codes, no-clobber output, inputs unchanged.
Python 3.11, 1453 passed, 4 skipped. Comparing the stored PDR 0.2 fixture
with a PDR 0.3 in which one algorithm became
X25519MLKEM768reports 2 of5 decisions changed and exits 0.
Documentation
docs/usage.md,docs/pdr-contract.md(Comparison), input limits indocs/input-contracts.mdand the README, CHANGELOG (Unreleased, Added).