-
Notifications
You must be signed in to change notification settings - Fork 97
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Constraint error while processing expression: Diagrams #940
Comments
One of the consequences of doing this bug fix is we didn't update docs, so I am pretty sure @Telos-sa demonstrated in office hours that we have not updated docs to match. I will want to discuss during the tail end of standup, but a documentation update is in order. @Telos-sa, sorry I did not connect the dots before the end of the call. You were right after all, can you please try re-running the constraint with the appropriate fedramp-automation/src/content/rev5/examples/ssp/xml/fedramp-ssp-example.oscal.xml Lines 4813 to 4832 in c0ad00e
fedramp-automation/src/content/rev5/examples/ssp/xml/fedramp-ssp-example.oscal.xml Lines 4770 to 4790 in c0ad00e
|
@aj-stein-gsa I updated the props for these diagrams, and added in "class"="data-flow" and "authorization-boundary" respectively:
And these are the corresponding resources
This structure is still causing the critical error:
Do you see something else that might be causing this error? I tested and the presence of "ns" doesn't matter |
@Telos-sa, can you please updated sample to your repository for this example and add the folders with the dummy data flow diagram files as well (to be clear, make the dummy image files in "OSCAL SSP/resources" folder per the snippet you provide above)? Thanks again for your bug report and follow-through. |
commit f010473 Author: wandmagic <156969148+wandmagic@users.noreply.github.com> Date: Tue Dec 10 15:08:00 2024 -0500 re-introduce implemented-requirements constraints (GSA#981) * re-introduce implemented-requirements constraints * add doc available check for health url * fix spacing * Update src/validations/constraints/fedramp-external-constraints.xml Co-authored-by: Gabeblis <gabriel.rodriguez@gsa.gov> * Update src/validations/constraints/fedramp-external-constraints.xml Co-authored-by: Gabeblis <gabriel.rodriguez@gsa.gov> --------- Co-authored-by: Gabeblis <gabriel.rodriguez@gsa.gov> commit c0ad00e Author: Gabeblis <gabriel.rodriguez@gsa.gov> Date: Mon Dec 9 17:17:47 2024 -0500 Adjust link for all profiles (GSA#979) commit 8561600 Author: Gabeblis <gabriel.rodriguez@gsa.gov> Date: Mon Dec 9 11:27:48 2024 -0500 Add Components To `information-type-800-60-v2r1` Allowed Values (GSA#973) * Add Leveraged Authorizations and External, Interconnected, and Unauthorized Systems components to information-type allowed values * Adjust constraint target commit 788b67e Author: Gabeblis <gabriel.rodriguez@gsa.gov> Date: Mon Dec 9 09:32:35 2024 -0500 Fix constraint targets (GSA#974) commit 9d7946c Author: A.J. Stein <alexander.stein@gsa.gov> Date: Fri Dec 6 17:10:04 2024 -0500 [chore] Update container image to cli v2.4.0 (GSA#971) commit b2c9712 Author: Gabeblis <gabriel.rodriguez@gsa.gov> Date: Fri Dec 6 15:26:04 2024 -0500 Add `used-by-link-references-component` constraint (GSA#972) * Add 'used-by-link-references-component' constraint * Fix message Co-authored-by: Kylie Hunter <kylie.hunter@gsa.gov> * fix message Co-authored-by: DimitriZhurkin <dimitri.zhurkin@noblis.org> --------- Co-authored-by: Kylie Hunter <kylie.hunter@gsa.gov> Co-authored-by: DimitriZhurkin <dimitri.zhurkin@noblis.org> commit 3dac668 Author: Gabeblis <gabriel.rodriguez@gsa.gov> Date: Fri Dec 6 13:43:16 2024 -0500 Add `component-has-used-by-link` constraint (GSA#970) * Add constraint 'protocol-has-used-by-link' * Fix message * Change constraint id * Fix message (last time) * Update src/validations/constraints/content/ssp-component-has-used-by-link-INVALID.xml Co-authored-by: A.J. Stein <aj@gsa.gov> --------- Co-authored-by: A.J. Stein <aj@gsa.gov> commit c3db2b2 Author: DimitriZhurkin <dimitri.zhurkin@noblis.org> Date: Thu Dec 5 13:07:39 2024 -0700 Add inter-boundary-component-has-direction constraint (GSA#930) (GSA#968) commit 5d6710f Author: Gabeblis <gabriel.rodriguez@gsa.gov> Date: Thu Dec 5 13:32:28 2024 -0500 Fix dev-constraint.js bug (GSA#967) commit a7f9022 Author: Gabeblis <gabriel.rodriguez@gsa.gov> Date: Thu Dec 5 13:23:21 2024 -0500 Add exists() to tests and remove duplicate constraint and fix system-implementation context (GSA#966) Remove duplicate constraint and fix system-implementation context commit 780b38a Author: wandmagic <156969148+wandmagic@users.noreply.github.com> Date: Thu Dec 5 12:50:29 2024 -0500 Hotfix/deprecate all valid (GSA#960) * deprecate ssp-all-valid * Update src/validations/constraints/content/ssp-has-network-architecture-diagram-link-href-target-VALID-1.xml Co-authored-by: A.J. Stein <aj@gsa.gov> * Update src/validations/constraints/content/ssp-has-authorization-boundary-diagram-link-href-target-VALID-1.xml Co-authored-by: A.J. Stein <aj@gsa.gov> * Update src/validations/constraints/content/ssp-has-data-flow-diagram-link-href-target-VALID-1.xml Co-authored-by: A.J. Stein <aj@gsa.gov> * Update src/validations/constraints/content/ssp-has-network-architecture-diagram-link-href-target-VALID-1.xml Co-authored-by: A.J. Stein <aj@gsa.gov> * Update fedramp-ssp-example.oscal.xml --------- Co-authored-by: A.J. Stein <aj@gsa.gov> commit 2c0e4de Author: Gabeblis <gabriel.rodriguez@gsa.gov> Date: Thu Dec 5 10:21:00 2024 -0500 Change cia-has-selected test (GSA#965) commit 9a8e155 Author: wandmagic <156969148+wandmagic@users.noreply.github.com> Date: Wed Dec 4 15:30:29 2024 -0500 Update fedramp-ssp-example.oscal.xml (GSA#959) commit 5f7ce81 Author: Gabeblis <gabriel.rodriguez@gsa.gov> Date: Tue Dec 3 23:38:31 2024 +0000 change example ssp location commit 56f399e Author: Gabeblis <gabriel.rodriguez@gsa.gov> Date: Tue Dec 3 23:23:59 2024 +0000 Edit content to make constraints pass commit d521a22 Author: Gabeblis <gabriel.rodriguez@gsa.gov> Date: Tue Dec 3 19:12:01 2024 +0000 Delete extra ssp commit 8cfb601 Author: Gabeblis <gabriel.rodriguez@gsa.gov> Date: Tue Dec 3 17:39:38 2024 +0000 Add example ssp to content file and edit constraint script to point yaml pass file to example ssp commit ff8f812 Author: ~ . ~ <paul.n.wand@gsa.gov> Date: Tue Dec 3 13:50:22 2024 -0500 fix ssp to pass tests commit 85ec424 Author: Gabeblis <gabriel.rodriguez@gsa.gov> Date: Tue Dec 3 17:17:18 2024 +0000 Add example ssp to content file and edit constraint script to point yaml pass file to example ssp commit 7312686 Author: Kylie Hunter <kylie.hunter@gsa.gov> Date: Mon Nov 25 16:15:01 2024 -0700 Add connection-security prop constraint for GSA#931 commit 6ccb539 Author: Gabeblis <gabriel.rodriguez@gsa.gov> Date: Tue Dec 3 16:39:47 2024 -0500 Add `issue-893` Constraints (GSA#949) * Add component-has-non-provider-responsible-role and tests * Add constraints and tests * Edit message commit dd3be5f Author: wandmagic <156969148+wandmagic@users.noreply.github.com> Date: Tue Dec 3 16:39:32 2024 -0500 remove rev4 constraints (GSA#954) commit 113c4f5 Author: Gabeblis <gabriel.rodriguez@gsa.gov> Date: Tue Dec 3 15:42:43 2024 -0500 Fix Bug Issue GSA#940 (GSA#951) commit c6f8e8f Author: wandmagic <156969148+wandmagic@users.noreply.github.com> Date: Tue Dec 3 13:08:35 2024 -0500 implementation point constraint (GSA#936) * implementation point constraint * add help uri * improve constraint * add extra fail content * Update src/validations/constraints/content/ssp-all-VALID.xml Co-authored-by: DimitriZhurkin <dimitri.zhurkin@noblis.org> * Update fedramp-external-constraints.xml Co-authored-by: Rene Tshiteya <rene-claude.tshiteya@gsa.gov> * implementation point constraint * add help uri * improve constraint * add extra fail content * Update src/validations/constraints/content/ssp-all-VALID.xml Co-authored-by: DimitriZhurkin <dimitri.zhurkin@noblis.org> * Update fedramp-external-constraints.xml Co-authored-by: Rene Tshiteya <rene-claude.tshiteya@gsa.gov> * add needed props to all valid * rebase Co-Authored-By: A.J. Stein <aj@gsa.gov> * Update src/validations/constraints/fedramp-external-constraints.xml Co-authored-by: A.J. Stein <aj@gsa.gov> --------- Co-authored-by: DimitriZhurkin <dimitri.zhurkin@noblis.org> Co-authored-by: Rene Tshiteya <rene-claude.tshiteya@gsa.gov> Co-authored-by: A.J. Stein <aj@gsa.gov> commit 1377478 Author: Gabeblis <gabriel.rodriguez@gsa.gov> Date: Tue Dec 3 08:57:37 2024 -0500 Add `component-responsible-role-references-party` constraint (GSA#945) * Add constraint 'component-responsible-role-references-party' and tests * correct test * Rename constraint and adjust help-url * Edit message Co-authored-by: A.J. Stein <aj@gsa.gov> --------- Co-authored-by: A.J. Stein <aj@gsa.gov> commit a8461fb Author: ~ . ~ <paul.n.wand@gsa.gov> Date: Mon Dec 2 11:09:13 2024 -0500 pin server + update oscal-js version commit b82c417 Author: Gabeblis <gabriel.rodriguez@gsa.gov> Date: Mon Dec 2 14:07:05 2024 -0500 Add `leveraged-authorization-has-valid-impact-level` Constraint (GSA#913) * Add leveraged-authorization constraint * rename constraint * fix constraint test * correct constraint test * Change 'http' to 'https' * Add level commit 1db5f97 Author: Gabeblis <gabriel.rodriguez@gsa.gov> Date: Mon Dec 2 13:13:17 2024 -0500 Constraints/cleanup constraints file (GSA#946) * clean up fedramp-external-constraints.xml * fix * Add message to fully-operational-date-type
@aj-stein-gsa I just added the files to the repository with all of the resources, and the updated prop structures for data-flow, authorization-boundary, and network-architecture |
After some debugging we determined that ancestor axis in a predicate is not properly evaluating _unless_ you explicitly declare a namespace binding declaration and use the prefix in this case. This variation works around metashcema-framework/metaschema-java#291 to successfully filter the target and evaluate the test.
I confirmed that the updated code and ran the test samples provided from our community partner @Telos-sa and the error is no longer thrown. This work is back to ready to ship now that docs are included. |
This relates to ...
What happened?
When running the FedRAMP constraints against the example SSP, errors occurred while evaluating the expressions related to the presence of the authorization boundary, data flow, and network architecture.
The three are nearly identical, and there is a syntax error in the metapath.
Upon closer evaluation, the constraint needed a few revisions, even if the syntax is corrected. This is due in part to ongoing re-modeling work.
Relevant log output
How do we replicate this issue?
Run oscal-cli v 2.2.0 against the example SSP file using the
fedramp-external-constraints.xml
file in thedevelop
branch.Observe the error for each of the three diagram types.
Where, exactly?
This is happening for each
//system-characteristics/*/diagram/@href
(where the*
representsauthorization-boundary
,data-flow
ornetwork-architecture
Other relevant details
The following should be used for each constraint:
Please note, we are actually checking the link if it is not a URI fragment, and it needs to be reachable. We are are aligning the "type" property with core OSCAL and using the
@class
to provide a more granular typing to meet FedRAMP's needs.The text was updated successfully, but these errors were encountered: