Skip to content

docs(hackbot): propose running Clauditor Smart Window mode as an agent - #6615

Open
groovecoder wants to merge 1 commit into
mozilla:masterfrom
groovecoder:propose-clauditor-smart-window
Open

docs(hackbot): propose running Clauditor Smart Window mode as an agent#6615
groovecoder wants to merge 1 commit into
mozilla:masterfrom
groovecoder:propose-clauditor-smart-window

docs(hackbot): propose running Clauditor Smart Window mode as an agent

a766d84
Select commit
Loading
Failed to load commit list.
Community-TC Integration / bugbug lint failed Aug 17, 2026 in 2m 17s

Community-TC (pull_request)

bugbug lint

Details

View task in Taskcluster | View logs in Taskcluster | View task group in Taskcluster

Task Status

Started: 2026-08-17T20:31:07.852Z
Resolved: 2026-08-17T20:33:23.763Z
Task Execution Time: 2 minutes, 15 seconds, 911 milliseconds
Task Status: failed
Reason Resolved: failed
TaskId: Q0b9lkQjShm1BwSSAtxQ2w
RunId: 0

Artifacts

- public/logs/live_backing.log (1.3 MB)
- public/logs/live.log


[taskcluster 2026-08-17T20:31:07.918Z] Worker Type (proj-bugbug/batch) settings:
[taskcluster 2026-08-17T20:31:07.918Z]   {
[taskcluster 2026-08-17T20:31:07.918Z]     "generic-worker": {
[taskcluster 2026-08-17T20:31:07.918Z]       "config": {
[taskcluster 2026-08-17T20:31:07.918Z]         "headlessTasks": false
[taskcluster 2026-08-17T20:31:07.918Z]       },
[taskcluster 2026-08-17T20:31:07.918Z]       "engine": "multiuser",
[taskcluster 2026-08-17T20:31:07.918Z]       "go-arch": "amd64",
[taskcluster 2026-08-17T20:31:07.918Z]       "go-os": "linux",
[taskcluster 2026-08-17T20:31:07.918Z]       "go-version": "go1.26.2",
[taskcluster 2026-08-17T20:31:07.918Z]       "release": "https://github.com/taskcluster/taskcluster/releases/tag/v99.1.0",
[taskcluster 2026-08-17T20:31:07.918Z]       "revision": "c76d61efe4bdc1a05bcec848739cd41ebf061f01",
[taskcluster 2026-08-17T20:31:07.918Z]       "source": "https://github.com/taskcluster/taskcluster/commits/c76d61efe4bdc1a05bcec848739cd41ebf061f01",
[taskcluster 2026-08-17T20:31:07.918Z]       "version": "99.1.0"
[taskcluster 2026-08-17T20:31:07.918Z]     },
[taskcluster 2026-08-17T20:31:07.918Z]     "image": "projects/community-tc-workers/global/images/generic-worker-ubuntu-24-04-aaynirqnxlbwcojgnbeo",
[taskcluster 2026-08-17T20:31:07.918Z]     "instance-id": "4495823038053274090",
[taskcluster 2026-08-17T20:31:07.918Z]     "instance-type": "projects/757942385826/machineTypes/n2-standard-2",
[taskcluster 2026-08-17T20:31:07.918Z]     "local-ipv4": "10.150.0.101",
[taskcluster 2026-08-17T20:31:07.918Z]     "machine-setup": {

...(74 lines hidden)...

[INFO] Installing environment for https://github.com/astral-sh/ruff-pre-commit.
[INFO] Once installed this environment will be reused.
[INFO] This may take a few minutes...
[INFO] Installing environment for https://github.com/pre-commit/pre-commit-hooks.
[INFO] Once installed this environment will be reused.
[INFO] This may take a few minutes...
[INFO] Installing environment for https://github.com/codespell-project/codespell.
[INFO] Once installed this environment will be reused.
[INFO] This may take a few minutes...
[INFO] Installing environment for https://github.com/marco-c/taskcluster_yml_validator.
[INFO] Once installed this environment will be reused.
[INFO] This may take a few minutes...
[INFO] Installing environment for https://github.com/asottile/yesqa.
[INFO] Once installed this environment will be reused.
[INFO] This may take a few minutes...
[INFO] Installing environment for https://github.com/pre-commit/mirrors-mypy.
[INFO] Once installed this environment will be reused.
[INFO] This may take a few minutes...
[INFO] Installing environment for https://github.com/pre-commit/mirrors-mypy.
[INFO] Once installed this environment will be reused.
[INFO] This may take a few minutes...
prettier.................................................................Failed
- hook id: prettier
- files were modified by this hook

docs/hackbot/clauditor-integration.md

ruff check...............................................................Passed
ruff format..............................................................Passed
check python ast.........................................................Passed
check docstring is first.................................................Passed
check that executables have shebangs.....................................Passed
check for merge conflicts................................................Passed
check for broken symlinks............................(no files to check)Skipped
debug statements (python)................................................Passed
trim trailing whitespace.................................................Passed
check yaml...............................................................Passed
mixed line ending........................................................Passed
python tests naming......................................................Passed
check json...............................................................Passed
check vcs permalinks.....................................................Passed
codespell................................................................Passed
taskcluster_yml..........................................................Passed
Strip unnecessary `# noqa`s..............................................Passed
mypy-bugbug..............................................................Passed
mypy-bugbug-http.........................................................Passed
Check for useless excludes...............................................Passed
pre-commit hook(s) made changes.
If you are seeing this message in CI, reproduce locally with: `pre-commit run --all-files`.
To run `pre-commit` as part of git workflow, use `pre-commit install`.
All changes made by hooks:
diff --git a/docs/hackbot/clauditor-integration.md b/docs/hackbot/clauditor-integration.md
index 4b090a25..635725e6 100644
--- a/docs/hackbot/clauditor-integration.md
+++ b/docs/hackbot/clauditor-integration.md
@@ -24,8 +24,8 @@ button to file the bug.
 history, and memories. A bug could leak that private data. So, we want a standing,
 automated check for those bugs, running on the same platform the Firefox teams already use.
 
-We use Hackbot's checkout, review, and bug-filing plumbing instead of clauditor's, and 
-instead of building our own. The audit runs on a schedule we control, and no bug is filed 
+We use Hackbot's checkout, review, and bug-filing plumbing instead of clauditor's, and
+instead of building our own. The audit runs on a schedule we control, and no bug is filed
 without a human saying yes.
 
 The integration is small. Smart Window mode is the lightest Clauditor mode. It
@@ -55,17 +55,17 @@ Firefox vulnerabilities.
   only needs a source checkout and an artifact test build. This makes it stable to
   integrate: it will not shift as the `generic` inventory evolves.
 - Clauditor can file bugs. Its cloud filing step (`src/cloud/auto_file.py` in the
-  Clauditor repo) supports a `--dry-run` flag that reports what it *would* file without
+  Clauditor repo) supports a `--dry-run` flag that reports what it _would_ file without
   filing it. But in our case, **Hackbot will file the bugs - not Clauditor.**
 
 #### New Clauditor Smart Window mode context
 
-Smart Window prevents private-data leaks by blocking cross-origin fetches when two flags 
+Smart Window prevents private-data leaks by blocking cross-origin fetches when two flags
 are present at the same time: `privateData` and `untrustedInput`.
 
 Smart Window trusts some fields of input because it **hardens** its prompts against malicious input.
 
-So, the Clauditor Smart Window mode hunts for a **hardening bypass** in `browser/components/aiwindow`: 
+So, the Clauditor Smart Window mode hunts for a **hardening bypass** in `browser/components/aiwindow`:
 a path where attacker-controlled web content reaches the model as if it were trusted when it should
 not be trusted. If it finds one, it proves exfiltration end to end.
 
@@ -112,19 +112,19 @@ Hackbot is a job launcher. Each agent is a self-contained folder under `agents/<
   Smart Window runs leave the checkout clean, so this patch will be empty for us; the
   agent publishes its files as artifacts instead (`ctx.publish_file`).
 
-#### How runs get triggered today 
+#### How runs get triggered today
 
 Three paths:
 
 1. a direct API POST (`POST /agents/{name}/runs`)
 2. a Phabricator webhook
-3. a pulse-listener that reacts to CI failures 
+3. a pulse-listener that reacts to CI failures
 
 **There is no scheduler and no cron.** Nightly runs need an external timer that calls the API.
 
 #### The action-review flow (important for bug filing)
 
-Hackbot separates *recording* an action from *applying* it.
+Hackbot separates _recording_ an action from _applying_ it.
 
 - An agent records an intent with a tool like `bugzilla.create_bug`. Nothing is written
   to Bugzilla. The intent lands in `summary.json` and shows in the UI.
@@ -174,7 +174,7 @@ A new Hackbot agent folder whose image installs Clauditor. The agent's `main()`
 subprocess. It reads Clauditor's finding from the output directory and translates it
 into a Hackbot result and a recorded `bugzilla.create_bug` action.
 
-**A bridge from clauditor results to hackbot results**: The Clauditor subprocess does not know 
+**A bridge from clauditor results to hackbot results**: The Clauditor subprocess does not know
 about Hackbot's action recorder. So a wrapper performs the handoff:
 
 1. Run Clauditor find-only (or `--dry-run`) so Clauditor files nothing itself.
@@ -183,20 +183,20 @@ about Hackbot's action recorder. So a wrapper performs the handoff:
 4. Record a Hackbot `bugzilla.create_bug` action with the finding, filed into a security
    group.
 
-Clauditor already splits finding from filing, and Hackbot already separates *recording* 
-an action from *applying* it, so this is a clean handoff.
+Clauditor already splits finding from filing, and Hackbot already separates _recording_
+an action from _applying_ it, so this is a clean handoff.
 
 #### Where the results land
 
 Clauditor writes its results to `<output>/<target-stem>_<YYYYmmdd_HHMMSS>/`. Point
 `--output` at a known directory and read the one child. It contains:
 
-| File | What it is |
-|---|---|
-| `browser_security_*.js` | The mochitest that proves the leak |
-| `crash_stack.txt` | The `mach test` output with the failing secure assertion |
-| `analysis.md` / `analysis.json` | The verifier's authoritative report |
-| `verifier_verdict-*.md` | The verifier's verdict per iteration |
+| File                            | What it is                                               |
+| ------------------------------- | -------------------------------------------------------- |
+| `browser_security_*.js`         | The mochitest that proves the leak                       |
+| `crash_stack.txt`               | The `mach test` output with the failing secure assertion |
+| `analysis.md` / `analysis.json` | The verifier's authoritative report                      |
+| `verifier_verdict-*.md`         | The verifier's verdict per iteration                     |
 
 These files are the deliverable. The wrapper publishes them as artifacts and builds the
 bug description from `analysis.md`.
@@ -237,16 +237,18 @@ prompts are shared or copied.
 ## Open questions and decisions
 
 1. **What drives a nightly run?**
-   Hackbot has no scheduler. An external timer must call the API once a day. 
+   Hackbot has no scheduler. An external timer must call the API once a day.
    Options:
-   * GCP Cloud Scheduler 
-   * Taskcluster cron hook.
- 
+
+   - GCP Cloud Scheduler
+   - Taskcluster cron hook.
+
    **Decision needed from Hackbot.**
 
 2. **Bug filing details.** We plan to file into a security-restricted group via a pending
    action an engineer approves. We need:
-   * the target product, component, and group, and a named owner who triages the pending bug.
+
+   - the target product, component, and group, and a named owner who triages the pending bug.
 
    **Decision needed from Smart Window.**
 
@@ -255,11 +257,12 @@ prompts are shared or copied.
    codebase. Options A and B put Clauditor inside the Hackbot agent image, so the image
    build needs a way to pull it. If the repo is private, that pull needs credentials.
    Options:
-   * (Recommended) **Install from Git (see below)** — the agent's `pyproject.toml` depends on Clauditor
+
+   - (Recommended) **Install from Git (see below)** — the agent's `pyproject.toml` depends on Clauditor
      at a pinned git ref. Simplest; a private repo needs a build-time deploy token or key.
-   * **Publish a package** — Clauditor ships to PyPI or a private Artifact Registry, and
+   - **Publish a package** — Clauditor ships to PyPI or a private Artifact Registry, and
      the agent pins a version. Cleaner versioning; Clauditor must set up publishing.
-   * **Vendor the prompts (Option C only)** — no code dependency. Copy the Smart Window
+   - **Vendor the prompts (Option C only)** — no code dependency. Copy the Smart Window
      prompts into Hackbot and keep them in sync by hand.
 
    **Decision needed from Clauditor + Hackbot.**
[taskcluster 2026-08-17T20:33:21.823Z]                        Exit Code: 1
[taskcluster 2026-08-17T20:33:21.823Z]                        User Time: 31.062ms
[taskcluster 2026-08-17T20:33:21.823Z]                      Kernel Time: 39.63ms
[taskcluster 2026-08-17T20:33:21.823Z]                        Wall Time: 1m48.582025831s
[taskcluster 2026-08-17T20:33:21.823Z]  Average Available System Memory: 6.29 GiB
[taskcluster 2026-08-17T20:33:21.823Z]       Average System Memory Used: 1.47 GiB
[taskcluster 2026-08-17T20:33:21.823Z]          Peak System Memory Used: 1.74 GiB
[taskcluster 2026-08-17T20:33:21.823Z]              Total System Memory: 7.75 GiB
[taskcluster 2026-08-17T20:33:21.823Z]                           Result: FAILED
[taskcluster 2026-08-17T20:33:21.824Z] === Task Finished ===
[taskcluster 2026-08-17T20:33:21.824Z] Task Duration: 1m48.582492564s
[taskcluster:error] exit status 1