chainsaw risk-weights

Show, preview, and apply per-signal risk-weight overrides

Show, preview, and apply per-signal risk-weight overrides

SubcommandWhat it does
chainsaw risk-weights applyPersist a previewed weight set (requires a fresh –simulate-id)
chainsaw risk-weights previewPreview the verdict-flip impact of a draft weight set
chainsaw risk-weights showPrint current category + signal weights
chainsaw risk-weights [command]

risk-weights is the CLI front-end for tuning the v2 risk engine’s per-signal weights with a mandatory simulate-then-confirm gate. The ‘preview’ subcommand returns a flip-impact projection (would-block / would-permit deltas plus sample flips) and a simulate_id; the ‘apply’ subcommand requires a fresh simulate_id from a recent preview.

The gate exists to prevent finger-fumble reclassifications: a single PUT with bad weights can flip thousands of packages from permit to block. preview-then-apply forces the operator to eyeball the impact before saving.

chainsaw risk-weights apply

Persist a previewed weight set (requires a fresh –simulate-id)

chainsaw risk-weights apply [flags]

apply PUTs the same –set values you previewed, attached to your preview’s simulate_id:

chainsaw risk-weights apply --simulate-id <id> --set vuln.cvss_high=70

The –set values must match the ones you previewed exactly — the server re-derives the simulate inputs hash from them and returns CHW-4830 if they drifted, if the preview is older than 1h, or if another operator saved different weights in between. Re-run ‘preview’ and apply the new id.

If the preview itself could not model the change – it returned a fallback reason instead of real projected impact – the server refuses the save with CHW-4834 rather than treating an empty projection as your consent. Fix the cause and re-preview, or pass –acknowledge-degraded-preview to save anyway; the waiver is recorded in the audit log against your user.

apply prints the weights the server read BACK from storage, so the output is proof the write landed rather than an echo of the request. Confirm independently with ‘chainsaw risk-weights show’.

Flags

FlagTypeDefaultDescription
--acknowledge-degraded-previewbool—save even though the preview could not model the change (server answers CHW-4834 otherwise); the waiver is audited
--setstringSlice—same –set values used during preview (must match exactly)
--simulate-idstring—simulate_id returned by a fresh ‘risk-weights preview’ run

The global flags apply here too.

chainsaw risk-weights preview

Preview the verdict-flip impact of a draft weight set

chainsaw risk-weights preview [flags]

Preview prints projected verdict flips for the supplied draft weights. Use –set repeatedly to override individual signals:

chainsaw risk-weights preview \
    --set vuln.cvss_high=70 \
    --set sc.publisher_changed=50

Signal ids must exist in the engine registry — list them with ‘chainsaw risk-weights show’ or GET /api/risk/signals. A few signals that back instant-block enforcement (vuln.kev, sc.known_malicious, qual.checksum_mismatch) are not tunable and are rejected.

Prints the simulate_id, the would-block / would-permit / flip counts, and the first 10 sample flips. The simulate_id is required by ‘apply’ and expires after 1 hour.

Flags

FlagTypeDefaultDescription
--setstringSlice—signal weight override in the form <signalId>=<int>; repeat for multiple

The global flags apply here too.

chainsaw risk-weights show

Print current category + signal weights

chainsaw risk-weights show