Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a02991-be07-7bb3-8b6d-e9701b5621de
69 lines
3 KiB
Markdown
69 lines
3 KiB
Markdown
# WH-ENG-20260822-AUDIT-E2-03 target pass
|
|
|
|
Date: 2026-08-22
|
|
Workplan task: `AUDIT-WP-0008-T05`
|
|
Evidence class: adversarial target run
|
|
Outcome: pass, with no reported limitations
|
|
|
|
## Claim and limit
|
|
|
|
An ordinary identity bound to fixture tenant A attempted to read and create
|
|
fixture data belonging to tenant B through audit-core's public application
|
|
routes. All three calibrated probes passed. This is evidence that the attacks
|
|
attempted in this bounded run did not work; it is not proof that audit-core's
|
|
tenant boundary always holds.
|
|
|
|
The target revision was
|
|
`sha256:c2fe39a0185b99be3fc0cb14d2de69772b8e66e20490097c9d11d90cc39719a6`.
|
|
The run started at `2026-08-22T22:09:30.705690Z`, ended at
|
|
`2026-08-22T22:10:25.073895Z`, and attempted ten operations with concurrency
|
|
one. No non-fixture data was collected.
|
|
|
|
## Probe observations
|
|
|
|
- `audit-event-by-id`: the tenant-B owner received the declared fixture with
|
|
status 200. The tenant-A attacker received the same status, schema and digest
|
|
as the deliberately absent-object control: 404, with no fixture match.
|
|
- `audit-correlation-slice`: the owner result contained both tenant-B fixture
|
|
markers. The attacker result contained zero tenant-B fixture markers.
|
|
- `audit-append-as-b`: the tenant-A attempt to append as tenant B was refused
|
|
with status 400. A subsequent owner read returned the same 404 digest and
|
|
schema as the absent-object control, demonstrating no created fixture.
|
|
|
|
The complete sanitized observations are in
|
|
`AUDIT-WP-0008-T05-whitehat-e2-03-final-report.json`, SHA-256
|
|
`2d5a21141b78024a5334881e2b7fd62a69c46931057f77515a6c6f18ec497593`.
|
|
|
|
## Custody and cleanup
|
|
|
|
Projection receipt
|
|
`sha256:c22ef5651efde1416f33936e193a3438c09a1284925b36f51fa6328519c7d02e`
|
|
bound the two projected handles to lease
|
|
`custody:32c03d05b32fa6850d65eeba7bd7e2a0`, expiring at 22:15Z. The runner was
|
|
deleted after the probe. Receipt-bound cleanup completed at 22:13:48Z, before
|
|
expiry, and removed both temporary identities, both exact KV paths, the
|
|
projection resources and mounted Secret. Independent post-cleanup status found
|
|
all exact lists empty, the runner absent, and audit-core `1/1` Ready. No secret
|
|
value was observed or retained.
|
|
|
|
Artifact hashes:
|
|
|
|
- projection receipt:
|
|
`eeb8abd84abf5451915f7ab2c45c722fa58b279a4ec8e62187d20d5af135cde4`
|
|
- cleanup receipt:
|
|
`74d53852f8a0eaead73d468e9e0e12d617807fa3f00028a7473bc3b765738889`
|
|
- broker receipt:
|
|
`85cf0e507d3b84188c1ea39fd9e6f948c2983a08a5aa94b578e952ac832d0433`
|
|
|
|
The sanitized final report reached `risk-nexus` as State Hub message
|
|
`40e3f825-fc70-4091-96d2-9ab01d42184a` with subject
|
|
`WHITEHAT TARGET PASS: WH-ENG-20260822-AUDIT-E2-03`.
|
|
|
|
## Freshness
|
|
|
|
The facility baseline is a 24-hour cadence plus run and reporting latency, with
|
|
event-triggered pre-promotion runs after relevant boundary changes. This
|
|
artifact is therefore due for review or replacement at
|
|
`2026-08-23T22:10:25Z`. Repeating that cadence reliably requires an automated
|
|
multi-driver orchestrator; the attended run proves the sequence but is not a
|
|
sustainable scheduler.
|