133 lines
5.1 KiB
Markdown
133 lines
5.1 KiB
Markdown
|
|
# Conformance reporting contract
|
||
|
|
|
||
|
|
**Owner:** gate-house
|
||
|
|
**Executor:** whitehat-security
|
||
|
|
**Posture observer:** kings-guard
|
||
|
|
**Finding triage:** risk-nexus
|
||
|
|
**Status:** normative for GH-WP-0001-T06
|
||
|
|
**Version:** conformance-reporting.v1
|
||
|
|
**Date:** 2026-09-01
|
||
|
|
|
||
|
|
## 1. Purpose
|
||
|
|
|
||
|
|
This contract establishes how execution of a Gate House assurance
|
||
|
|
specification returns to doctrine review. It preserves four distinct judgments:
|
||
|
|
|
||
|
|
```text
|
||
|
|
Gate House specifies the invariant and executable target
|
||
|
|
whitehat-security attacks and reports whether the observed control held
|
||
|
|
risk-nexus owns finding severity, disclosure, and owner routing
|
||
|
|
Gate House decides whether the result requires doctrine change
|
||
|
|
```
|
||
|
|
|
||
|
|
Gate House does not grade its own specification by reinterpreting a whitehat
|
||
|
|
result, assign severity, close an implementation defect, or block delivery.
|
||
|
|
|
||
|
|
## 2. Report envelope
|
||
|
|
|
||
|
|
Whitehat-security continues to use `whitehat-run/v1` as its native report. For
|
||
|
|
Gate House conformance return, the report or a value-safe projection must also
|
||
|
|
make these fields expressible:
|
||
|
|
|
||
|
|
```yaml
|
||
|
|
schema_version: conformance-reporting.v1
|
||
|
|
report_id: <stable id>
|
||
|
|
specification:
|
||
|
|
id: asm-assurance-targets.v1
|
||
|
|
test_id: T-03
|
||
|
|
target:
|
||
|
|
component: <repo or protected system>
|
||
|
|
revision: <immutable revision>
|
||
|
|
environment: <fixture/build/production>
|
||
|
|
claim:
|
||
|
|
invariant_ids: [A-14, INV-05]
|
||
|
|
engagement_id: <whitehat engagement>
|
||
|
|
authorization_id: <recorded authorization>
|
||
|
|
run_id: <whitehat run>
|
||
|
|
outcome: pass | finding | inconclusive | aborted
|
||
|
|
known_bad_calibration_ref: <evidence ref>
|
||
|
|
evidence_refs: []
|
||
|
|
emission_guarantee_refs: []
|
||
|
|
limitations: []
|
||
|
|
assurance_statement: <bounded statement>
|
||
|
|
returned_at: <RFC 3339 UTC>
|
||
|
|
```
|
||
|
|
|
||
|
|
The projection contains no credential value, secret, unrelated response body,
|
||
|
|
severity, disclosure decision, or exploit detail unsafe for the recipient.
|
||
|
|
|
||
|
|
## 3. Outcome rules
|
||
|
|
|
||
|
|
- Every outcome returns, including `pass`, because target revision and run date
|
||
|
|
define the freshness of limited assurance.
|
||
|
|
- `inconclusive` and `aborted` do not count as conformance.
|
||
|
|
- A known-bad calibration that has never failed makes the target
|
||
|
|
`inconclusive`, even if the real target probe reports no effect.
|
||
|
|
- A changed target revision invalidates any claim that the earlier result is
|
||
|
|
current unless the executor records why the change is immaterial.
|
||
|
|
- Absence of a report is `not_run`, not `pass`.
|
||
|
|
- A passing report states only that the recorded attacks did not cross the
|
||
|
|
boundary under the recorded conditions.
|
||
|
|
|
||
|
|
## 4. Return transport
|
||
|
|
|
||
|
|
The durable coordination envelope is a State Hub inbox message to
|
||
|
|
`gate-house`:
|
||
|
|
|
||
|
|
```text
|
||
|
|
Subject: [GH-CONFORMANCE] <test-id> <outcome> <target>@<revision>
|
||
|
|
Body: report id, safe report/evidence references, specification version,
|
||
|
|
run and authorization ids, limitations, and requested Gate House action
|
||
|
|
```
|
||
|
|
|
||
|
|
Large or sensitive evidence remains under whitehat-security/risk-nexus custody;
|
||
|
|
the message carries stable references and a value-safe summary. The emitting
|
||
|
|
repository records the report in its own work structure before sending the
|
||
|
|
message.
|
||
|
|
|
||
|
|
## 5. Finding routes
|
||
|
|
|
||
|
|
| Result | Required route |
|
||
|
|
| --- | --- |
|
||
|
|
| Implementation control failed | whitehat-security → risk-nexus → implementation owner; Gate House receives the safe conformance report. |
|
||
|
|
| Doctrine is ambiguous, contradictory, unsafe, or impossible to test | whitehat-security or kings-guard → Gate House intake/message, citing test and evidence. |
|
||
|
|
| Target or execution harness gap | whitehat-security owns or promotes the gap in its repository; Gate House records the test as pending. |
|
||
|
|
| Posture, stream-silence, or live-observation gap | kings-guard owns or promotes the observation gap and returns the safe finding to Gate House. |
|
||
|
|
| Severity/disclosure question | risk-nexus only. |
|
||
|
|
|
||
|
|
One observation may take both the implementation and doctrine routes. The two
|
||
|
|
records cross-reference one another; Gate House does not absorb the owner's
|
||
|
|
remediation task.
|
||
|
|
|
||
|
|
## 6. Gate House review record
|
||
|
|
|
||
|
|
For each returned report, Gate House records:
|
||
|
|
|
||
|
|
- report, target, revision, test, and invariant identifiers;
|
||
|
|
- whitehat outcome without changing it;
|
||
|
|
- doctrine disposition: `no_change`, `clarify`, `revise`, `new_target`, or
|
||
|
|
`withdraw_claim`;
|
||
|
|
- any Gate House intake, decision, contract revision, or workplan produced;
|
||
|
|
- implementation/risk-nexus reference where a control failed;
|
||
|
|
- next review trigger: target revision, cadence date, or finding closure.
|
||
|
|
|
||
|
|
A conformance review is complete when the result has an explicit doctrine
|
||
|
|
disposition and every residual has a live owner. Closing a Gate House review
|
||
|
|
does not close the underlying security finding.
|
||
|
|
|
||
|
|
## 7. Cadence and aggregation
|
||
|
|
|
||
|
|
Cadence belongs to whitehat-security because the run interval is part of the
|
||
|
|
attacker model and exposure window. Gate House may request a minimum review
|
||
|
|
condition, but it must not label stale evidence current.
|
||
|
|
|
||
|
|
Gate House may publish an aggregate conformance view only if it preserves:
|
||
|
|
|
||
|
|
- target and revision specificity;
|
||
|
|
- last executed and next due times;
|
||
|
|
- outcome and limitations;
|
||
|
|
- tests that are pending, inapplicable, inconclusive, or not run;
|
||
|
|
- the audit completeness bound.
|
||
|
|
|
||
|
|
An aggregate must not turn missing reports into green cells.
|