Record Whitehat ASM fixture calibrations
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a05e30-2884-71b0-98d7-7edd16ae737b
This commit is contained in:
parent
774f69ff80
commit
18ec61a696
5 changed files with 102 additions and 6 deletions
|
|
@ -0,0 +1,76 @@
|
|||
# Conformance review — Whitehat ASM fixture calibrations
|
||||
|
||||
**Repository:** gate-house
|
||||
**Status:** fixture harness calibrated; live targets pending
|
||||
**Date:** 2026-09-02
|
||||
**Executor:** whitehat-security
|
||||
**Executor revision:** `6f1ca0b`
|
||||
**Source:** State Hub message `32926191-4ca1-46ad-8eec-0d499036d66b`
|
||||
**Specification:** `asm-assurance-targets.v1`
|
||||
**Evidence class:** `fixture`
|
||||
**Gate House disposition:** `no_change`
|
||||
**Workplan:** GH-WP-0001-T06
|
||||
|
||||
## Returned calibration
|
||||
|
||||
Whitehat-security created in-process registrations and evidence for Canon T-01
|
||||
through T-10:
|
||||
|
||||
```text
|
||||
targets/fixture-asm-tNN.json
|
||||
evidence/offline-asm-tNN-calibration.json
|
||||
```
|
||||
|
||||
For every test, the Whitehat-owned known-bad fixture loses the specified oracle
|
||||
and records a `finding`; the corresponding known-good fixture records `pass`.
|
||||
T-08 and T-09 each calibrate two distinct failure shapes. T-06 drives the
|
||||
committed secrets-engine consume client at revision `4b4d556` through an
|
||||
in-process CAS opener; the other fixtures are Whitehat-owned in-process models
|
||||
of their target invariant.
|
||||
|
||||
Gate House reproduced the focused suite against Whitehat revision `6f1ca0b`:
|
||||
|
||||
```text
|
||||
uv run --project /home/worsch/whitehat-security \
|
||||
pytest -p no:cacheprovider tests/test_asm.py tests/test_plane.py tests/test_cli.py
|
||||
53 passed in 0.34s
|
||||
```
|
||||
|
||||
This establishes that each published target has a probe capable of detecting a
|
||||
known-bad case. It closes the risk that a probe could report green merely
|
||||
because it cannot observe its own oracle.
|
||||
|
||||
## Evidence bound
|
||||
|
||||
This is harness calibration, not assurance of ten estate systems:
|
||||
|
||||
- evidence class is `fixture`;
|
||||
- no network, live service, OpenBao instance, credential, packet, or production
|
||||
effect was used;
|
||||
- no live `asm-tNN` registration became applicable;
|
||||
- no component other than the bounded T-06 consume client was exercised;
|
||||
- a fixture `pass` means the probe distinguished its known-good model from its
|
||||
known-bad model, not that the corresponding estate control currently holds.
|
||||
|
||||
All live T-01 through T-10 targets remain `pending` / `not_run` until an owner
|
||||
names the surface, identities, and window and Whitehat admits a dated
|
||||
engagement. `WHITEHAT-WP-0007-T11` preserves that residual.
|
||||
|
||||
## Doctrine disposition
|
||||
|
||||
`no_change` to `asm-assurance-targets.v1`.
|
||||
|
||||
The returned fixture set implements Whitehat-owned attack designs while
|
||||
preserving Gate House's invariant and oracle identifiers. No calibration
|
||||
exposed an ambiguous, contradictory, or untestable Gate House target. This
|
||||
disposition accepts the harness/specification fit only; it does not convert
|
||||
fixture outcomes into live conformance.
|
||||
|
||||
## Reporting residual
|
||||
|
||||
The standalone T-06 return has the required subject and safe evidence
|
||||
reference, but its message/artifact pair does not yet express the engagement
|
||||
and authorization references required by `conformance-reporting.v1`. Gate
|
||||
House requested a reporting-only correction in reply
|
||||
`07572202-c855-4235-8289-5a3d9c8f28ae`; no rerun or live target is required.
|
||||
|
||||
Loading…
Add table
Add a link
Reference in a new issue