Finish GH-WP-0001 conformance loop

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a05e30-2884-71b0-98d7-7edd16ae737b
This commit is contained in:
tegwick 2026-09-02 15:49:25 +02:00
parent 18ec61a696
commit c0c25e7056
7 changed files with 158 additions and 43 deletions

View file

@ -1,7 +1,7 @@
# Conformance candidate — secrets-engine approval consumption
**Repository:** gate-house
**Status:** candidate; not executed by whitehat-security
**Status:** promoted into Whitehat fixture calibration; live target pending
**Date:** 2026-09-02
**Canon target:** T-06 — Approval Replay Test
**Implementer:** secrets-engine
@ -45,18 +45,15 @@ inferred from the surrounding workplan history. Gate House accepts that
correction. The initial test count remains a working-tree suitability check;
the immutable candidate revision is `4b4d556`.
## What whitehat-security must still supply
## Whitehat return
Whitehat-security owns the probe design and outcome. A conforming return still
requires all of the following under `conformance-reporting.v1`:
Whitehat-security supplied the fixture-only probe, known-bad calibration, and
contract-complete return under `conformance-reporting.v1`:
1. independently identify the exact target revision and fixture boundary;
2. author a known-bad fixture that disables at least one replay protection,
such as different-digest conflict or atomic single-use consumption;
3. demonstrate that the known-bad fixture accepts a prohibited replay or loses
the T-06 oracle;
4. run the same probe against the unmodified candidate;
5. return `pass`, `fail`, `blocked`, or `not_run` with safe evidence references.
- Whitehat evidence revision `75deaf0`;
- return message `a1ebf012-bd1e-43d2-843c-ba3ddecb8c82`;
- final Gate House review
`docs/conformance/2026-09-02-whitehat-t06-fixture-return.md`.
The existing implementer tests may be reused as setup evidence but must not be
reported as independent Whitehat evidence.