# Conformance candidate — secrets-engine approval consumption **Repository:** gate-house **Status:** promoted into Whitehat fixture calibration; live target pending **Date:** 2026-09-02 **Canon target:** T-06 — Approval Replay Test **Implementer:** secrets-engine **Implementation revision:** `4b4d556` **Initial observation:** uncommitted working tree at repository revision `465c0d7` **Source:** State Hub message `99bf84bf-18d2-4e63-a7ac-25078e1c72d5` **Workplan:** GH-WP-0001-T06 ## Why this is a candidate secrets-engine reports that every privileged production OpenBao handler now passes through one shared consume-before-effect function. The implementation is at `src/secrets_engine/approval_consume.py`; its consumer contract is at `docs/approval-consumption.md`. The surface exercises the Gate House T-06 invariant without requiring a live secret, credential, approval service, or OpenBao mutation: - an exact same-digest retry is idempotent success; - a different digest produces a conflict and no OpenBao call; - missing binding, authorization failure, unavailability, and unreachable approval-engine all fail closed before OpenBao; - a failed effect does not unconsume the approval; - the evidence shape contains identifiers and digests, not secret values. Gate House initially ran the implementer's focused unit suite against the then-current working tree at revision `465c0d7` as a target-suitability check: ```text uv run --project /home/worsch/secrets-engine \ pytest -p no:cacheprovider tests/test_approval_consume.py 17 passed in 0.36s ``` This confirms that a bounded fixture surface exists. It is not an offensive probe, a known-bad calibration, or a conformance verdict. Whitehat-security later established that `approval_consume.py` first appears in committed history at `4b4d556`, not at `3cd9955` as Gate House initially inferred from the surrounding workplan history. Gate House accepts that correction. The initial test count remains a working-tree suitability check; the immutable candidate revision is `4b4d556`. ## Whitehat return Whitehat-security supplied the fixture-only probe, known-bad calibration, and contract-complete return under `conformance-reporting.v1`: - Whitehat evidence revision `75deaf0`; - return message `a1ebf012-bd1e-43d2-843c-ba3ddecb8c82`; - final Gate House review `docs/conformance/2026-09-02-whitehat-t06-fixture-return.md`. The existing implementer tests may be reused as setup evidence but must not be reported as independent Whitehat evidence. ## Authorization boundary This candidate authorizes no live probe and no production OpenBao, credential, approval, packet, or side effect. Whitehat may accept, revise, reject, or split the candidate under its own rules of engagement. Gate House specifies only the invariant, target, oracle, and report shape.