Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a05e30-2884-71b0-98d7-7edd16ae737b
74 lines
2.8 KiB
Markdown
74 lines
2.8 KiB
Markdown
# Conformance review — Whitehat ASM fixture calibrations
|
|
|
|
**Repository:** gate-house
|
|
**Status:** fixture harness calibrated; live targets pending
|
|
**Date:** 2026-09-02
|
|
**Executor:** whitehat-security
|
|
**Executor revision:** `6f1ca0b`
|
|
**Source:** State Hub message `32926191-4ca1-46ad-8eec-0d499036d66b`
|
|
**Specification:** `asm-assurance-targets.v1`
|
|
**Evidence class:** `fixture`
|
|
**Gate House disposition:** `no_change`
|
|
**Workplan:** GH-WP-0001-T06
|
|
|
|
## Returned calibration
|
|
|
|
Whitehat-security created in-process registrations and evidence for Canon T-01
|
|
through T-10:
|
|
|
|
```text
|
|
targets/fixture-asm-tNN.json
|
|
evidence/offline-asm-tNN-calibration.json
|
|
```
|
|
|
|
For every test, the Whitehat-owned known-bad fixture loses the specified oracle
|
|
and records a `finding`; the corresponding known-good fixture records `pass`.
|
|
T-08 and T-09 each calibrate two distinct failure shapes. T-06 drives the
|
|
committed secrets-engine consume client at revision `4b4d556` through an
|
|
in-process CAS opener; the other fixtures are Whitehat-owned in-process models
|
|
of their target invariant.
|
|
|
|
Gate House reproduced the focused suite against Whitehat revision `6f1ca0b`:
|
|
|
|
```text
|
|
uv run --project /home/worsch/whitehat-security \
|
|
pytest -p no:cacheprovider tests/test_asm.py tests/test_plane.py tests/test_cli.py
|
|
53 passed in 0.34s
|
|
```
|
|
|
|
This establishes that each published target has a probe capable of detecting a
|
|
known-bad case. It closes the risk that a probe could report green merely
|
|
because it cannot observe its own oracle.
|
|
|
|
## Evidence bound
|
|
|
|
This is harness calibration, not assurance of ten estate systems:
|
|
|
|
- evidence class is `fixture`;
|
|
- no network, live service, OpenBao instance, credential, packet, or production
|
|
effect was used;
|
|
- no live `asm-tNN` registration became applicable;
|
|
- no component other than the bounded T-06 consume client was exercised;
|
|
- a fixture `pass` means the probe distinguished its known-good model from its
|
|
known-bad model, not that the corresponding estate control currently holds.
|
|
|
|
All live T-01 through T-10 targets remain `pending` / `not_run` until an owner
|
|
names the surface, identities, and window and Whitehat admits a dated
|
|
engagement. `WHITEHAT-WP-0007-T11` preserves that residual.
|
|
|
|
## Doctrine disposition
|
|
|
|
`no_change` to `asm-assurance-targets.v1`.
|
|
|
|
The returned fixture set implements Whitehat-owned attack designs while
|
|
preserving Gate House's invariant and oracle identifiers. No calibration
|
|
exposed an ambiguous, contradictory, or untestable Gate House target. This
|
|
disposition accepts the harness/specification fit only; it does not convert
|
|
fixture outcomes into live conformance.
|
|
|
|
## Reporting closure
|
|
|
|
Whitehat supplied the complete T-06 envelope, including engagement and
|
|
authorization references, in message
|
|
`a1ebf012-bd1e-43d2-843c-ba3ddecb8c82`. Final review:
|
|
`docs/conformance/2026-09-02-whitehat-t06-fixture-return.md`.
|