Record the audit-core E2-03 target pass and close T03/T07

Land the sanitized WH-ENG-20260822-AUDIT-E2-03 report, mark the
engagement completed and terminal, and close the applicable E2 harness
and risk-nexus delivery tasks. flex-auth stays pending; tenant-engine
stays not_applicable.

Assistant: grok
Assistant-Session: 01a02670-3345-76f2-a014-70fde8e2a2bb
This commit is contained in:
tegwick 2026-08-23 00:42:31 +02:00
parent 5fcb3ec280
commit 3295b715c5
18 changed files with 293 additions and 72 deletions

View file

@ -5,6 +5,9 @@ This directory stores sanitized run artifacts. `offline-calibration.json` and
and prove only that the harness distinguishes known-good from known-bad
behavior. They are not target assurance. `WH-ENG-20260822-AUDIT-E2-02-abort.json`
is an abort record (`evidence_class: abort`), not an E2 pass or finding.
`WH-ENG-20260822-AUDIT-E2-03.json` is the first authorized target pass; SHA-256
`2d5a21141b78024a5334881e2b7fd62a69c46931057f77515a6c6f18ec497593`. A pass
means only that the attempted attacks did not work.
Before committing target evidence, verify that it contains no response body,
credential, database URL, real tenant identifier, or real tenant value. A

View file

@ -0,0 +1,182 @@
{
"assurance_statement": "Pass means only that the attacks attempted in this run did not work; it is not proof that the tenant boundary always holds.",
"attacker_model": "E2-authenticated-tenant-a",
"attempted_operations": 10,
"authorization_id": "operator-session-2026-08-22-e2-03-approval",
"cleanup": "WP-0025 receipt-bound cleanup completed at 2026-08-22T22:13:48Z for projection sha256:c22ef5651efde1416f33936e193a3438c09a1284925b36f51fa6328519c7d02e",
"credential_revocation": "revoked by railiance-platform custody cleanup for lease custody:32c03d05b32fa6850d65eeba7bd7e2a0",
"ended_at": "2026-08-22T22:10:25.073895Z",
"engagement_id": "WH-ENG-20260822-AUDIT-E2-03",
"evidence_class": "target",
"limitations": [],
"outcome": "pass",
"posture_claim": "implemented E2; currently evidenced E1",
"probes": [
{
"observations": {
"absent": {
"content_type": "application/json",
"count": 1,
"fixture_match_count": 0,
"run_digest": "6f1b8575bc0a114ac8eee4ce04e67bf2c0a727ddd706069453bc69e208960041",
"schema": [
"$",
"$.error:str"
],
"status": 404
},
"attacker": {
"content_type": "application/json",
"count": 1,
"fixture_match_count": 0,
"run_digest": "6f1b8575bc0a114ac8eee4ce04e67bf2c0a727ddd706069453bc69e208960041",
"schema": [
"$",
"$.error:str"
],
"status": 404
},
"owner": {
"content_type": "application/json",
"count": 1,
"fixture_match_count": 2,
"run_digest": "bbed8ca6ed1e1343885ddc0945869af4f430127da9d3523f6b26ed1688f493e6",
"schema": [
"$",
"$.accepted_at:str",
"$.action:str",
"$.actor:NoneType",
"$.details",
"$.details.correlation_id:str",
"$.details.data",
"$.details.data.fixture_id:str",
"$.event_id:str",
"$.observed_at:str",
"$.outcome:str",
"$.reason:NoneType",
"$.resource:str",
"$.schema_version:str",
"$.scope:str",
"$.source:str",
"$.tenant:str"
],
"status": 200
}
},
"operation": "read",
"outcome": "pass",
"probe_id": "audit-event-by-id",
"reasons": []
},
{
"observations": {
"attacker": {
"content_type": "application/json",
"count": 1,
"fixture_match_count": 0,
"run_digest": "f023e92394bf5d3a1d8127f78eaa038afcf409159ad82637af0aeaa3bde6c276",
"schema": [
"$",
"$.events[]",
"$.events[]",
"$.events[].accepted_at:str",
"$.events[].action:str",
"$.events[].actor:NoneType",
"$.events[].details",
"$.events[].details.correlation_id:str",
"$.events[].details.data",
"$.events[].details.data.fixture_id:str",
"$.events[].event_id:str",
"$.events[].observed_at:str",
"$.events[].outcome:str",
"$.events[].reason:NoneType",
"$.events[].resource:str",
"$.events[].schema_version:str",
"$.events[].scope:str",
"$.events[].source:str",
"$.events[].tenant:str"
],
"status": 200
},
"owner": {
"content_type": "application/json",
"count": 1,
"fixture_match_count": 2,
"run_digest": "3411e7a6de77dc184926bf94ca492f7fccc3c3dfa3d1041763c35bbaa666e7eb",
"schema": [
"$",
"$.events[]",
"$.events[]",
"$.events[].accepted_at:str",
"$.events[].action:str",
"$.events[].actor:NoneType",
"$.events[].details",
"$.events[].details.correlation_id:str",
"$.events[].details.data",
"$.events[].details.data.fixture_id:str",
"$.events[].event_id:str",
"$.events[].observed_at:str",
"$.events[].outcome:str",
"$.events[].reason:NoneType",
"$.events[].resource:str",
"$.events[].schema_version:str",
"$.events[].scope:str",
"$.events[].source:str",
"$.events[].tenant:str"
],
"status": 200
}
},
"operation": "read",
"outcome": "pass",
"probe_id": "audit-correlation-slice",
"reasons": []
},
{
"observations": {
"absent": {
"content_type": "application/json",
"count": 1,
"fixture_match_count": 0,
"run_digest": "6f1b8575bc0a114ac8eee4ce04e67bf2c0a727ddd706069453bc69e208960041",
"schema": [
"$",
"$.error:str"
],
"status": 404
},
"attacker": {
"content_type": "application/json",
"count": 1,
"fixture_match_count": 0,
"run_digest": "01f07af3e3c784c765f1190d0d6607e15cfb972ff2562a3a7566237b3ef1f88e",
"schema": [
"$",
"$.error:str"
],
"status": 400
},
"state_after": {
"content_type": "application/json",
"count": 1,
"fixture_match_count": 0,
"run_digest": "6f1b8575bc0a114ac8eee4ce04e67bf2c0a727ddd706069453bc69e208960041",
"schema": [
"$",
"$.error:str"
],
"status": 404
}
},
"operation": "create",
"outcome": "pass",
"probe_id": "audit-append-as-b",
"reasons": []
}
],
"run_id": "WH-ENG-20260822-AUDIT-E2-03-2026-08-22T22:09:30.705690Z",
"schema_version": "whitehat-run/v1",
"started_at": "2026-08-22T22:09:30.705690Z",
"target": "audit-core",
"target_revision": "sha256:c2fe39a0185b99be3fc0cb14d2de69772b8e66e20490097c9d11d90cc39719a6"
}