Record the audit-core E2-03 target pass and close T03/T07
Land the sanitized WH-ENG-20260822-AUDIT-E2-03 report, mark the engagement completed and terminal, and close the applicable E2 harness and risk-nexus delivery tasks. flex-auth stays pending; tenant-engine stays not_applicable. Assistant: grok Assistant-Session: 01a02670-3345-76f2-a014-70fde8e2a2bb
This commit is contained in:
parent
5fcb3ec280
commit
3295b715c5
18 changed files with 293 additions and 72 deletions
|
|
@ -5,6 +5,9 @@ This directory stores sanitized run artifacts. `offline-calibration.json` and
|
|||
and prove only that the harness distinguishes known-good from known-bad
|
||||
behavior. They are not target assurance. `WH-ENG-20260822-AUDIT-E2-02-abort.json`
|
||||
is an abort record (`evidence_class: abort`), not an E2 pass or finding.
|
||||
`WH-ENG-20260822-AUDIT-E2-03.json` is the first authorized target pass; SHA-256
|
||||
`2d5a21141b78024a5334881e2b7fd62a69c46931057f77515a6c6f18ec497593`. A pass
|
||||
means only that the attempted attacks did not work.
|
||||
|
||||
Before committing target evidence, verify that it contains no response body,
|
||||
credential, database URL, real tenant identifier, or real tenant value. A
|
||||
|
|
|
|||
182
evidence/WH-ENG-20260822-AUDIT-E2-03.json
Normal file
182
evidence/WH-ENG-20260822-AUDIT-E2-03.json
Normal file
|
|
@ -0,0 +1,182 @@
|
|||
{
|
||||
"assurance_statement": "Pass means only that the attacks attempted in this run did not work; it is not proof that the tenant boundary always holds.",
|
||||
"attacker_model": "E2-authenticated-tenant-a",
|
||||
"attempted_operations": 10,
|
||||
"authorization_id": "operator-session-2026-08-22-e2-03-approval",
|
||||
"cleanup": "WP-0025 receipt-bound cleanup completed at 2026-08-22T22:13:48Z for projection sha256:c22ef5651efde1416f33936e193a3438c09a1284925b36f51fa6328519c7d02e",
|
||||
"credential_revocation": "revoked by railiance-platform custody cleanup for lease custody:32c03d05b32fa6850d65eeba7bd7e2a0",
|
||||
"ended_at": "2026-08-22T22:10:25.073895Z",
|
||||
"engagement_id": "WH-ENG-20260822-AUDIT-E2-03",
|
||||
"evidence_class": "target",
|
||||
"limitations": [],
|
||||
"outcome": "pass",
|
||||
"posture_claim": "implemented E2; currently evidenced E1",
|
||||
"probes": [
|
||||
{
|
||||
"observations": {
|
||||
"absent": {
|
||||
"content_type": "application/json",
|
||||
"count": 1,
|
||||
"fixture_match_count": 0,
|
||||
"run_digest": "6f1b8575bc0a114ac8eee4ce04e67bf2c0a727ddd706069453bc69e208960041",
|
||||
"schema": [
|
||||
"$",
|
||||
"$.error:str"
|
||||
],
|
||||
"status": 404
|
||||
},
|
||||
"attacker": {
|
||||
"content_type": "application/json",
|
||||
"count": 1,
|
||||
"fixture_match_count": 0,
|
||||
"run_digest": "6f1b8575bc0a114ac8eee4ce04e67bf2c0a727ddd706069453bc69e208960041",
|
||||
"schema": [
|
||||
"$",
|
||||
"$.error:str"
|
||||
],
|
||||
"status": 404
|
||||
},
|
||||
"owner": {
|
||||
"content_type": "application/json",
|
||||
"count": 1,
|
||||
"fixture_match_count": 2,
|
||||
"run_digest": "bbed8ca6ed1e1343885ddc0945869af4f430127da9d3523f6b26ed1688f493e6",
|
||||
"schema": [
|
||||
"$",
|
||||
"$.accepted_at:str",
|
||||
"$.action:str",
|
||||
"$.actor:NoneType",
|
||||
"$.details",
|
||||
"$.details.correlation_id:str",
|
||||
"$.details.data",
|
||||
"$.details.data.fixture_id:str",
|
||||
"$.event_id:str",
|
||||
"$.observed_at:str",
|
||||
"$.outcome:str",
|
||||
"$.reason:NoneType",
|
||||
"$.resource:str",
|
||||
"$.schema_version:str",
|
||||
"$.scope:str",
|
||||
"$.source:str",
|
||||
"$.tenant:str"
|
||||
],
|
||||
"status": 200
|
||||
}
|
||||
},
|
||||
"operation": "read",
|
||||
"outcome": "pass",
|
||||
"probe_id": "audit-event-by-id",
|
||||
"reasons": []
|
||||
},
|
||||
{
|
||||
"observations": {
|
||||
"attacker": {
|
||||
"content_type": "application/json",
|
||||
"count": 1,
|
||||
"fixture_match_count": 0,
|
||||
"run_digest": "f023e92394bf5d3a1d8127f78eaa038afcf409159ad82637af0aeaa3bde6c276",
|
||||
"schema": [
|
||||
"$",
|
||||
"$.events[]",
|
||||
"$.events[]",
|
||||
"$.events[].accepted_at:str",
|
||||
"$.events[].action:str",
|
||||
"$.events[].actor:NoneType",
|
||||
"$.events[].details",
|
||||
"$.events[].details.correlation_id:str",
|
||||
"$.events[].details.data",
|
||||
"$.events[].details.data.fixture_id:str",
|
||||
"$.events[].event_id:str",
|
||||
"$.events[].observed_at:str",
|
||||
"$.events[].outcome:str",
|
||||
"$.events[].reason:NoneType",
|
||||
"$.events[].resource:str",
|
||||
"$.events[].schema_version:str",
|
||||
"$.events[].scope:str",
|
||||
"$.events[].source:str",
|
||||
"$.events[].tenant:str"
|
||||
],
|
||||
"status": 200
|
||||
},
|
||||
"owner": {
|
||||
"content_type": "application/json",
|
||||
"count": 1,
|
||||
"fixture_match_count": 2,
|
||||
"run_digest": "3411e7a6de77dc184926bf94ca492f7fccc3c3dfa3d1041763c35bbaa666e7eb",
|
||||
"schema": [
|
||||
"$",
|
||||
"$.events[]",
|
||||
"$.events[]",
|
||||
"$.events[].accepted_at:str",
|
||||
"$.events[].action:str",
|
||||
"$.events[].actor:NoneType",
|
||||
"$.events[].details",
|
||||
"$.events[].details.correlation_id:str",
|
||||
"$.events[].details.data",
|
||||
"$.events[].details.data.fixture_id:str",
|
||||
"$.events[].event_id:str",
|
||||
"$.events[].observed_at:str",
|
||||
"$.events[].outcome:str",
|
||||
"$.events[].reason:NoneType",
|
||||
"$.events[].resource:str",
|
||||
"$.events[].schema_version:str",
|
||||
"$.events[].scope:str",
|
||||
"$.events[].source:str",
|
||||
"$.events[].tenant:str"
|
||||
],
|
||||
"status": 200
|
||||
}
|
||||
},
|
||||
"operation": "read",
|
||||
"outcome": "pass",
|
||||
"probe_id": "audit-correlation-slice",
|
||||
"reasons": []
|
||||
},
|
||||
{
|
||||
"observations": {
|
||||
"absent": {
|
||||
"content_type": "application/json",
|
||||
"count": 1,
|
||||
"fixture_match_count": 0,
|
||||
"run_digest": "6f1b8575bc0a114ac8eee4ce04e67bf2c0a727ddd706069453bc69e208960041",
|
||||
"schema": [
|
||||
"$",
|
||||
"$.error:str"
|
||||
],
|
||||
"status": 404
|
||||
},
|
||||
"attacker": {
|
||||
"content_type": "application/json",
|
||||
"count": 1,
|
||||
"fixture_match_count": 0,
|
||||
"run_digest": "01f07af3e3c784c765f1190d0d6607e15cfb972ff2562a3a7566237b3ef1f88e",
|
||||
"schema": [
|
||||
"$",
|
||||
"$.error:str"
|
||||
],
|
||||
"status": 400
|
||||
},
|
||||
"state_after": {
|
||||
"content_type": "application/json",
|
||||
"count": 1,
|
||||
"fixture_match_count": 0,
|
||||
"run_digest": "6f1b8575bc0a114ac8eee4ce04e67bf2c0a727ddd706069453bc69e208960041",
|
||||
"schema": [
|
||||
"$",
|
||||
"$.error:str"
|
||||
],
|
||||
"status": 404
|
||||
}
|
||||
},
|
||||
"operation": "create",
|
||||
"outcome": "pass",
|
||||
"probe_id": "audit-append-as-b",
|
||||
"reasons": []
|
||||
}
|
||||
],
|
||||
"run_id": "WH-ENG-20260822-AUDIT-E2-03-2026-08-22T22:09:30.705690Z",
|
||||
"schema_version": "whitehat-run/v1",
|
||||
"started_at": "2026-08-22T22:09:30.705690Z",
|
||||
"target": "audit-core",
|
||||
"target_revision": "sha256:c2fe39a0185b99be3fc0cb14d2de69772b8e66e20490097c9d11d90cc39719a6"
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue