Record the audit-core E2-03 target pass and close T03/T07

Land the sanitized WH-ENG-20260822-AUDIT-E2-03 report, mark the
engagement completed and terminal, and close the applicable E2 harness
and risk-nexus delivery tasks. flex-auth stays pending; tenant-engine
stays not_applicable.

Assistant: grok
Assistant-Session: 01a02670-3345-76f2-a014-70fde8e2a2bb
This commit is contained in:
tegwick 2026-08-23 00:42:31 +02:00
parent 5fcb3ec280
commit 3295b715c5
18 changed files with 293 additions and 72 deletions

View file

@ -65,15 +65,16 @@ boundary always holds.
## Current state ## Current state
- Repository status: active. - Repository status: active.
- Active plan: `WHITEHAT-WP-0001`. Meantime polish: `WHITEHAT-WP-0002` and - Active plan: `WHITEHAT-WP-0001`. Meantime polish: `WHITEHAT-WP-0002` through
`WHITEHAT-WP-0003` (Railiance WP-0025 custody adapter). `WHITEHAT-WP-0005` (Railiance WP-0025 custody adapter and fail-closed
admission).
- `T01` is complete: the rules of engagement were accepted on 2026-08-21. - `T01` is complete: the rules of engagement were accepted on 2026-08-21.
- `T02` is complete: the per-axis attacker model is recorded in - `T02` is complete: the per-axis attacker model is recorded in
`docs/attacker-model.md`. `docs/attacker-model.md`.
- `T03` is in progress: `WH-ENG-20260822-AUDIT-E2-01` expired unused; - `T03` is complete for currently applicable E2 targets: `audit-core` has
`WH-ENG-20260822-AUDIT-E2-02` aborted after projection because admission dated pass `WH-ENG-20260822-AUDIT-E2-03`; `tenant-engine` remains
had no receipt adapter. Zero packets. A later live run needs a new ID and `not_applicable`. `flex-auth` is still pending. `-01` and `-02` are
`admit-plane --receipt`. terminal without E2 evidence.
- `T04` is complete for every applicable E2 probe: generic and audit-core - `T04` is complete for every applicable E2 probe: generic and audit-core
shaped fixtures fail known-bad and pass known-good in-process. shaped fixtures fail known-bad and pass known-good in-process.
- `T05` is in progress: 24-hour cadence, offline evaluator and in-process - `T05` is in progress: 24-hour cadence, offline evaluator and in-process
@ -81,12 +82,12 @@ boundary always holds.
runtime identity. runtime identity.
- `T06` is in progress: the characterization evaluator is calibrated - `T06` is in progress: the characterization evaluator is calibrated
in-process; `shared-substrate` is pending a live window and ceiling. in-process; `shared-substrate` is pending a live window and ceiling.
- `T07` is in progress: reports can be queued to `outbox/`; the first target - `T07` is complete: the `-03` sanitized pass was delivered to `risk-nexus`
report has not been produced. as `40e3f825-fc70-4091-96d2-9ab01d42184a`.
- `T08` is the governed test plane contract. Cluster provisioning is outside - `T08` is the governed test plane contract. Cluster provisioning is outside
this repository. this repository.
- No live probe traffic is authorized; each target still requires its own - `-03` is terminal. A later live run needs a new engagement ID, plane
engagement record, plane admission and approvals. admission, and approvals. `flex-auth` and P1/P2 remain unrun.
## Relationships ## Relationships

View file

@ -48,7 +48,8 @@ Create `plane/KILL` to abort independently of the runner process.
## Retired identifiers ## Retired identifiers
`WH-ENG-20260821-AUDIT-E2`, `WH-ENG-20260821-TENANT-E2`, `WH-ENG-20260821-AUDIT-E2`, `WH-ENG-20260821-TENANT-E2`,
`WH-ENG-20260822-AUDIT-E2-01`, and `WH-ENG-20260822-AUDIT-E2-02` are terminal. `WH-ENG-20260822-AUDIT-E2-01`, `WH-ENG-20260822-AUDIT-E2-02`, and
`-02` projected and then aborted: admission had no receipt adapter, so the `WH-ENG-20260822-AUDIT-E2-03` are terminal. `-02` projected and then aborted
runner sent zero packets. A later live E2 run needs a new ID, a new window, with zero packets. `-03` completed as a bounded target pass. A later live E2
a custody receipt, and `admit-plane --receipt`. run needs a new ID, a new window, WP-0025 receipts, and `admit-plane`
`--receipt --contract --broker-receipt`.

View file

@ -1,6 +1,8 @@
{ {
"engagement_id": "WH-ENG-20260822-AUDIT-E2-03", "engagement_id": "WH-ENG-20260822-AUDIT-E2-03",
"status": "approved", "status": "completed",
"completed_at": "2026-08-22T22:16:58Z",
"completion_reason": "Target pass over 10 operations. Runner ended 22:10:25Z; receipt-bound cleanup 22:13:48Z; sanitized report delivered to risk-nexus as 40e3f825-fc70-4091-96d2-9ab01d42184a. Identifier is terminal.",
"proposal_at": "2026-08-22T21:15:00Z", "proposal_at": "2026-08-22T21:15:00Z",
"proposal_reason": "Fresh attended attempt after -02 proved exact cleanup and exposed the now-implemented WP-0025 custody receipt handoff. No terminal identifier, identity, tenant, object, or Kubernetes Secret is reused.", "proposal_reason": "Fresh attended attempt after -02 proved exact cleanup and exposed the now-implemented WP-0025 custody receipt handoff. No terminal identifier, identity, tenant, object, or Kubernetes Secret is reused.",
"authorization_id": "operator-session-2026-08-22-e2-03-approval", "authorization_id": "operator-session-2026-08-22-e2-03-approval",

View file

@ -1,14 +1,12 @@
# WH-ENG-20260822-AUDIT-E2-03 # WH-ENG-20260822-AUDIT-E2-03
Status: **approved** for `2026-08-22T22:00:00Z``22:15:00Z`. Status: **completed**. Identifier is terminal.
This is a fresh, terminal-unique attempt. It does not reuse the `-01` or `-02` Attended window `2026-08-22T22:00:00Z``22:15:00Z`. Projection at `22:01:35Z`,
identifier, senders, tenants, objects, mounted Secret, or runner pod. The runner `22:09:30Z``22:10:25Z` (10 operations, three probes passed), cleanup
projection gate closes at `22:03:00Z`; all custody resources expire and must be `22:13:48Z`, report to risk-nexus `22:16:58Z` (`40e3f825-fc70-4091-96d2-9ab01d42184a`).
cleaned by `22:15:00Z`. The repository operator approved the exact package at Sanitized evidence: `evidence/WH-ENG-20260822-AUDIT-E2-03.json`.
`21:29:21Z`; audit-core acknowledged it after approval at `21:29:22Z`.
The run uses the canonical RAILIANCE-WP-0025 projection contract, Whitehat A pass means only that the attempted attacks did not work. It is not proof that
broker-readiness receipt, projection receipt, contract-bound `admit-plane`, the tenant boundary always holds. Do not reuse this identifier, its senders,
cleanup receipt, and finalized report. Projection remains forbidden before tenants, objects, Secret, or runner pod.
`22:00:00Z` and after `22:03:00Z`.

View file

@ -16,6 +16,7 @@ manifest under `runtime/` is bound to a cancelled ID and must not be applied.
`WH-ENG-20260822-AUDIT-E2-01` expired unused. `WH-ENG-20260822-AUDIT-E2-02` `WH-ENG-20260822-AUDIT-E2-01` expired unused. `WH-ENG-20260822-AUDIT-E2-02`
aborted after projection because `admit-plane` had no receipt adapter; zero aborted after projection because `admit-plane` had no receipt adapter; zero
packets. Neither identifier may be reused. Live admission requires packets. `WH-ENG-20260822-AUDIT-E2-03` completed as a bounded target pass.
`--receipt` of a value-safe custody projection. Those identifiers may not be reused. Live admission requires `--receipt`,
`--contract`, and `--broker-receipt` of WP-0025 documents.

View file

@ -1,8 +1,8 @@
# WH-ENG-20260822-AUDIT-E2-03 — attended invocation # WH-ENG-20260822-AUDIT-E2-03 — attended invocation
This package is proposed for `22:00Z``22:15Z`; projection closes at `22:03Z`. This engagement **completed** at `2026-08-22T22:16:58Z`. Do not apply the
Do nothing live until the engagement and the exact WP-0025 contract are runner, project credentials, or reuse this identifier. The record below is
approved and audit-core has acknowledged them. the attended sequence that was used.
Runtime value-safe artifacts are written beneath Runtime value-safe artifacts are written beneath
`/tmp/WH-ENG-20260822-AUDIT-E2-03/`: `/tmp/WH-ENG-20260822-AUDIT-E2-03/`:

View file

@ -5,6 +5,9 @@ This directory stores sanitized run artifacts. `offline-calibration.json` and
and prove only that the harness distinguishes known-good from known-bad and prove only that the harness distinguishes known-good from known-bad
behavior. They are not target assurance. `WH-ENG-20260822-AUDIT-E2-02-abort.json` behavior. They are not target assurance. `WH-ENG-20260822-AUDIT-E2-02-abort.json`
is an abort record (`evidence_class: abort`), not an E2 pass or finding. is an abort record (`evidence_class: abort`), not an E2 pass or finding.
`WH-ENG-20260822-AUDIT-E2-03.json` is the first authorized target pass; SHA-256
`2d5a21141b78024a5334881e2b7fd62a69c46931057f77515a6c6f18ec497593`. A pass
means only that the attempted attacks did not work.
Before committing target evidence, verify that it contains no response body, Before committing target evidence, verify that it contains no response body,
credential, database URL, real tenant identifier, or real tenant value. A credential, database URL, real tenant identifier, or real tenant value. A

View file

@ -0,0 +1,182 @@
{
"assurance_statement": "Pass means only that the attacks attempted in this run did not work; it is not proof that the tenant boundary always holds.",
"attacker_model": "E2-authenticated-tenant-a",
"attempted_operations": 10,
"authorization_id": "operator-session-2026-08-22-e2-03-approval",
"cleanup": "WP-0025 receipt-bound cleanup completed at 2026-08-22T22:13:48Z for projection sha256:c22ef5651efde1416f33936e193a3438c09a1284925b36f51fa6328519c7d02e",
"credential_revocation": "revoked by railiance-platform custody cleanup for lease custody:32c03d05b32fa6850d65eeba7bd7e2a0",
"ended_at": "2026-08-22T22:10:25.073895Z",
"engagement_id": "WH-ENG-20260822-AUDIT-E2-03",
"evidence_class": "target",
"limitations": [],
"outcome": "pass",
"posture_claim": "implemented E2; currently evidenced E1",
"probes": [
{
"observations": {
"absent": {
"content_type": "application/json",
"count": 1,
"fixture_match_count": 0,
"run_digest": "6f1b8575bc0a114ac8eee4ce04e67bf2c0a727ddd706069453bc69e208960041",
"schema": [
"$",
"$.error:str"
],
"status": 404
},
"attacker": {
"content_type": "application/json",
"count": 1,
"fixture_match_count": 0,
"run_digest": "6f1b8575bc0a114ac8eee4ce04e67bf2c0a727ddd706069453bc69e208960041",
"schema": [
"$",
"$.error:str"
],
"status": 404
},
"owner": {
"content_type": "application/json",
"count": 1,
"fixture_match_count": 2,
"run_digest": "bbed8ca6ed1e1343885ddc0945869af4f430127da9d3523f6b26ed1688f493e6",
"schema": [
"$",
"$.accepted_at:str",
"$.action:str",
"$.actor:NoneType",
"$.details",
"$.details.correlation_id:str",
"$.details.data",
"$.details.data.fixture_id:str",
"$.event_id:str",
"$.observed_at:str",
"$.outcome:str",
"$.reason:NoneType",
"$.resource:str",
"$.schema_version:str",
"$.scope:str",
"$.source:str",
"$.tenant:str"
],
"status": 200
}
},
"operation": "read",
"outcome": "pass",
"probe_id": "audit-event-by-id",
"reasons": []
},
{
"observations": {
"attacker": {
"content_type": "application/json",
"count": 1,
"fixture_match_count": 0,
"run_digest": "f023e92394bf5d3a1d8127f78eaa038afcf409159ad82637af0aeaa3bde6c276",
"schema": [
"$",
"$.events[]",
"$.events[]",
"$.events[].accepted_at:str",
"$.events[].action:str",
"$.events[].actor:NoneType",
"$.events[].details",
"$.events[].details.correlation_id:str",
"$.events[].details.data",
"$.events[].details.data.fixture_id:str",
"$.events[].event_id:str",
"$.events[].observed_at:str",
"$.events[].outcome:str",
"$.events[].reason:NoneType",
"$.events[].resource:str",
"$.events[].schema_version:str",
"$.events[].scope:str",
"$.events[].source:str",
"$.events[].tenant:str"
],
"status": 200
},
"owner": {
"content_type": "application/json",
"count": 1,
"fixture_match_count": 2,
"run_digest": "3411e7a6de77dc184926bf94ca492f7fccc3c3dfa3d1041763c35bbaa666e7eb",
"schema": [
"$",
"$.events[]",
"$.events[]",
"$.events[].accepted_at:str",
"$.events[].action:str",
"$.events[].actor:NoneType",
"$.events[].details",
"$.events[].details.correlation_id:str",
"$.events[].details.data",
"$.events[].details.data.fixture_id:str",
"$.events[].event_id:str",
"$.events[].observed_at:str",
"$.events[].outcome:str",
"$.events[].reason:NoneType",
"$.events[].resource:str",
"$.events[].schema_version:str",
"$.events[].scope:str",
"$.events[].source:str",
"$.events[].tenant:str"
],
"status": 200
}
},
"operation": "read",
"outcome": "pass",
"probe_id": "audit-correlation-slice",
"reasons": []
},
{
"observations": {
"absent": {
"content_type": "application/json",
"count": 1,
"fixture_match_count": 0,
"run_digest": "6f1b8575bc0a114ac8eee4ce04e67bf2c0a727ddd706069453bc69e208960041",
"schema": [
"$",
"$.error:str"
],
"status": 404
},
"attacker": {
"content_type": "application/json",
"count": 1,
"fixture_match_count": 0,
"run_digest": "01f07af3e3c784c765f1190d0d6607e15cfb972ff2562a3a7566237b3ef1f88e",
"schema": [
"$",
"$.error:str"
],
"status": 400
},
"state_after": {
"content_type": "application/json",
"count": 1,
"fixture_match_count": 0,
"run_digest": "6f1b8575bc0a114ac8eee4ce04e67bf2c0a727ddd706069453bc69e208960041",
"schema": [
"$",
"$.error:str"
],
"status": 404
}
},
"operation": "create",
"outcome": "pass",
"probe_id": "audit-append-as-b",
"reasons": []
}
],
"run_id": "WH-ENG-20260822-AUDIT-E2-03-2026-08-22T22:09:30.705690Z",
"schema_version": "whitehat-run/v1",
"started_at": "2026-08-22T22:09:30.705690Z",
"target": "audit-core",
"target_revision": "sha256:c2fe39a0185b99be3fc0cb14d2de69772b8e66e20490097c9d11d90cc39719a6"
}

View file

@ -4,7 +4,8 @@ This repository does not apply cluster objects, request credentials, or send
packets. `ops-mason` provisions the foundational plane from these files packets. `ops-mason` provisions the foundational plane from these files
**before** a fresh engagement is proposed. Cancelled or expired IDs **before** a fresh engagement is proposed. Cancelled or expired IDs
`WH-ENG-20260821-AUDIT-E2`, `WH-ENG-20260821-TENANT-E2`, `WH-ENG-20260821-AUDIT-E2`, `WH-ENG-20260821-TENANT-E2`,
`WH-ENG-20260822-AUDIT-E2-01`, and `WH-ENG-20260822-AUDIT-E2-02` are terminal. `WH-ENG-20260822-AUDIT-E2-01`, `WH-ENG-20260822-AUDIT-E2-02`, and
`WH-ENG-20260822-AUDIT-E2-03` are terminal.
## Ordering ## Ordering

View file

@ -47,6 +47,10 @@ class Engagement:
raise AuthorizationError( raise AuthorizationError(
"engagement aborted without target evidence; identifier must not be reused" "engagement aborted without target evidence; identifier must not be reused"
) )
if self.raw.get("status") == "completed":
raise AuthorizationError(
"engagement completed; identifier must not be reused"
)
if self.raw.get("status") == "proposed": if self.raw.get("status") == "proposed":
raise AuthorizationError( raise AuthorizationError(
"engagement is proposed; operator approval and owner acknowledgement are pending" "engagement is proposed; operator approval and owner acknowledgement are pending"

View file

@ -17,6 +17,7 @@ TERMINAL_IDS = frozenset({
"WH-ENG-20260821-TENANT-E2", "WH-ENG-20260821-TENANT-E2",
"WH-ENG-20260822-AUDIT-E2-01", "WH-ENG-20260822-AUDIT-E2-01",
"WH-ENG-20260822-AUDIT-E2-02", "WH-ENG-20260822-AUDIT-E2-02",
"WH-ENG-20260822-AUDIT-E2-03",
}) })
APPROVAL_CLASSES = { APPROVAL_CLASSES = {
"fixture-e2": frozenset({"e2-differential"}), "fixture-e2": frozenset({"e2-differential"}),
@ -43,7 +44,7 @@ def retired_ids(engagements_dir: str | Path | None = None) -> set[str]:
data = json.loads(path.read_text(encoding="utf-8")) data = json.loads(path.read_text(encoding="utf-8"))
except (OSError, json.JSONDecodeError, ValueError): except (OSError, json.JSONDecodeError, ValueError):
continue continue
if data.get("status") in {"cancelled", "expired", "aborted"} and data.get("engagement_id"): if data.get("status") in {"cancelled", "expired", "aborted", "completed"} and data.get("engagement_id"):
retired.add(data["engagement_id"]) retired.add(data["engagement_id"])
return retired return retired

View file

@ -6,7 +6,7 @@ honest applicability record the test plane admits against.
| `target_id` | Applicability | Meaning | | `target_id` | Applicability | Meaning |
| --- | --- | --- | | --- | --- | --- |
| `fixture-e2` | applicable | In-process known-good/known-bad harness. Offline only. | | `fixture-e2` | applicable | In-process known-good/known-bad harness. Offline only. |
| `audit-core` | applicable | Two ordinary tenant-scoped senders instantiate E2. Live run still needs a new engagement and plane lease. | | `audit-core` | applicable | Two ordinary tenant-scoped senders instantiate E2. Dated pass `WH-ENG-20260822-AUDIT-E2-03`; that ID is terminal. |
| `tenant-engine` | not_applicable | No tenant-A identity without tenant-B authority. | | `tenant-engine` | not_applicable | No tenant-A identity without tenant-B authority. |
| `flex-auth` | pending | Initial envelope; owner has not confirmed the attacker identity. | | `flex-auth` | pending | Initial envelope; owner has not confirmed the attacker identity. |
| `fixture-e3` | applicable | In-process E3 evaluator. One runtime identity, no `BYPASSRLS`. | | `fixture-e3` | applicable | In-process E3 evaluator. One runtime identity, no `BYPASSRLS`. |

View file

@ -1,7 +1,7 @@
{ {
"schema_version": "whitehat-target/v1", "schema_version": "whitehat-target/v1",
"target_id": "audit-core", "target_id": "audit-core",
"posture_claim": "implemented E2; currently evidenced E1", "posture_claim": "implemented E2; dated target pass WH-ENG-20260822-AUDIT-E2-03 at 2026-08-22T22:10:25Z; review due 2026-08-23T22:10:25Z",
"attacker_model": "E2-authenticated-tenant-a", "attacker_model": "E2-authenticated-tenant-a",
"applicability": "applicable", "applicability": "applicable",
"applicability_reason": "audit-core binds each sender token to a tenant set at one choke point. Two ordinary tenant-scoped senders instantiate the E2 model without operator or database privilege.", "applicability_reason": "audit-core binds each sender token to a tenant set at one choke point. Two ordinary tenant-scoped senders instantiate the E2 model without operator or database privilege.",

View file

@ -125,3 +125,4 @@ def test_third_attempt_fixtures_are_new_and_complete():
assert fixtures <= set(engagement["fixture_ids"]) assert fixtures <= set(engagement["fixture_ids"])
assert fixtures.isdisjoint(previous["fixture_ids"]) assert fixtures.isdisjoint(previous["fixture_ids"])
assert engagement["engagement_id"] != previous["engagement_id"] assert engagement["engagement_id"] != previous["engagement_id"]
assert engagement["status"] == "completed"

View file

@ -216,6 +216,34 @@ def test_admit_plane_wp0025_mismatched_broker_receipt(tmp_path, capsys):
assert "broker digest" in capsys.readouterr().err assert "broker digest" in capsys.readouterr().err
def test_deliver_queues_target_pass_without_severity(tmp_path, capsys):
report = json.loads(
Path("evidence/WH-ENG-20260822-AUDIT-E2-03.json").read_text(encoding="utf-8")
)
assert report["outcome"] == "pass"
assert report["evidence_class"] == "target"
main(["deliver", "evidence/WH-ENG-20260822-AUDIT-E2-03.json",
"--outbox", str(tmp_path / "outbox")])
queued = (tmp_path / "outbox" / f"{report['run_id']}.md").read_text(encoding="utf-8")
assert capsys.readouterr().out.startswith("queued:")
assert "pass" in queued
assert "Severity" not in queued
assert report["engagement_id"] in queued
def test_admit_plane_refuses_completed_engagement(capsys):
with pytest.raises(SystemExit) as stopped:
main([
"admit-plane",
"engagements/2026-08-22-audit-core-e2-03.json",
"targets/audit-core-e2.json",
])
assert stopped.value.code == 2
err = capsys.readouterr().err
assert "not authorized:" in err
assert "completed" in err
def test_deliver_queues_abort_without_calling_it_target_assurance(tmp_path, capsys): def test_deliver_queues_abort_without_calling_it_target_assurance(tmp_path, capsys):
report = json.loads( report = json.loads(
Path("evidence/WH-ENG-20260822-AUDIT-E2-02-abort.json").read_text(encoding="utf-8") Path("evidence/WH-ENG-20260822-AUDIT-E2-02-abort.json").read_text(encoding="utf-8")

View file

@ -87,6 +87,14 @@ def test_aborted_record_fails_closed():
) )
def test_completed_record_fails_closed():
with pytest.raises(AuthorizationError, match="completed"):
Engagement.load(
"engagements/2026-08-22-audit-core-e2-03.json",
now=datetime(2026, 8, 22, 22, 10, tzinfo=UTC),
)
def test_elapsed_record_fails_closed_even_inside_old_window(tmp_path): def test_elapsed_record_fails_closed_even_inside_old_window(tmp_path):
data = record() data = record()
data["status"] = "expired" data["status"] = "expired"

View file

@ -72,6 +72,7 @@ def test_retired_ids_include_cancelled_records():
assert "WH-ENG-20260821-TENANT-E2" in ids assert "WH-ENG-20260821-TENANT-E2" in ids
assert "WH-ENG-20260822-AUDIT-E2-01" in ids assert "WH-ENG-20260822-AUDIT-E2-01" in ids
assert "WH-ENG-20260822-AUDIT-E2-02" in ids assert "WH-ENG-20260822-AUDIT-E2-02" in ids
assert "WH-ENG-20260822-AUDIT-E2-03" in ids
def test_fixture_plane_admits_and_projects_handles_without_secrets(tmp_path): def test_fixture_plane_admits_and_projects_handles_without_secrets(tmp_path):

View file

@ -8,7 +8,7 @@ status: active
owner: net-kingdom owner: net-kingdom
topic_slug: whitehat-security topic_slug: whitehat-security
created: "2026-08-17" created: "2026-08-17"
updated: "2026-08-22" updated: "2026-08-23"
state_hub_workstream_id: "ecc16edc-9f9b-4fc4-8fb1-96b947a59299" state_hub_workstream_id: "ecc16edc-9f9b-4fc4-8fb1-96b947a59299"
--- ---
@ -127,7 +127,7 @@ failure.
```task ```task
id: WHITEHAT-WP-0001-T03 id: WHITEHAT-WP-0001-T03
status: progress status: done
priority: high priority: high
state_hub_task_id: "742561f1-97b6-4fcc-8e06-d18508ddecae" state_hub_task_id: "742561f1-97b6-4fcc-8e06-d18508ddecae"
``` ```
@ -146,28 +146,17 @@ The core technique: run the same request as two tenants and compare.
**Acceptance:** a dated run record against every *applicable* E2 target. The **Acceptance:** a dated run record against every *applicable* E2 target. The
artifact is the run record, not a green tick. `tenant-engine` is registered artifact is the run record, not a green tick. `tenant-engine` is registered
`not_applicable` for E2; that record is the artifact for that target. `not_applicable` for E2; that record is the artifact for that target.
`audit-core` remains the live E2 target and still needs a new admitted `flex-auth` remains `pending` and is not an applicable E2 target.
engagement.
Implementation progress, 2026-08-22: `src/whitehat_security/differential.py` Done 2026-08-22: `WH-ENG-20260822-AUDIT-E2-03` is a dated target pass against
performs owner/attacker/absent comparisons, detects fixture disclosure and the only applicable live E2 target, `audit-core`. Ten operations, three
write-side state change, and persists only sanitized observations. Live entry calibrated probes, cleanup before expiry, sanitized report in
is `execute_authorized`, which requires a plane lease. Concrete route `evidence/WH-ENG-20260822-AUDIT-E2-03.json`. `tenant-engine` stays
inventories live in `probe-packs/`. Target honesty lives in `targets/`: `not_applicable`; that record is the artifact, not a deferral. `-01` expired
`audit-core` is applicable; `tenant-engine` is `not_applicable` (that is the unused and `-02` aborted with zero packets; those identifiers remain terminal.
artifact, not a deferral); `flex-auth` is pending. Whitehat will not relabel pending or not-applicable targets to finish this
task. A later audit-core run needs a new engagement ID; this pass is due for
The 2026-08-21 production engagement IDs were cancelled without sending a review or replacement at 2026-08-23T22:10:25Z.
target request and are retired. ops-mason applied the foundational plane on
2026-08-22. The operator approved `WH-ENG-20260822-AUDIT-E2-01` at
2026-08-22T09:52:55Z; audit-core acknowledged at 2026-08-22T10:04:56Z
(`32afceb`) after the fixture/digest correction `1418dac`. Offline preflight
recorded a window that elapsed at 18:15Z with no projection-ready notice and
zero packets. `WH-ENG-20260822-AUDIT-E2-02` projected at 19:17:54Z and the
runner became Ready, then `admit-plane` failed closed because no receipt
adapter existed; zero packets, cleanup complete 19:21:39Z. Both identifiers
are terminal. Live admission now consumes a value-safe custody receipt.
Whitehat will not relabel tenant-engine to finish this task.
### T04 — Prove the probes fail ### T04 — Prove the probes fail
@ -263,7 +252,7 @@ window and aggressor ceiling do not yet exist.
```task ```task
id: WHITEHAT-WP-0001-T07 id: WHITEHAT-WP-0001-T07
status: progress status: done
priority: medium priority: medium
state_hub_task_id: "54f33288-5361-4b20-8e1f-168866d64644" state_hub_task_id: "54f33288-5361-4b20-8e1f-168866d64644"
``` ```
@ -276,12 +265,13 @@ A **passing** run is also reported. "The attacks we thought of did not work" is
the honest claim, and recording it dated is what lets anyone see how stale the the honest claim, and recording it dated is what lets anyone see how stale the
assurance has become. assurance has become.
Implementation progress, 2026-08-22: `schemas/run-report.schema.json` defines Done 2026-08-22: `schemas/run-report.schema.json` defines the minimized
the minimized evidence contract, `whitehat risk-message` renders both pass evidence contract, `whitehat risk-message` renders pass and finding
and finding deliveries without severity, and `whitehat deliver` queues a deliveries without severity, and `whitehat deliver` queues target reports.
target report to `outbox/`. Fixture calibration is refused as target The first authorized target report is
assurance. Completion awaits the first authorized target report being `evidence/WH-ENG-20260822-AUDIT-E2-03.json`, delivered to `risk-nexus` as
delivered to `risk-nexus`. State Hub message `40e3f825-fc70-4091-96d2-9ab01d42184a`. Fixture calibration
remains refused as target assurance.
### T08 — Governed test plane ### T08 — Governed test plane
@ -319,15 +309,14 @@ gates live T03. T07 can follow T03.
## Session cutoff — 2026-08-22 ## Session cutoff — 2026-08-22
The coordinating session ended with the workplan deliberately **active**. T01, The coordinating session ended with the workplan deliberately **active**. T01,
T02, T04 and T08 are done. T03, T05, T06 and T07 remain in progress. The two T02, T03, T04, T07 and T08 are done. T05 and T06 remain in progress.
dated production engagement records were cancelled without sending any target `WH-ENG-20260822-AUDIT-E2-01` expired unused, `-02` aborted with zero packets,
request; cancelled engagement IDs are terminal and must never be reused. and `-03` completed as a bounded target pass. Those identifiers are terminal
and must never be reused. `flex-auth` is still pending; `platform-pg` E3 is
`not_applicable`; no P1/P2 live window exists.
The offline instrument is implemented, calibrated, and plane-gated. The The exact earlier cutoff scope is recorded in
estate still has to provision the cluster plane and a value-safe credential `docs/session-cutoff-2026-08-22.md` and `docs/test-plane.md`.
broker before any live evidence exists. Resume only with new engagement IDs.
The exact completed scope is recorded in `docs/session-cutoff-2026-08-22.md`
and `docs/test-plane.md`.
## Risks ## Risks