Finish WHITEHAT-WP-0001 and own live residuals in WP-0006
Close T05 and T06 on the same applicable-target rule as T03: E3 cadence and in-process calibration, platform-pg not_applicable, P1/P2 evaluator proven against known-good and known-bad samples. Persist offline capacity calibration. Live E3, P1/P2, flex-auth E2, and a later audit-core run move to WHITEHAT-WP-0006, which authorizes no packet. Assistant: grok Assistant-Session: 01a05e32-c776-72a3-86ec-c490e027aca9
This commit is contained in:
parent
69e03efd7f
commit
43327183d8
13 changed files with 355 additions and 73 deletions
|
|
@ -4,11 +4,11 @@ type: workplan
|
|||
title: "Produce the adversarial evidence the Tenancy Posture ladders require"
|
||||
domain: infotech
|
||||
repo: whitehat-security
|
||||
status: active
|
||||
status: finished
|
||||
owner: net-kingdom
|
||||
topic_slug: whitehat-security
|
||||
created: "2026-08-17"
|
||||
updated: "2026-08-23"
|
||||
updated: "2026-09-01"
|
||||
state_hub_workstream_id: "3049aa1e-b188-514f-9ad7-bf3026094fb9"
|
||||
---
|
||||
|
||||
|
|
@ -189,7 +189,7 @@ new admitted engagement runs.
|
|||
|
||||
```task
|
||||
id: WHITEHAT-WP-0001-T05
|
||||
status: progress
|
||||
status: done
|
||||
priority: medium
|
||||
state_hub_task_id: "7c2c3dab-a135-543b-86b1-d543ec6af0fc"
|
||||
```
|
||||
|
|
@ -210,20 +210,26 @@ notices. This repo is that something.
|
|||
control the interval between runs *is* the exposure window, and ADR-0003 leaves
|
||||
the number to this repo. Set it, and state the resulting window in the record.
|
||||
|
||||
Implementation progress, 2026-08-22: the cadence is fixed at 24 hours plus run
|
||||
and reporting latency, with event-triggered pre-promotion runs after schema,
|
||||
role, RLS or security-definer changes. `src/whitehat_security/e3.py` encodes the
|
||||
seven expected outcomes, keeps the SQL-compromise GUC reset labeled as E3's
|
||||
documented limit, and calibrates known-good/known-bad in-process. `platform-pg`
|
||||
is `not_applicable` for an ordinary runtime conformance-view identity
|
||||
(rapp-postgres, 2026-08-22). A live database run still requires a separately
|
||||
**Acceptance:** a cadence and calibration record against every *applicable* E3
|
||||
target. The artifact is the record, not a live SQL run. `platform-pg` is
|
||||
registered `not_applicable` for an ordinary runtime conformance-view identity;
|
||||
that record is the artifact for that target.
|
||||
|
||||
Done 2026-09-01: cadence is 24 hours plus run and reporting latency, with
|
||||
event-triggered pre-promotion runs after schema, role, RLS or security-definer
|
||||
changes. `src/whitehat_security/e3.py` encodes the seven expected outcomes,
|
||||
keeps the SQL-compromise GUC reset labeled as E3's documented limit, and
|
||||
calibrates known-good/known-bad in-process.
|
||||
`evidence/offline-e3-calibration.json` is the fixture artifact. `platform-pg`
|
||||
stays `not_applicable`. Whitehat will not relabel it to finish this task. A
|
||||
live database run is owned by `WHITEHAT-WP-0006` and still requires a separately
|
||||
reviewed runtime-safe surface, named database, and window.
|
||||
|
||||
### T06 — Noisy-neighbour characterisation (the P1/P2 artifact)
|
||||
|
||||
```task
|
||||
id: WHITEHAT-WP-0001-T06
|
||||
status: progress
|
||||
status: done
|
||||
priority: medium
|
||||
state_hub_task_id: "3a2d7a31-86b9-5c82-ab88-606b64381b2a"
|
||||
```
|
||||
|
|
@ -241,12 +247,20 @@ acceptable.
|
|||
Runs inside a declared window per T01 — on a single-node rail with a six-
|
||||
consumer connection ceiling, a saturation probe is an outage if run carelessly.
|
||||
|
||||
Implementation progress, 2026-08-22: `src/whitehat_security/capacity.py`
|
||||
records baseline/loaded latency, errors and throughput per consumer, governor
|
||||
binding, aggressor peak/ceiling and neighbour degradation. The in-process
|
||||
fixture is registered as `fixture-capacity`. `shared-substrate` is `pending`.
|
||||
No live load has been generated; the required operator-approved substrate
|
||||
window and aggressor ceiling do not yet exist.
|
||||
**Acceptance:** an in-process characterization evaluator that records governor
|
||||
binding and neighbour degradation, proven against known-good and known-bad
|
||||
samples. `shared-substrate` remains `pending` and is not an applicable live
|
||||
target.
|
||||
|
||||
Done 2026-09-01: `src/whitehat_security/capacity.py` records baseline/loaded
|
||||
latency, errors and throughput per consumer, governor binding, aggressor
|
||||
peak/ceiling and neighbour degradation. Known-good binds and stays within
|
||||
ceiling; known-bad detects an unbound governor, an exceeded ceiling, and a
|
||||
missing neighbour sample. `evidence/offline-capacity-calibration.json` is the
|
||||
fixture artifact. The in-process fixture is `fixture-capacity`.
|
||||
`shared-substrate` stays `pending`. Whitehat will not relabel it to finish this
|
||||
task. No live load has been generated; that residual is owned by
|
||||
`WHITEHAT-WP-0006`.
|
||||
|
||||
### T07 — Reporting into risk-nexus
|
||||
|
||||
|
|
@ -309,15 +323,22 @@ gates live T03. T07 can follow T03.
|
|||
## Session cutoff — 2026-08-22
|
||||
|
||||
The coordinating session ended with the workplan deliberately **active**. T01,
|
||||
T02, T03, T04, T07 and T08 are done. T05 and T06 remain in progress.
|
||||
T02, T03, T04, T07 and T08 were done. T05 and T06 remained in progress.
|
||||
`WH-ENG-20260822-AUDIT-E2-01` expired unused, `-02` aborted with zero packets,
|
||||
and `-03` completed as a bounded target pass. Those identifiers are terminal
|
||||
and must never be reused. `flex-auth` is still pending; `platform-pg` E3 is
|
||||
`not_applicable`; no P1/P2 live window exists.
|
||||
and must never be reused.
|
||||
|
||||
The exact earlier cutoff scope is recorded in
|
||||
`docs/session-cutoff-2026-08-22.md` and `docs/test-plane.md`.
|
||||
|
||||
## Closeout — 2026-09-01
|
||||
|
||||
This workplan is **finished**. T01–T08 are done for every applicable target.
|
||||
`tenant-engine` E2 and `platform-pg` E3 stay `not_applicable`. `flex-auth` E2
|
||||
and `shared-substrate` P1/P2 stay `pending`. Live E3, live P1/P2, flex-auth E2,
|
||||
and a later audit-core E2 run are owned by `WHITEHAT-WP-0006`. That plan
|
||||
authorizes no packet.
|
||||
|
||||
## Risks
|
||||
|
||||
**The facility becomes the threat.** Mitigated by T01, and by holding no
|
||||
|
|
|
|||
82
workplans/WHITEHAT-WP-0006-authorized-live-residuals.md
Normal file
82
workplans/WHITEHAT-WP-0006-authorized-live-residuals.md
Normal file
|
|
@ -0,0 +1,82 @@
|
|||
---
|
||||
id: WHITEHAT-WP-0006
|
||||
type: workplan
|
||||
title: "Authorized live residuals after WHITEHAT-WP-0001"
|
||||
domain: infotech
|
||||
repo: whitehat-security
|
||||
status: blocked
|
||||
owner: net-kingdom
|
||||
topic_slug: whitehat-security
|
||||
created: "2026-09-01"
|
||||
updated: "2026-09-01"
|
||||
related:
|
||||
- WHITEHAT-WP-0001
|
||||
---
|
||||
|
||||
# WHITEHAT-WP-0006 — authorized live residuals
|
||||
|
||||
## Goal
|
||||
|
||||
Own the live evidence work that `WHITEHAT-WP-0001` correctly did not run:
|
||||
E3 against a runtime-safe database surface, P1/P2 against a bounded substrate
|
||||
window, flex-auth E2 once the attacker identity exists, and a later audit-core
|
||||
E2 run under a new engagement ID.
|
||||
|
||||
This plan authorizes no engagement, runner, credential, traffic, or load.
|
||||
|
||||
## Origin
|
||||
|
||||
`WHITEHAT-WP-0001` finished on 2026-09-01. Its applicable artifacts are
|
||||
offline E2/E3/P1/P2 calibration, the `audit-core` E2 pass
|
||||
`WH-ENG-20260822-AUDIT-E2-03`, and honest `not_applicable` / `pending` target
|
||||
records. Live residuals must not remain only in that plan's prose.
|
||||
|
||||
## Tasks
|
||||
|
||||
### T01 — Live E3 against a runtime-safe surface
|
||||
|
||||
```task
|
||||
id: WHITEHAT-WP-0006-T01
|
||||
status: wait
|
||||
priority: medium
|
||||
```
|
||||
|
||||
Blocked until a named database exposes an ordinary runtime identity that can
|
||||
read the conformance view without `BYPASSRLS`, superuser or owner privilege,
|
||||
and until a complete engagement record names the database, window, rate
|
||||
ceiling, abort contact and finding destination. `platform-pg` stays
|
||||
`not_applicable` until that identity exists. Do not open a database
|
||||
connection to finish this task.
|
||||
|
||||
### T02 — Live P1/P2 against a bounded substrate window
|
||||
|
||||
```task
|
||||
id: WHITEHAT-WP-0006-T02
|
||||
status: wait
|
||||
priority: medium
|
||||
```
|
||||
|
||||
Blocked until an operator-approved substrate window names the aggressor
|
||||
consumer, allowance, concurrency/resource ceilings, service classes, headroom
|
||||
threshold and abort thresholds. `shared-substrate` stays `pending` until that
|
||||
window exists. Do not generate load to finish this task.
|
||||
|
||||
### T03 — Remaining E2 under new engagement IDs
|
||||
|
||||
```task
|
||||
id: WHITEHAT-WP-0006-T03
|
||||
status: wait
|
||||
priority: medium
|
||||
```
|
||||
|
||||
Blocked until either `flex-auth` names a confirmed tenant-A identity with no
|
||||
tenant-B authority, or a later `audit-core` run is approved under a **new**
|
||||
engagement ID. `WH-ENG-20260822-AUDIT-E2-01`, `-02` and `-03` are terminal and
|
||||
must not be reused. `tenant-engine` stays `not_applicable`. Do not send a
|
||||
packet to finish this task.
|
||||
|
||||
## Sequencing
|
||||
|
||||
None of these tasks starts without the engagement record and approvals
|
||||
required by the rules of engagement §1 plus plane admission. T01, T02 and T03
|
||||
are independent. Offline fixture work stays on `WHITEHAT-WP-0001`.
|
||||
Loading…
Add table
Add a link
Reference in a new issue