Finish WHITEHAT-WP-0001 and own live residuals in WP-0006

Close T05 and T06 on the same applicable-target rule as T03: E3 cadence
and in-process calibration, platform-pg not_applicable, P1/P2 evaluator
proven against known-good and known-bad samples. Persist offline capacity
calibration. Live E3, P1/P2, flex-auth E2, and a later audit-core run
move to WHITEHAT-WP-0006, which authorizes no packet.

Assistant: grok
Assistant-Session: 01a05e32-c776-72a3-86ec-c490e027aca9
This commit is contained in:
tegwick 2026-09-01 20:26:47 +02:00
parent 69e03efd7f
commit 43327183d8
13 changed files with 355 additions and 73 deletions

View file

@ -4,11 +4,11 @@ type: workplan
title: "Produce the adversarial evidence the Tenancy Posture ladders require"
domain: infotech
repo: whitehat-security
status: active
status: finished
owner: net-kingdom
topic_slug: whitehat-security
created: "2026-08-17"
updated: "2026-08-23"
updated: "2026-09-01"
state_hub_workstream_id: "3049aa1e-b188-514f-9ad7-bf3026094fb9"
---
@ -189,7 +189,7 @@ new admitted engagement runs.
```task
id: WHITEHAT-WP-0001-T05
status: progress
status: done
priority: medium
state_hub_task_id: "7c2c3dab-a135-543b-86b1-d543ec6af0fc"
```
@ -210,20 +210,26 @@ notices. This repo is that something.
control the interval between runs *is* the exposure window, and ADR-0003 leaves
the number to this repo. Set it, and state the resulting window in the record.
Implementation progress, 2026-08-22: the cadence is fixed at 24 hours plus run
and reporting latency, with event-triggered pre-promotion runs after schema,
role, RLS or security-definer changes. `src/whitehat_security/e3.py` encodes the
seven expected outcomes, keeps the SQL-compromise GUC reset labeled as E3's
documented limit, and calibrates known-good/known-bad in-process. `platform-pg`
is `not_applicable` for an ordinary runtime conformance-view identity
(rapp-postgres, 2026-08-22). A live database run still requires a separately
**Acceptance:** a cadence and calibration record against every *applicable* E3
target. The artifact is the record, not a live SQL run. `platform-pg` is
registered `not_applicable` for an ordinary runtime conformance-view identity;
that record is the artifact for that target.
Done 2026-09-01: cadence is 24 hours plus run and reporting latency, with
event-triggered pre-promotion runs after schema, role, RLS or security-definer
changes. `src/whitehat_security/e3.py` encodes the seven expected outcomes,
keeps the SQL-compromise GUC reset labeled as E3's documented limit, and
calibrates known-good/known-bad in-process.
`evidence/offline-e3-calibration.json` is the fixture artifact. `platform-pg`
stays `not_applicable`. Whitehat will not relabel it to finish this task. A
live database run is owned by `WHITEHAT-WP-0006` and still requires a separately
reviewed runtime-safe surface, named database, and window.
### T06 — Noisy-neighbour characterisation (the P1/P2 artifact)
```task
id: WHITEHAT-WP-0001-T06
status: progress
status: done
priority: medium
state_hub_task_id: "3a2d7a31-86b9-5c82-ab88-606b64381b2a"
```
@ -241,12 +247,20 @@ acceptable.
Runs inside a declared window per T01 — on a single-node rail with a six-
consumer connection ceiling, a saturation probe is an outage if run carelessly.
Implementation progress, 2026-08-22: `src/whitehat_security/capacity.py`
records baseline/loaded latency, errors and throughput per consumer, governor
binding, aggressor peak/ceiling and neighbour degradation. The in-process
fixture is registered as `fixture-capacity`. `shared-substrate` is `pending`.
No live load has been generated; the required operator-approved substrate
window and aggressor ceiling do not yet exist.
**Acceptance:** an in-process characterization evaluator that records governor
binding and neighbour degradation, proven against known-good and known-bad
samples. `shared-substrate` remains `pending` and is not an applicable live
target.
Done 2026-09-01: `src/whitehat_security/capacity.py` records baseline/loaded
latency, errors and throughput per consumer, governor binding, aggressor
peak/ceiling and neighbour degradation. Known-good binds and stays within
ceiling; known-bad detects an unbound governor, an exceeded ceiling, and a
missing neighbour sample. `evidence/offline-capacity-calibration.json` is the
fixture artifact. The in-process fixture is `fixture-capacity`.
`shared-substrate` stays `pending`. Whitehat will not relabel it to finish this
task. No live load has been generated; that residual is owned by
`WHITEHAT-WP-0006`.
### T07 — Reporting into risk-nexus
@ -309,15 +323,22 @@ gates live T03. T07 can follow T03.
## Session cutoff — 2026-08-22
The coordinating session ended with the workplan deliberately **active**. T01,
T02, T03, T04, T07 and T08 are done. T05 and T06 remain in progress.
T02, T03, T04, T07 and T08 were done. T05 and T06 remained in progress.
`WH-ENG-20260822-AUDIT-E2-01` expired unused, `-02` aborted with zero packets,
and `-03` completed as a bounded target pass. Those identifiers are terminal
and must never be reused. `flex-auth` is still pending; `platform-pg` E3 is
`not_applicable`; no P1/P2 live window exists.
and must never be reused.
The exact earlier cutoff scope is recorded in
`docs/session-cutoff-2026-08-22.md` and `docs/test-plane.md`.
## Closeout — 2026-09-01
This workplan is **finished**. T01T08 are done for every applicable target.
`tenant-engine` E2 and `platform-pg` E3 stay `not_applicable`. `flex-auth` E2
and `shared-substrate` P1/P2 stay `pending`. Live E3, live P1/P2, flex-auth E2,
and a later audit-core E2 run are owned by `WHITEHAT-WP-0006`. That plan
authorizes no packet.
## Risks
**The facility becomes the threat.** Mitigated by T01, and by holding no

View file

@ -0,0 +1,82 @@
---
id: WHITEHAT-WP-0006
type: workplan
title: "Authorized live residuals after WHITEHAT-WP-0001"
domain: infotech
repo: whitehat-security
status: blocked
owner: net-kingdom
topic_slug: whitehat-security
created: "2026-09-01"
updated: "2026-09-01"
related:
- WHITEHAT-WP-0001
---
# WHITEHAT-WP-0006 — authorized live residuals
## Goal
Own the live evidence work that `WHITEHAT-WP-0001` correctly did not run:
E3 against a runtime-safe database surface, P1/P2 against a bounded substrate
window, flex-auth E2 once the attacker identity exists, and a later audit-core
E2 run under a new engagement ID.
This plan authorizes no engagement, runner, credential, traffic, or load.
## Origin
`WHITEHAT-WP-0001` finished on 2026-09-01. Its applicable artifacts are
offline E2/E3/P1/P2 calibration, the `audit-core` E2 pass
`WH-ENG-20260822-AUDIT-E2-03`, and honest `not_applicable` / `pending` target
records. Live residuals must not remain only in that plan's prose.
## Tasks
### T01 — Live E3 against a runtime-safe surface
```task
id: WHITEHAT-WP-0006-T01
status: wait
priority: medium
```
Blocked until a named database exposes an ordinary runtime identity that can
read the conformance view without `BYPASSRLS`, superuser or owner privilege,
and until a complete engagement record names the database, window, rate
ceiling, abort contact and finding destination. `platform-pg` stays
`not_applicable` until that identity exists. Do not open a database
connection to finish this task.
### T02 — Live P1/P2 against a bounded substrate window
```task
id: WHITEHAT-WP-0006-T02
status: wait
priority: medium
```
Blocked until an operator-approved substrate window names the aggressor
consumer, allowance, concurrency/resource ceilings, service classes, headroom
threshold and abort thresholds. `shared-substrate` stays `pending` until that
window exists. Do not generate load to finish this task.
### T03 — Remaining E2 under new engagement IDs
```task
id: WHITEHAT-WP-0006-T03
status: wait
priority: medium
```
Blocked until either `flex-auth` names a confirmed tenant-A identity with no
tenant-B authority, or a later `audit-core` run is approved under a **new**
engagement ID. `WH-ENG-20260822-AUDIT-E2-01`, `-02` and `-03` are terminal and
must not be reused. `tenant-engine` stays `not_applicable`. Do not send a
packet to finish this task.
## Sequencing
None of these tasks starts without the engagement record and approvals
required by the rules of engagement §1 plus plane admission. T01, T02 and T03
are independent. Offline fixture work stays on `WHITEHAT-WP-0001`.