Promote ASM T-01–T-10 into WHITEHAT-WP-0007 and triage each test
Extend whitehat-target/v1 with fixture-asm/asm instead of mapping onto E2, E3, or capacity. Register all ten Canon tests as pending with named blockers, known-bad designs, and result routes. Add a value-safe conformance-message renderer. Authorizes no probe. Assistant: grok Assistant-Session: 01a05e32-c776-72a3-86ec-c490e027aca9
This commit is contained in:
parent
44d6958b71
commit
5384f051d2
24 changed files with 850 additions and 16 deletions
43
targets/asm-t04.json
Normal file
43
targets/asm-t04.json
Normal file
|
|
@ -0,0 +1,43 @@
|
|||
{
|
||||
"schema_version": "whitehat-target/v1",
|
||||
"target_id": "asm-t04",
|
||||
"posture_claim": "ASM T-04",
|
||||
"attacker_model": "ordinary actor attempting to widen its own authority ceiling",
|
||||
"applicability": "pending",
|
||||
"applicability_reason": "No ordinary-actor versus independent-governance identity pair exposed to this facility. Known-bad design: the actor can modify its own ceiling. This registration does not authorize a probe.",
|
||||
"approval_classes": [
|
||||
"asm"
|
||||
],
|
||||
"specification": "asm-assurance-targets.v1",
|
||||
"test_id": "T-04",
|
||||
"title": "Policy Self-Modification Test",
|
||||
"claims": [
|
||||
"INV-07",
|
||||
"INV-11",
|
||||
"A-11"
|
||||
],
|
||||
"oracle": "no-self-widening-policy-effect",
|
||||
"surface": [
|
||||
"policy-change-pep",
|
||||
"access-engine",
|
||||
"policy-repository"
|
||||
],
|
||||
"result_route": {
|
||||
"conformance": "gate-house",
|
||||
"implementation_finding": "risk-nexus",
|
||||
"specification_finding": "gate-house",
|
||||
"harness_gap": "whitehat-security"
|
||||
},
|
||||
"routes": [],
|
||||
"identities": {
|
||||
"count": 0,
|
||||
"role": "none until the owning surface names a test identity",
|
||||
"broker_audience": "whitehat-asm/t-04"
|
||||
},
|
||||
"abort_telemetry": [
|
||||
"kill_switch",
|
||||
"scope_boundary",
|
||||
"missing_known_bad_calibration",
|
||||
"secret_value_observed"
|
||||
]
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue