Close T05 and T06 on the same applicable-target rule as T03: E3 cadence and in-process calibration, platform-pg not_applicable, P1/P2 evaluator proven against known-good and known-bad samples. Persist offline capacity calibration. Live E3, P1/P2, flex-auth E2, and a later audit-core run move to WHITEHAT-WP-0006, which authorizes no packet. Assistant: grok Assistant-Session: 01a05e32-c776-72a3-86ec-c490e027aca9 |
||
|---|---|---|
| .. | ||
| offline-calibration.json | ||
| offline-capacity-calibration.json | ||
| offline-e3-calibration.json | ||
| README.md | ||
| WH-ENG-20260822-AUDIT-E2-02-abort.json | ||
| WH-ENG-20260822-AUDIT-E2-03.json | ||
Evidence
This directory stores sanitized run artifacts. offline-calibration.json,
offline-e3-calibration.json and offline-capacity-calibration.json are
generated from repository-created fixtures and prove only that the harness
distinguishes known-good from known-bad behavior. They are not target
assurance. WH-ENG-20260822-AUDIT-E2-02-abort.json
is an abort record (evidence_class: abort), not an E2 pass or finding.
WH-ENG-20260822-AUDIT-E2-03.json is the first authorized target pass; SHA-256
2d5a21141b78024a5334881e2b7fd62a69c46931057f77515a6c6f18ec497593. A pass
means only that the attempted attacks did not work.
Before committing target evidence, verify that it contains no response body, credential, database URL, real tenant identifier, or real tenant value. A run-local digest is allowed; it must not be reusable across runs as a data oracle.