whitehat-security/targets/README.md
tegwick 5384f051d2 Promote ASM T-01–T-10 into WHITEHAT-WP-0007 and triage each test
Extend whitehat-target/v1 with fixture-asm/asm instead of mapping onto
E2, E3, or capacity. Register all ten Canon tests as pending with named
blockers, known-bad designs, and result routes. Add a value-safe
conformance-message renderer. Authorizes no probe.

Assistant: grok
Assistant-Session: 01a05e32-c776-72a3-86ec-c490e027aca9
2026-09-02 01:11:16 +02:00

20 lines
1.3 KiB
Markdown

# Target registrations
A target name is not an E2 boundary. Each file in this directory is the
honest applicability record the test plane admits against.
| `target_id` | Applicability | Meaning |
| --- | --- | --- |
| `fixture-e2` | applicable | In-process known-good/known-bad harness. Offline only. |
| `audit-core` | applicable | Two ordinary tenant-scoped senders instantiate E2. Dated pass `WH-ENG-20260822-AUDIT-E2-03`; that ID is terminal. |
| `tenant-engine` | not_applicable | No tenant-A identity without tenant-B authority. |
| `flex-auth` | pending | Initial envelope; owner has not confirmed the attacker identity. |
| `fixture-e3` | applicable | In-process E3 evaluator. One runtime identity, no `BYPASSRLS`. |
| `platform-pg` | not_applicable | No ordinary runtime identity can read the conformance view. |
| `fixture-capacity` | applicable | In-process P1/P2 evaluator. Generates no load. |
| `shared-substrate` | pending | Live capacity needs an operator window and aggressor ceiling. |
| `asm-t01``asm-t10` | pending | Gate House ASM T-01…T-10. Separate `asm` class; not E2/E3/capacity. See `WHITEHAT-WP-0007`. |
`not_applicable` is a completed artifact, not a deferral. Do not relabel it to
close a workplan. Do not reuse cancelled engagement IDs from `engagements/`.
Pending ASM targets are not admitted. They preserve Canon `test_id` values.