whitehat-security/workplans/WHITEHAT-WP-0004-canonical-custody-binding.md
tegwick a61d7df925 Record DoD-Ok on WHITEHAT-WP-0002 through 0005
Finished custody-adapter plans were quality-debt-open without a DoD
assessment. Index WHITEHAT-IN-0001 as closed.

Assistant: grok
Assistant-Session: 01a05e32-c776-72a3-86ec-c490e027aca9
2026-09-01 20:52:54 +02:00

1.9 KiB

id type title domain repo status owner topic_slug created updated related state_hub_workstream_id quality_dod quality_dod_at quality_dod_by quality_dod_note
WHITEHAT-WP-0004 workplan Bind the WP-0025 adapter to canonical, fail-closed custody receipts infotech whitehat-security finished net-kingdom whitehat-security 2026-08-22 2026-09-01
WHITEHAT-WP-0003
RAILIANCE-WP-0025
779ad220-2ce3-5117-aec8-bb4a97d43d98 DoD-Ok 2026-09-01 grok T01 done; WP-0025 receipts fail closed without a matching projection contract. Authorizes no traffic.

WHITEHAT-WP-0004 — canonical custody binding

Goal

Close the Railiance WP-0025 owner review of adapter 1a38080 / HEAD da6f5fb: the consumer discovered the four schemas and its focused tests passed, but it was not fail-closed or canonically bound. A live projection receipt must not admit a plane lease unless it matches a supplied projection contract.

This plan authorizes no engagement, runner, credential, or traffic.

Origin

Platform progress d1fce546 (2026-08-22T20:09:59Z) on RAILIANCE-WP-0025 T03: noncanonical receipt_id, projection_contract_digest not derived from the supplied contract, incomplete resource UIDs accepted, runtime --contract optional, and receipt validation unbound from target, identities, resources, broker digest, times, and canonical receipt id.

Tasks

T01 — Require a contract and bind the receipt canonically

id: WHITEHAT-WP-0004-T01
status: done
priority: high
state_hub_task_id: "e3cf7d58-de89-5f6f-b411-297418bdd79a"

PlatformCustodyBroker and admit-plane refuse a WP-0025 projection receipt without --contract. Validation derives the contract digest, requires the canonical receipt_id, and binds target, identities, resource names, the three Kubernetes UIDs, broker digest, and projection/expiry times. The focused adapter tests reject each of those fail-open cases.