From 379404189b57f77c48eb697b0ee5ec8d2cb9b544 Mon Sep 17 00:00:00 2001 From: Brad Edwards Date: Sat, 3 Oct 2026 04:27:30 +0200 Subject: [PATCH 1/2] Fix TechVault study compatibility with RAES 6.0.1 --- ...ault-participant-affiliations-preflight.md | 69 +++++++++ .../associated-artifacts.json | 14 +- .../pack.compatibility.yaml | 2 +- packs/techvault-participant-study/pack.yaml | 2 +- .../techvault-participant-study.bindings.json | 28 ++-- .../sdl/techvault-participant-study.sdl.yaml | 133 +++++++++--------- packs/techvault/associated-artifacts.json | 14 +- packs/techvault/pack.compatibility.yaml | 2 +- packs/techvault/pack.yaml | 2 +- packs/techvault/sdl/techvault.bindings.json | 28 ++-- packs/techvault/sdl/techvault.sdl.yaml | 131 +++++++++-------- pyproject.toml | 4 +- requirements/runtime.txt | 6 +- tests/test_distribution.py | 11 +- tests/test_release_publish.py | 22 +-- tests/test_techvault_pack.py | 7 +- tests/test_techvault_study_pack.py | 62 +++++++- tests/test_verify.py | 8 +- uv.lock | 8 +- 19 files changed, 337 insertions(+), 216 deletions(-) create mode 100644 docs/development/techvault-participant-affiliations-preflight.md diff --git a/docs/development/techvault-participant-affiliations-preflight.md b/docs/development/techvault-participant-affiliations-preflight.md new file mode 100644 index 0000000..06292f7 --- /dev/null +++ b/docs/development/techvault-participant-affiliations-preflight.md @@ -0,0 +1,69 @@ +# TechVault participant affiliations preflight + +Issue #401 is a compatibility correction to first-party RAES content. RAES owns +the agent affiliation shape and the parse, compile, and admission rules. This +repository owns the two TechVault pack copies, their byte-bound associated +artifacts, and the release that makes the corrected study pack consumable. No +pack-owned participant schema, migration alias, or admission policy is needed. + +## Contract and scope + +Use one compatible **published** RAES release as the exactly pinned dependency +and as the authority in the regression. The study pack's three agent +declarations must use its `affiliations` contract. The base TechVault pack also +declares `entity` on its two agents; a pin change that rejects that field must +bring those declarations forward as well, because hosted-pack and package tests +validate both packs. Compare the final parsed agent affiliations with the +intended `study-control`, `red-team`, and `blue-team` entities. Do not treat a +syntactic rename as proof that authority or audience is unchanged. + +Affiliation identifies an agent's relation to an entity. It does not grant the +controller authority or participant access. Preserve the separate +`authority_anchors`, `operating_scope`, `interactive_access`, +`observation_boundaries`, inject source and recipients, delivery policies, +mixed-control transitions, evidence requirements, and the authored red-start, +red-stop, blue-start, blue-stop order. The existing study regression checks the +compiled addresses and ticks; it needs a RAES-owned admission check of the +participant delivery bindings and their authority and exposure boundaries. +That admission test should use a deterministic, non-secret compatible fixture, +not backend credentials or a live provider session. A passing `validate_pack` +or successful compile alone does not establish admission. + +## Cross-cutting guardrails + +| Layer | Existing authority and constraint | +| --- | --- | +| SDL shape and semantics | `raes.parse_sdl_file`, `instantiate_scenario`, `raes_processor.compiler.compile_runtime_model`, and the published RAES admission contract. Use their public models and diagnostics; add no local SDL DTO, validator, exception hierarchy, or fallback for `entity`. | +| Pack validation | `validation.validate_pack` is the silent consumer result. `content_ci` adds trusted author checks. Keep their bounded, payload-free diagnostic and logging behavior; do not route foreign packs through pack-local executable tests. | +| Filesystem and content identity | `_pack_fs`, `digest.validate_pack_content_manifest`, and `digest.pack_content_digest` guard contained reads and exact inventory. `tools/refresh_pack_sdl_binding.py` is the SDL-only authoring path that retargets surviving external-concept subjects and rebinds their manifest members. Use `derive_pack_content_manifest` when another member's bytes or inventory change. Verify the resulting digest from the final tree; never hand-edit hashes or claim a digest from unvalidated bytes. | +| Concepts and schemes | ADR 0038 and RAES `admit_external_concept_bindings` own concept admission. The scheme snapshot is an independently pinned source, not a digest of agent affiliations. Preserve its bytes when its source and concepts are unchanged; revalidate it and its manifest member after rebinding. | +| Exposure and secrets | Keep `pack.compatibility.yaml` artifact boundaries, release participant-view and leak gates, RAES observation boundaries, and existing generated-secret references. The SDL has no provider credential, host path, environment binding, or executable launch command. Test fixtures, CLI argv, logs, and errors must contain no secret values or instruction payload dumps. | +| Publication | `pyproject.toml` includes both packs in wheel and sdist. Use the hosted-pack validation and release checks plus packaged-content tests. Release Please owns the project version and `CHANGELOG.md`; the `dev` to `main` promotion and release workflow own publication. | + +The extensibility seam is the pinned RAES public contract and its admission +fixture: a later participant profile or affiliation variation should change +authored RAES data and the fixture, not introduce a TechVault-specific parser or +hard-code Claude Code into a generic pack validator. Preserve the +`participant-implementation-manifest:claude-code` reference as authored study +data. Backend mapping of that reference and provider session lifecycle remain +outside this repository. + +## Published RAES 6.0.1 compatibility + +RAES 6.0.1 admits participant delivery addresses as temporal subjects and +requires agent affiliations. It also accepts required evidence media types only +when a registered output contract can validate their content. The two TechVault +packs previously required `text/plain` or `application/x-ndjson` for three +evidence needs without a matching RAES output contract. Leave their encodings +unspecified while preserving each requirement's source, scope, channel, +redaction, integrity, retention, and loss-disclosure intent. Do not relabel a +plain-text transcript as JSON merely to satisfy the parser. + +## Boundaries + +No changes to the four-inject study design, evidence meaning, scoring, telemetry, +backend admission policy, runtime controller, credential delivery, or live +qualification are implied. Do not conflate affiliation with authorization, +observation with instruction delivery, the pack set digest with an SDL or scheme +digest, or a validated local checkout with a published package. Do not encode +APTL-specific catalog paths or backend commands into canonical pack metadata. diff --git a/packs/techvault-participant-study/associated-artifacts.json b/packs/techvault-participant-study/associated-artifacts.json index 1724fa3..69e6ad1 100644 --- a/packs/techvault-participant-study/associated-artifacts.json +++ b/packs/techvault-participant-study/associated-artifacts.json @@ -1,7 +1,7 @@ { "schema_version": "associated-artifact-manifest/v1", "manifest_id": "techvault-participant-study-associated-artifacts", - "manifest_version": "0.1.0", + "manifest_version": "0.1.1", "canonicalization_profile": "associated-artifact-set/v1", "scope": "scenario", "parent_ref": { @@ -547,7 +547,7 @@ "uri": "raes-environment-pack:/pack.compatibility.yaml", "checksum": { "algorithm": "sha256", - "value": "11592e4c23fe22092c9c7aeb06c18c0d4bf27992c8ac8cf868a5a23f52156735" + "value": "079837132da23c786ecfa8991a810e50dc3c7d79fbe0b89b22f7aec2fc5c1f87" }, "size_bytes": 1607, "created_at": "2026-08-02T00:00:00Z", @@ -563,7 +563,7 @@ "uri": "raes-environment-pack:/pack.yaml", "checksum": { "algorithm": "sha256", - "value": "ad659b564b3bfc38206a61f94d8b2422a941666740529939ba63ec24da671171" + "value": "e2f0a8063d8770e37a68f98bb139f5aa3ae1729f35d0b20319508672559467cc" }, "size_bytes": 552, "created_at": "2026-08-02T00:00:00Z", @@ -595,7 +595,7 @@ "uri": "raes-environment-pack:/sdl/techvault-participant-study.bindings.json", "checksum": { "algorithm": "sha256", - "value": "08d6197a94bceb75325d63bb5e469c188534a93cc99a1f14d967964af4b1ab06" + "value": "7c4c678ebe41cedfb06d9cf879bc8db7886229a54e8f699f0310045b2bddd854" }, "size_bytes": 44611, "created_at": "2026-09-13T00:00:00Z", @@ -627,9 +627,9 @@ "uri": "raes-environment-pack:/sdl/techvault-participant-study.sdl.yaml", "checksum": { "algorithm": "sha256", - "value": "1fec5130185eadea28157af10fb76c3394ad21c349d2849628d0f4e5c3fc1e24" + "value": "bacbfb918bff2fab5bc730bce2ac1668fbc409e007dd84f17d47496d23cb73e0" }, - "size_bytes": 167003, + "size_bytes": 166927, "created_at": "2026-08-02T00:00:00Z", "source": "environment-pack-author", "satisfies_refs": [], @@ -733,5 +733,5 @@ "description": "Exact defensive stdio MCP source packages for the SOC workstation." } }, - "set_digest": "sha256:94dc0236f3e2d4c62db782040acd73b1739ba0bf12adec580289a916fbfcce5a" + "set_digest": "sha256:fdde7b1a8b9377f7ddd473417de1f3fd3e24549e4560d8d6392f1727b3af5357" } diff --git a/packs/techvault-participant-study/pack.compatibility.yaml b/packs/techvault-participant-study/pack.compatibility.yaml index 8bcfcc9..7e9b938 100644 --- a/packs/techvault-participant-study/pack.compatibility.yaml +++ b/packs/techvault-participant-study/pack.compatibility.yaml @@ -2,7 +2,7 @@ schema_version: "environment-pack-compatibility/v2" pack: name: techvault-participant-study title: TechVault - version: 0.1.0 + version: 0.1.1 status: built provenance_ledger: docs/provenance-ledger.yaml source: diff --git a/packs/techvault-participant-study/pack.yaml b/packs/techvault-participant-study/pack.yaml index 4976e10..c904838 100644 --- a/packs/techvault-participant-study/pack.yaml +++ b/packs/techvault-participant-study/pack.yaml @@ -1,6 +1,6 @@ name: techvault-participant-study title: TechVault Participant Study -version: 0.1.0 +version: 0.1.1 status: built description: >- The TechVault enterprise intrusion environment plus an SDL-authored, diff --git a/packs/techvault-participant-study/sdl/techvault-participant-study.bindings.json b/packs/techvault-participant-study/sdl/techvault-participant-study.bindings.json index 9a81f6d..6ce0264 100644 --- a/packs/techvault-participant-study/sdl/techvault-participant-study.bindings.json +++ b/packs/techvault-participant-study/sdl/techvault-participant-study.bindings.json @@ -10,7 +10,7 @@ "owning_contract_id": "sdl-authoring-input-v1", "lifecycle_phase": "normalized-authoring", "canonical_ref": "nodes.webapp.runtime.applications.techvault-portal.routes.ping-tool", - "artifact_digest": "sha256:631d3ca119b18647d2f32a7fbe229c9bad5a224f51ffc1c61831741f1d9d9b74" + "artifact_digest": "sha256:4fbffb486f2c9500c4ebe8b3f82da334a52d493f6a147dc43a1c6f12febbfb7e" }, "scheme": { "scheme_id": "mitre-cwe", @@ -87,7 +87,7 @@ "owning_contract_id": "sdl-authoring-input-v1", "lifecycle_phase": "normalized-authoring", "canonical_ref": "nodes.webapp.runtime.applications.techvault-portal.routes.debug", - "artifact_digest": "sha256:631d3ca119b18647d2f32a7fbe229c9bad5a224f51ffc1c61831741f1d9d9b74" + "artifact_digest": "sha256:4fbffb486f2c9500c4ebe8b3f82da334a52d493f6a147dc43a1c6f12febbfb7e" }, "scheme": { "scheme_id": "mitre-cwe", @@ -164,7 +164,7 @@ "owning_contract_id": "sdl-authoring-input-v1", "lifecycle_phase": "normalized-authoring", "canonical_ref": "nodes.webapp.runtime.applications.techvault-portal.routes.debug", - "artifact_digest": "sha256:631d3ca119b18647d2f32a7fbe229c9bad5a224f51ffc1c61831741f1d9d9b74" + "artifact_digest": "sha256:4fbffb486f2c9500c4ebe8b3f82da334a52d493f6a147dc43a1c6f12febbfb7e" }, "scheme": { "scheme_id": "mitre-cwe", @@ -241,7 +241,7 @@ "owning_contract_id": "sdl-authoring-input-v1", "lifecycle_phase": "normalized-authoring", "canonical_ref": "nodes.webapp.runtime.applications.techvault-portal.routes.api-token", - "artifact_digest": "sha256:631d3ca119b18647d2f32a7fbe229c9bad5a224f51ffc1c61831741f1d9d9b74" + "artifact_digest": "sha256:4fbffb486f2c9500c4ebe8b3f82da334a52d493f6a147dc43a1c6f12febbfb7e" }, "scheme": { "scheme_id": "mitre-cwe", @@ -318,7 +318,7 @@ "owning_contract_id": "sdl-authoring-input-v1", "lifecycle_phase": "normalized-authoring", "canonical_ref": "nodes.webapp.runtime.applications.techvault-portal.routes.api-file", - "artifact_digest": "sha256:631d3ca119b18647d2f32a7fbe229c9bad5a224f51ffc1c61831741f1d9d9b74" + "artifact_digest": "sha256:4fbffb486f2c9500c4ebe8b3f82da334a52d493f6a147dc43a1c6f12febbfb7e" }, "scheme": { "scheme_id": "mitre-cwe", @@ -395,7 +395,7 @@ "owning_contract_id": "sdl-authoring-input-v1", "lifecycle_phase": "normalized-authoring", "canonical_ref": "nodes.webapp.runtime.applications.techvault-portal.routes.api-user", - "artifact_digest": "sha256:631d3ca119b18647d2f32a7fbe229c9bad5a224f51ffc1c61831741f1d9d9b74" + "artifact_digest": "sha256:4fbffb486f2c9500c4ebe8b3f82da334a52d493f6a147dc43a1c6f12febbfb7e" }, "scheme": { "scheme_id": "mitre-cwe", @@ -472,7 +472,7 @@ "owning_contract_id": "sdl-authoring-input-v1", "lifecycle_phase": "normalized-authoring", "canonical_ref": "nodes.webapp.runtime.applications.techvault-portal.routes.admin", - "artifact_digest": "sha256:631d3ca119b18647d2f32a7fbe229c9bad5a224f51ffc1c61831741f1d9d9b74" + "artifact_digest": "sha256:4fbffb486f2c9500c4ebe8b3f82da334a52d493f6a147dc43a1c6f12febbfb7e" }, "scheme": { "scheme_id": "mitre-cwe", @@ -549,7 +549,7 @@ "owning_contract_id": "sdl-authoring-input-v1", "lifecycle_phase": "normalized-authoring", "canonical_ref": "nodes.webapp.runtime.applications.techvault-portal.routes.login", - "artifact_digest": "sha256:631d3ca119b18647d2f32a7fbe229c9bad5a224f51ffc1c61831741f1d9d9b74" + "artifact_digest": "sha256:4fbffb486f2c9500c4ebe8b3f82da334a52d493f6a147dc43a1c6f12febbfb7e" }, "scheme": { "scheme_id": "mitre-cwe", @@ -626,7 +626,7 @@ "owning_contract_id": "sdl-authoring-input-v1", "lifecycle_phase": "normalized-authoring", "canonical_ref": "nodes.webapp.runtime.applications.techvault-portal.routes.search", - "artifact_digest": "sha256:631d3ca119b18647d2f32a7fbe229c9bad5a224f51ffc1c61831741f1d9d9b74" + "artifact_digest": "sha256:4fbffb486f2c9500c4ebe8b3f82da334a52d493f6a147dc43a1c6f12febbfb7e" }, "scheme": { "scheme_id": "mitre-cwe", @@ -703,7 +703,7 @@ "owning_contract_id": "sdl-authoring-input-v1", "lifecycle_phase": "normalized-authoring", "canonical_ref": "nodes.webapp.runtime.applications.techvault-portal.routes.upload", - "artifact_digest": "sha256:631d3ca119b18647d2f32a7fbe229c9bad5a224f51ffc1c61831741f1d9d9b74" + "artifact_digest": "sha256:4fbffb486f2c9500c4ebe8b3f82da334a52d493f6a147dc43a1c6f12febbfb7e" }, "scheme": { "scheme_id": "mitre-cwe", @@ -780,7 +780,7 @@ "owning_contract_id": "sdl-authoring-input-v1", "lifecycle_phase": "normalized-authoring", "canonical_ref": "nodes.webapp.runtime.applications.techvault-portal.routes.login", - "artifact_digest": "sha256:631d3ca119b18647d2f32a7fbe229c9bad5a224f51ffc1c61831741f1d9d9b74" + "artifact_digest": "sha256:4fbffb486f2c9500c4ebe8b3f82da334a52d493f6a147dc43a1c6f12febbfb7e" }, "scheme": { "scheme_id": "mitre-cwe", @@ -857,7 +857,7 @@ "owning_contract_id": "sdl-authoring-input-v1", "lifecycle_phase": "normalized-authoring", "canonical_ref": "nodes.webapp.runtime.applications.techvault-portal.routes.api-token", - "artifact_digest": "sha256:631d3ca119b18647d2f32a7fbe229c9bad5a224f51ffc1c61831741f1d9d9b74" + "artifact_digest": "sha256:4fbffb486f2c9500c4ebe8b3f82da334a52d493f6a147dc43a1c6f12febbfb7e" }, "scheme": { "scheme_id": "mitre-cwe", @@ -934,7 +934,7 @@ "owning_contract_id": "sdl-authoring-input-v1", "lifecycle_phase": "normalized-authoring", "canonical_ref": "nodes.webapp.runtime.applications.techvault-portal.routes.search", - "artifact_digest": "sha256:631d3ca119b18647d2f32a7fbe229c9bad5a224f51ffc1c61831741f1d9d9b74" + "artifact_digest": "sha256:4fbffb486f2c9500c4ebe8b3f82da334a52d493f6a147dc43a1c6f12febbfb7e" }, "scheme": { "scheme_id": "mitre-cwe", @@ -1011,7 +1011,7 @@ "owning_contract_id": "sdl-authoring-input-v1", "lifecycle_phase": "normalized-authoring", "canonical_ref": "nodes.webapp.runtime.applications.techvault-portal.routes.comment", - "artifact_digest": "sha256:631d3ca119b18647d2f32a7fbe229c9bad5a224f51ffc1c61831741f1d9d9b74" + "artifact_digest": "sha256:4fbffb486f2c9500c4ebe8b3f82da334a52d493f6a147dc43a1c6f12febbfb7e" }, "scheme": { "scheme_id": "mitre-cwe", diff --git a/packs/techvault-participant-study/sdl/techvault-participant-study.sdl.yaml b/packs/techvault-participant-study/sdl/techvault-participant-study.sdl.yaml index 3dc8d69..8f8925d 100644 --- a/packs/techvault-participant-study/sdl/techvault-participant-study.sdl.yaml +++ b/packs/techvault-participant-study/sdl/techvault-participant-study.sdl.yaml @@ -2475,13 +2475,13 @@ content: path: /var/ossec/etc/rules/webapp_rules.xml source: name: techvault-wazuh-webapp-rules - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-wazuh-webapp-rules-requirement explicitness: exact exact_artifact: artifact_id: techvault-wazuh-webapp-rules - version: 0.1.0 + version: 0.1.1 digest: sha256:67db59b11e89ee2fca6515ce6ae2c433793a12aea5510355af0858e66cc2a844 media_type: application/xml permitted_routes: @@ -2498,13 +2498,13 @@ content: path: /var/ossec/etc/rules/suricata_rules.xml source: name: techvault-wazuh-suricata-rules - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-wazuh-suricata-rules-requirement explicitness: exact exact_artifact: artifact_id: techvault-wazuh-suricata-rules - version: 0.1.0 + version: 0.1.1 digest: sha256:b1fdf64371c5ea24f8e1ce47ea2d0aba185f2f6697702c4bb092c2f3d696547c media_type: application/xml permitted_routes: @@ -2517,13 +2517,13 @@ content: path: /var/ossec/etc/rules/ad_rules.xml source: name: techvault-wazuh-ad-rules - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-wazuh-ad-rules-requirement explicitness: exact exact_artifact: artifact_id: techvault-wazuh-ad-rules - version: 0.1.0 + version: 0.1.1 digest: sha256:8fdb8953d8e774c928adc6cef1a2eb06ef219b6feedc519092c0f1ca33cdc10b media_type: application/xml permitted_routes: @@ -2536,13 +2536,13 @@ content: path: /var/ossec/etc/rules/database_rules.xml source: name: techvault-wazuh-database-rules - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-wazuh-database-rules-requirement explicitness: exact exact_artifact: artifact_id: techvault-wazuh-database-rules - version: 0.1.0 + version: 0.1.1 digest: sha256:3799f8319eaf0da79c2c2a6e9468750122e6afcc715ee8095870ce750e366e15 media_type: application/xml permitted_routes: @@ -2555,13 +2555,13 @@ content: path: /var/ossec/etc/rules/falco_rules.xml source: name: techvault-wazuh-falco-rules - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-wazuh-falco-rules-requirement explicitness: exact exact_artifact: artifact_id: techvault-wazuh-falco-rules - version: 0.1.0 + version: 0.1.1 digest: sha256:b5bfba268ac98b2046322c5b363d628083bf4f935aa56daa2f6264fbf93ffeb4 media_type: application/xml permitted_routes: @@ -2574,13 +2574,13 @@ content: path: /var/ossec/etc/decoders/postgresql_decoders.xml source: name: techvault-wazuh-postgresql-decoders - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-wazuh-postgresql-decoders-requirement explicitness: exact exact_artifact: artifact_id: techvault-wazuh-postgresql-decoders - version: 0.1.0 + version: 0.1.1 digest: sha256:dd72b3d2a2912a0fca61b2d3c69e08deafce6821b357106ad90023965de1757a media_type: application/xml permitted_routes: @@ -2593,13 +2593,13 @@ content: path: /var/ossec/etc/decoders/samba_decoders.xml source: name: techvault-wazuh-samba-decoders - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-wazuh-samba-decoders-requirement explicitness: exact exact_artifact: artifact_id: techvault-wazuh-samba-decoders - version: 0.1.0 + version: 0.1.1 digest: sha256:acf2c9fd0d6f0816c7791544c2a580ad0124039105f37c4fffc494ae04f7ffe7 media_type: application/xml permitted_routes: @@ -2612,13 +2612,13 @@ content: destination: /var/ossec/integrations source: name: techvault-wazuh-integrations - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-wazuh-integrations-requirement explicitness: exact exact_artifact: artifact_id: techvault-wazuh-integrations - version: 0.1.0 + version: 0.1.1 digest: sha256:7c6afe833433bd6674b390cf09d23808bd7b0427927bcb533b067d674d08e417 media_type: application/x-tar permitted_routes: @@ -2631,13 +2631,13 @@ content: path: /etc/suricata/suricata.yaml source: name: techvault-suricata-config - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-suricata-config-requirement explicitness: exact exact_artifact: artifact_id: techvault-suricata-config - version: 0.1.0 + version: 0.1.1 digest: sha256:d1bf43326da10781b8b20c10c78ad2bbbc25a64c50019fd7933a56bb52b42471 media_type: application/yaml permitted_routes: @@ -2654,13 +2654,13 @@ content: path: /etc/suricata/rules/local.rules source: name: techvault-suricata-local-rules - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-suricata-local-rules-requirement explicitness: exact exact_artifact: artifact_id: techvault-suricata-local-rules - version: 0.1.0 + version: 0.1.1 digest: sha256:c453a657ff6aba3bc756432c2300bffb6602532f6099236ddfbd17d091d2add4 media_type: text/plain permitted_routes: @@ -2673,13 +2673,13 @@ content: path: /var/lib/suricata/rules/misp/misp-iocs.rules source: name: techvault-suricata-misp-ioc-rules-seed - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-suricata-misp-ioc-rules-seed-requirement explicitness: exact exact_artifact: artifact_id: techvault-suricata-misp-ioc-rules-seed - version: 0.1.0 + version: 0.1.1 digest: sha256:462aecd67796a9ff9acd80e2bb2e9e597f05bfb05892c0766110bca933a30ede media_type: text/plain permitted_routes: @@ -2692,13 +2692,13 @@ content: path: /var/lib/suricata/rules/misp/misp-md5.list source: name: techvault-suricata-misp-md5-seed - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-suricata-misp-md5-seed-requirement explicitness: exact exact_artifact: artifact_id: techvault-suricata-misp-md5-seed - version: 0.1.0 + version: 0.1.1 digest: sha256:66be1ef4237386fd2e34a978fc245bb2030641fd76409062d72919954830f376 media_type: text/plain permitted_routes: @@ -2711,13 +2711,13 @@ content: path: /var/lib/suricata/rules/misp/misp-sha1.list source: name: techvault-suricata-misp-sha1-seed - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-suricata-misp-sha1-seed-requirement explicitness: exact exact_artifact: artifact_id: techvault-suricata-misp-sha1-seed - version: 0.1.0 + version: 0.1.1 digest: sha256:d91e7c095d162c8efb5ff55389043cf429809899df45f32f931f5d2eae381f0c media_type: text/plain permitted_routes: @@ -2730,13 +2730,13 @@ content: path: /var/lib/suricata/rules/misp/misp-sha256.list source: name: techvault-suricata-misp-sha256-seed - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-suricata-misp-sha256-seed-requirement explicitness: exact exact_artifact: artifact_id: techvault-suricata-misp-sha256-seed - version: 0.1.0 + version: 0.1.1 digest: sha256:b059ca012bd1345811fb9aae5e7a758498b33063887b092956bd083e41fa85dd media_type: text/plain permitted_routes: @@ -2764,13 +2764,13 @@ content: path: /opt/techvault/cortex-analyzers/TechVaultScenarioContext/analyzer.json source: name: techvault-cortex-analyzer-definition - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-cortex-analyzer-definition-requirement explicitness: exact exact_artifact: artifact_id: techvault-cortex-analyzer-definition - version: 0.1.0 + version: 0.1.1 digest: sha256:9c8bfce7a9b41ed10f549e1d841879ec350a3ea1b4b03b6658313255ef435970 media_type: application/json permitted_routes: @@ -2787,13 +2787,13 @@ content: path: /opt/techvault/cortex-analyzers/TechVaultScenarioContext/techvault_scenario_context.py source: name: techvault-cortex-analyzer-executable - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-cortex-analyzer-executable-requirement explicitness: exact exact_artifact: artifact_id: techvault-cortex-analyzer-executable - version: 0.1.0 + version: 0.1.1 digest: sha256:ce6962465bc7bdd6394b4df3785685a8cf32f22689671dfda644540ffc51f152 media_type: text/x-python permitted_routes: @@ -2810,13 +2810,13 @@ content: path: /app/pyproject.toml source: name: techvault-misp-sync-pyproject - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-misp-sync-pyproject-requirement explicitness: exact exact_artifact: artifact_id: techvault-misp-sync-pyproject - version: 0.1.0 + version: 0.1.1 digest: sha256:0e7214cdacc8f396e91360782c9aaf6d8c6523d2fb944cfcd3763c4ac996450f media_type: text/x-toml permitted_routes: @@ -2833,13 +2833,13 @@ content: path: /app/README.md source: name: techvault-misp-sync-readme - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-misp-sync-readme-requirement explicitness: exact exact_artifact: artifact_id: techvault-misp-sync-readme - version: 0.1.0 + version: 0.1.1 digest: sha256:07c3dee4987c47e57bc8f0333073abdc07b832a7e82136c3123577531978231b media_type: text/markdown permitted_routes: @@ -2856,13 +2856,13 @@ content: path: /app/hatch_build.py source: name: techvault-misp-sync-hatch-build - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-misp-sync-hatch-build-requirement explicitness: exact exact_artifact: artifact_id: techvault-misp-sync-hatch-build - version: 0.1.0 + version: 0.1.1 digest: sha256:975022d60fe6f5187b169d3e20932fd6c242dc1658f59232627eab7e75bf713c media_type: text/x-python permitted_routes: @@ -2879,13 +2879,13 @@ content: destination: /app/src source: name: techvault-misp-sync-src - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-misp-sync-src-requirement explicitness: exact exact_artifact: artifact_id: techvault-misp-sync-src - version: 0.1.0 + version: 0.1.1 digest: sha256:c872e56e963934883190f7fed307116504c39d6771a528852a8b4e27682e8b91 media_type: application/x-tar permitted_routes: @@ -2902,13 +2902,13 @@ content: destination: /app source: name: techvault-webapp-app - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-webapp-app-requirement explicitness: exact exact_artifact: artifact_id: techvault-webapp-app - version: 0.1.0 + version: 0.1.1 digest: sha256:521886364d4cb8bf4f6b3be05bf5598cba182b27a7ee4715ae0dc518134f4101 media_type: application/x-tar permitted_routes: @@ -2925,13 +2925,13 @@ content: path: /etc/bind/named.conf source: name: techvault-dns-named-conf - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-dns-named-conf-requirement explicitness: exact exact_artifact: artifact_id: techvault-dns-named-conf - version: 0.1.0 + version: 0.1.1 digest: sha256:3df85c5e388295b0e321598c9932a78bfb18e47315263c6990e9e36cb1b62ee7 media_type: text/plain permitted_routes: @@ -2948,13 +2948,13 @@ content: path: /etc/bind/zones/techvault.local.zone source: name: techvault-dns-forward-zone - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-dns-forward-zone-requirement explicitness: exact exact_artifact: artifact_id: techvault-dns-forward-zone - version: 0.1.0 + version: 0.1.1 digest: sha256:d12de977f09275e342454a58ca004f7909ff808c29143b4c6d4ecb14db611a82 media_type: text/plain permitted_routes: @@ -2971,13 +2971,13 @@ content: path: /etc/bind/zones/172.20.rev source: name: techvault-dns-reverse-zone - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-dns-reverse-zone-requirement explicitness: exact exact_artifact: artifact_id: techvault-dns-reverse-zone - version: 0.1.0 + version: 0.1.1 digest: sha256:ceb577f74bf3841ee10dae1a35e07afb921f9136bd4f9dbbd60d4afd1a4f0a02 media_type: text/plain permitted_routes: @@ -2994,13 +2994,13 @@ content: path: /etc/samba/smb.conf source: name: techvault-fileshare-smb-conf - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-fileshare-smb-conf-requirement explicitness: exact exact_artifact: artifact_id: techvault-fileshare-smb-conf - version: 0.1.0 + version: 0.1.1 digest: sha256:847edd4733cb764eba178c933831bf1af2359cd9042674994f70b91491a289e0 media_type: text/plain permitted_routes: @@ -3023,13 +3023,13 @@ content: destination: /srv/shares source: name: techvault-fileshare-shares - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-fileshare-shares-requirement explicitness: exact exact_artifact: artifact_id: techvault-fileshare-shares - version: 0.1.0 + version: 0.1.1 digest: sha256:342bc178915bd1fc8d84d2a57511175ad386eec08ac2830b9757c8dc2847e726 media_type: application/x-tar permitted_routes: @@ -3050,13 +3050,13 @@ content: destination: /home/dev-user source: name: techvault-workstation-dev-user-home - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-workstation-dev-user-home-requirement explicitness: exact exact_artifact: artifact_id: techvault-workstation-dev-user-home - version: 0.1.0 + version: 0.1.1 digest: sha256:a1a4f93fe5783a0ed1caf7c7bb78c1fae1506d4ab5eef34464f43b4e4884b4b7 media_type: application/x-tar permitted_routes: @@ -3080,13 +3080,13 @@ content: path: /opt/db-init/01-schema.sql source: name: techvault-db-init-schema - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-db-init-schema-requirement explicitness: exact exact_artifact: artifact_id: techvault-db-init-schema - version: 0.1.0 + version: 0.1.1 digest: sha256:7a1748928d6222db2e3877ec8f6599ec7e1aec8c2956d2842b8e49e146c52981 media_type: application/sql permitted_routes: @@ -3103,13 +3103,13 @@ content: path: /opt/db-init/02-seed-data.sql source: name: techvault-db-init-seed - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-db-init-seed-requirement explicitness: exact exact_artifact: artifact_id: techvault-db-init-seed - version: 0.1.0 + version: 0.1.1 digest: sha256:c98ab23427180f604ca9ccec5a00b426dc8d883a4102bbba24e76d5cda0f03dc media_type: application/sql permitted_routes: @@ -3197,13 +3197,13 @@ content: destination: /opt/techvault/mcp source: name: techvault-red-mcp-sources - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-red-mcp-sources-requirement explicitness: exact exact_artifact: artifact_id: techvault-red-mcp-sources - version: 0.1.0 + version: 0.1.1 digest: sha256:3536a2fd58eab9a2bfdc0ad90be4fdfd45bba9db1ef4acb5a54ff76126e7788e media_type: application/x-tar permitted_routes: @@ -3220,13 +3220,13 @@ content: destination: /opt/techvault/mcp source: name: techvault-blue-mcp-sources - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-blue-mcp-sources-requirement explicitness: exact exact_artifact: artifact_id: techvault-blue-mcp-sources - version: 0.1.0 + version: 0.1.1 digest: sha256:74e850e04e5e428cc0bb4cd5e4a6480373cd1e9a2a686fb40a0e560cd941f111 media_type: application/x-tar permitted_routes: @@ -3477,7 +3477,6 @@ evidence_requirements: boundary_kind: system_under_test channel: log artifact_role: network_detection_rule_readiness - media_types: [text/plain] sensitivity: plain redaction: redact_sensitive integrity: checksum @@ -3496,7 +3495,6 @@ evidence_requirements: boundary_kind: participant_equivalent channel: log artifact_role: network_detection_alert - media_types: [application/x-ndjson] sensitivity: plain redaction: redact_sensitive integrity: checksum @@ -3513,7 +3511,6 @@ evidence_requirements: window: the full run, from range readiness through teardown channel: participant_output artifact_role: participant_session_transcript - media_types: [text/plain] sensitivity: plain redaction: redact_secrets integrity: chain_of_custody @@ -3626,12 +3623,12 @@ entities: description: Defensive participant operating from the SOC workstation. agents: study-controller: - entity: study-control + affiliations: [study-control] description: Controller for the authored participant start and stop directions. authority_anchors: [entities.study-control] operating_scope: [nodes.kali, nodes.soc-workstation] red-team-operator: - entity: red-team + affiliations: [red-team] description: Claude Code red-team participant working from the Kali host. authority_anchors: [entities.red-team] operating_scope: [nodes.kali, nodes.webapp] @@ -3641,7 +3638,7 @@ agents: target_ref: kali channel: ssh blue-team-operator: - entity: blue-team + affiliations: [blue-team] description: Claude Code blue-team participant using the defensive stdio MCP tools from the SOC workstation. authority_anchors: [entities.blue-team] operating_scope: [nodes.soc-workstation, nodes.wazuh-manager, nodes.suricata, nodes.webapp] diff --git a/packs/techvault/associated-artifacts.json b/packs/techvault/associated-artifacts.json index 2835eca..36284ae 100644 --- a/packs/techvault/associated-artifacts.json +++ b/packs/techvault/associated-artifacts.json @@ -1,7 +1,7 @@ { "schema_version": "associated-artifact-manifest/v1", "manifest_id": "techvault-associated-artifacts", - "manifest_version": "0.1.0", + "manifest_version": "0.1.1", "canonicalization_profile": "associated-artifact-set/v1", "scope": "scenario", "parent_ref": { @@ -547,7 +547,7 @@ "uri": "raes-environment-pack:/pack.compatibility.yaml", "checksum": { "algorithm": "sha256", - "value": "bdd9b049c9ef59f9df38db2b9dd6eeb6096323c01349581f164663098099c076" + "value": "f5ba62b49f72ccaade1560f8e70a78053d5fbd4dd507f8e3f2e425b78b044967" }, "size_bytes": 1571, "created_at": "2026-08-02T00:00:00Z", @@ -563,7 +563,7 @@ "uri": "raes-environment-pack:/pack.yaml", "checksum": { "algorithm": "sha256", - "value": "57533d1e95793afddacdfded33f89e2c0b068b89bd6e58b3545782924e34990a" + "value": "c3fa3e8ce917ae78c606d25a1ffe7bc4d06f5f65403735412bbb6c79c3e0c9b4" }, "size_bytes": 542, "created_at": "2026-08-02T00:00:00Z", @@ -595,7 +595,7 @@ "uri": "raes-environment-pack:/sdl/techvault.bindings.json", "checksum": { "algorithm": "sha256", - "value": "b3a0bf1067bec5f2784713494b32daa6338fe3abaa48a925ec7aeaac1916fe2b" + "value": "007b85f63ec0b1e2904942fcbc2bb0f94648f68e7e460561ac047ccbec95eda4" }, "size_bytes": 44611, "created_at": "2026-09-13T00:00:00Z", @@ -627,9 +627,9 @@ "uri": "raes-environment-pack:/sdl/techvault.sdl.yaml", "checksum": { "algorithm": "sha256", - "value": "664001b66088d2370f088ed660c0e917557277c7d6f417d200cc1911af60ee88" + "value": "e9ba7711835219a46a1886fe7b52f56a32e80b9b0a255401f218d1732dd9ef5f" }, - "size_bytes": 141686, + "size_bytes": 141602, "created_at": "2026-08-02T00:00:00Z", "source": "environment-pack-author", "satisfies_refs": [], @@ -733,5 +733,5 @@ "description": "Exact defensive stdio MCP source packages for the SOC workstation." } }, - "set_digest": "sha256:db98a9daa62a092a0c6b001217027d7f4ad489889e95d01050e77f148e8ef29b" + "set_digest": "sha256:df00ea2a2672864ad8c711a3eab3a8a7bffff4db058b4a9acde032a61b2a1504" } diff --git a/packs/techvault/pack.compatibility.yaml b/packs/techvault/pack.compatibility.yaml index 6163d2a..87ee82d 100644 --- a/packs/techvault/pack.compatibility.yaml +++ b/packs/techvault/pack.compatibility.yaml @@ -2,7 +2,7 @@ schema_version: "environment-pack-compatibility/v2" pack: name: techvault title: TechVault - version: 0.1.0 + version: 0.1.1 status: built provenance_ledger: docs/provenance-ledger.yaml source: diff --git a/packs/techvault/pack.yaml b/packs/techvault/pack.yaml index 4619422..9fa583c 100644 --- a/packs/techvault/pack.yaml +++ b/packs/techvault/pack.yaml @@ -1,6 +1,6 @@ name: techvault title: TechVault -version: 0.1.0 +version: 0.1.1 status: built description: >- A complete enterprise intrusion scenario spanning a vulnerable customer diff --git a/packs/techvault/sdl/techvault.bindings.json b/packs/techvault/sdl/techvault.bindings.json index 97c99f0..1c189f7 100644 --- a/packs/techvault/sdl/techvault.bindings.json +++ b/packs/techvault/sdl/techvault.bindings.json @@ -10,7 +10,7 @@ "owning_contract_id": "sdl-authoring-input-v1", "lifecycle_phase": "normalized-authoring", "canonical_ref": "nodes.webapp.runtime.applications.techvault-portal.routes.ping-tool", - "artifact_digest": "sha256:7ae738c5c6ac7a6c8685adaaa8623dea412b6c33614a1d8c3e6d2ce7b28cbb69" + "artifact_digest": "sha256:b705580d343537c7bf3c7ef76ec4b2b1f8b832984b4b8b16106ea8ee536e955d" }, "scheme": { "scheme_id": "mitre-cwe", @@ -87,7 +87,7 @@ "owning_contract_id": "sdl-authoring-input-v1", "lifecycle_phase": "normalized-authoring", "canonical_ref": "nodes.webapp.runtime.applications.techvault-portal.routes.debug", - "artifact_digest": "sha256:7ae738c5c6ac7a6c8685adaaa8623dea412b6c33614a1d8c3e6d2ce7b28cbb69" + "artifact_digest": "sha256:b705580d343537c7bf3c7ef76ec4b2b1f8b832984b4b8b16106ea8ee536e955d" }, "scheme": { "scheme_id": "mitre-cwe", @@ -164,7 +164,7 @@ "owning_contract_id": "sdl-authoring-input-v1", "lifecycle_phase": "normalized-authoring", "canonical_ref": "nodes.webapp.runtime.applications.techvault-portal.routes.debug", - "artifact_digest": "sha256:7ae738c5c6ac7a6c8685adaaa8623dea412b6c33614a1d8c3e6d2ce7b28cbb69" + "artifact_digest": "sha256:b705580d343537c7bf3c7ef76ec4b2b1f8b832984b4b8b16106ea8ee536e955d" }, "scheme": { "scheme_id": "mitre-cwe", @@ -241,7 +241,7 @@ "owning_contract_id": "sdl-authoring-input-v1", "lifecycle_phase": "normalized-authoring", "canonical_ref": "nodes.webapp.runtime.applications.techvault-portal.routes.api-token", - "artifact_digest": "sha256:7ae738c5c6ac7a6c8685adaaa8623dea412b6c33614a1d8c3e6d2ce7b28cbb69" + "artifact_digest": "sha256:b705580d343537c7bf3c7ef76ec4b2b1f8b832984b4b8b16106ea8ee536e955d" }, "scheme": { "scheme_id": "mitre-cwe", @@ -318,7 +318,7 @@ "owning_contract_id": "sdl-authoring-input-v1", "lifecycle_phase": "normalized-authoring", "canonical_ref": "nodes.webapp.runtime.applications.techvault-portal.routes.api-file", - "artifact_digest": "sha256:7ae738c5c6ac7a6c8685adaaa8623dea412b6c33614a1d8c3e6d2ce7b28cbb69" + "artifact_digest": "sha256:b705580d343537c7bf3c7ef76ec4b2b1f8b832984b4b8b16106ea8ee536e955d" }, "scheme": { "scheme_id": "mitre-cwe", @@ -395,7 +395,7 @@ "owning_contract_id": "sdl-authoring-input-v1", "lifecycle_phase": "normalized-authoring", "canonical_ref": "nodes.webapp.runtime.applications.techvault-portal.routes.api-user", - "artifact_digest": "sha256:7ae738c5c6ac7a6c8685adaaa8623dea412b6c33614a1d8c3e6d2ce7b28cbb69" + "artifact_digest": "sha256:b705580d343537c7bf3c7ef76ec4b2b1f8b832984b4b8b16106ea8ee536e955d" }, "scheme": { "scheme_id": "mitre-cwe", @@ -472,7 +472,7 @@ "owning_contract_id": "sdl-authoring-input-v1", "lifecycle_phase": "normalized-authoring", "canonical_ref": "nodes.webapp.runtime.applications.techvault-portal.routes.admin", - "artifact_digest": "sha256:7ae738c5c6ac7a6c8685adaaa8623dea412b6c33614a1d8c3e6d2ce7b28cbb69" + "artifact_digest": "sha256:b705580d343537c7bf3c7ef76ec4b2b1f8b832984b4b8b16106ea8ee536e955d" }, "scheme": { "scheme_id": "mitre-cwe", @@ -549,7 +549,7 @@ "owning_contract_id": "sdl-authoring-input-v1", "lifecycle_phase": "normalized-authoring", "canonical_ref": "nodes.webapp.runtime.applications.techvault-portal.routes.login", - "artifact_digest": "sha256:7ae738c5c6ac7a6c8685adaaa8623dea412b6c33614a1d8c3e6d2ce7b28cbb69" + "artifact_digest": "sha256:b705580d343537c7bf3c7ef76ec4b2b1f8b832984b4b8b16106ea8ee536e955d" }, "scheme": { "scheme_id": "mitre-cwe", @@ -626,7 +626,7 @@ "owning_contract_id": "sdl-authoring-input-v1", "lifecycle_phase": "normalized-authoring", "canonical_ref": "nodes.webapp.runtime.applications.techvault-portal.routes.search", - "artifact_digest": "sha256:7ae738c5c6ac7a6c8685adaaa8623dea412b6c33614a1d8c3e6d2ce7b28cbb69" + "artifact_digest": "sha256:b705580d343537c7bf3c7ef76ec4b2b1f8b832984b4b8b16106ea8ee536e955d" }, "scheme": { "scheme_id": "mitre-cwe", @@ -703,7 +703,7 @@ "owning_contract_id": "sdl-authoring-input-v1", "lifecycle_phase": "normalized-authoring", "canonical_ref": "nodes.webapp.runtime.applications.techvault-portal.routes.upload", - "artifact_digest": "sha256:7ae738c5c6ac7a6c8685adaaa8623dea412b6c33614a1d8c3e6d2ce7b28cbb69" + "artifact_digest": "sha256:b705580d343537c7bf3c7ef76ec4b2b1f8b832984b4b8b16106ea8ee536e955d" }, "scheme": { "scheme_id": "mitre-cwe", @@ -780,7 +780,7 @@ "owning_contract_id": "sdl-authoring-input-v1", "lifecycle_phase": "normalized-authoring", "canonical_ref": "nodes.webapp.runtime.applications.techvault-portal.routes.login", - "artifact_digest": "sha256:7ae738c5c6ac7a6c8685adaaa8623dea412b6c33614a1d8c3e6d2ce7b28cbb69" + "artifact_digest": "sha256:b705580d343537c7bf3c7ef76ec4b2b1f8b832984b4b8b16106ea8ee536e955d" }, "scheme": { "scheme_id": "mitre-cwe", @@ -857,7 +857,7 @@ "owning_contract_id": "sdl-authoring-input-v1", "lifecycle_phase": "normalized-authoring", "canonical_ref": "nodes.webapp.runtime.applications.techvault-portal.routes.api-token", - "artifact_digest": "sha256:7ae738c5c6ac7a6c8685adaaa8623dea412b6c33614a1d8c3e6d2ce7b28cbb69" + "artifact_digest": "sha256:b705580d343537c7bf3c7ef76ec4b2b1f8b832984b4b8b16106ea8ee536e955d" }, "scheme": { "scheme_id": "mitre-cwe", @@ -934,7 +934,7 @@ "owning_contract_id": "sdl-authoring-input-v1", "lifecycle_phase": "normalized-authoring", "canonical_ref": "nodes.webapp.runtime.applications.techvault-portal.routes.search", - "artifact_digest": "sha256:7ae738c5c6ac7a6c8685adaaa8623dea412b6c33614a1d8c3e6d2ce7b28cbb69" + "artifact_digest": "sha256:b705580d343537c7bf3c7ef76ec4b2b1f8b832984b4b8b16106ea8ee536e955d" }, "scheme": { "scheme_id": "mitre-cwe", @@ -1011,7 +1011,7 @@ "owning_contract_id": "sdl-authoring-input-v1", "lifecycle_phase": "normalized-authoring", "canonical_ref": "nodes.webapp.runtime.applications.techvault-portal.routes.comment", - "artifact_digest": "sha256:7ae738c5c6ac7a6c8685adaaa8623dea412b6c33614a1d8c3e6d2ce7b28cbb69" + "artifact_digest": "sha256:b705580d343537c7bf3c7ef76ec4b2b1f8b832984b4b8b16106ea8ee536e955d" }, "scheme": { "scheme_id": "mitre-cwe", diff --git a/packs/techvault/sdl/techvault.sdl.yaml b/packs/techvault/sdl/techvault.sdl.yaml index b1b7ce3..6200e6a 100644 --- a/packs/techvault/sdl/techvault.sdl.yaml +++ b/packs/techvault/sdl/techvault.sdl.yaml @@ -2475,13 +2475,13 @@ content: path: /var/ossec/etc/rules/webapp_rules.xml source: name: techvault-wazuh-webapp-rules - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-wazuh-webapp-rules-requirement explicitness: exact exact_artifact: artifact_id: techvault-wazuh-webapp-rules - version: 0.1.0 + version: 0.1.1 digest: sha256:67db59b11e89ee2fca6515ce6ae2c433793a12aea5510355af0858e66cc2a844 media_type: application/xml permitted_routes: @@ -2498,13 +2498,13 @@ content: path: /var/ossec/etc/rules/suricata_rules.xml source: name: techvault-wazuh-suricata-rules - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-wazuh-suricata-rules-requirement explicitness: exact exact_artifact: artifact_id: techvault-wazuh-suricata-rules - version: 0.1.0 + version: 0.1.1 digest: sha256:b1fdf64371c5ea24f8e1ce47ea2d0aba185f2f6697702c4bb092c2f3d696547c media_type: application/xml permitted_routes: @@ -2517,13 +2517,13 @@ content: path: /var/ossec/etc/rules/ad_rules.xml source: name: techvault-wazuh-ad-rules - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-wazuh-ad-rules-requirement explicitness: exact exact_artifact: artifact_id: techvault-wazuh-ad-rules - version: 0.1.0 + version: 0.1.1 digest: sha256:8fdb8953d8e774c928adc6cef1a2eb06ef219b6feedc519092c0f1ca33cdc10b media_type: application/xml permitted_routes: @@ -2536,13 +2536,13 @@ content: path: /var/ossec/etc/rules/database_rules.xml source: name: techvault-wazuh-database-rules - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-wazuh-database-rules-requirement explicitness: exact exact_artifact: artifact_id: techvault-wazuh-database-rules - version: 0.1.0 + version: 0.1.1 digest: sha256:3799f8319eaf0da79c2c2a6e9468750122e6afcc715ee8095870ce750e366e15 media_type: application/xml permitted_routes: @@ -2555,13 +2555,13 @@ content: path: /var/ossec/etc/rules/falco_rules.xml source: name: techvault-wazuh-falco-rules - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-wazuh-falco-rules-requirement explicitness: exact exact_artifact: artifact_id: techvault-wazuh-falco-rules - version: 0.1.0 + version: 0.1.1 digest: sha256:b5bfba268ac98b2046322c5b363d628083bf4f935aa56daa2f6264fbf93ffeb4 media_type: application/xml permitted_routes: @@ -2574,13 +2574,13 @@ content: path: /var/ossec/etc/decoders/postgresql_decoders.xml source: name: techvault-wazuh-postgresql-decoders - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-wazuh-postgresql-decoders-requirement explicitness: exact exact_artifact: artifact_id: techvault-wazuh-postgresql-decoders - version: 0.1.0 + version: 0.1.1 digest: sha256:dd72b3d2a2912a0fca61b2d3c69e08deafce6821b357106ad90023965de1757a media_type: application/xml permitted_routes: @@ -2593,13 +2593,13 @@ content: path: /var/ossec/etc/decoders/samba_decoders.xml source: name: techvault-wazuh-samba-decoders - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-wazuh-samba-decoders-requirement explicitness: exact exact_artifact: artifact_id: techvault-wazuh-samba-decoders - version: 0.1.0 + version: 0.1.1 digest: sha256:acf2c9fd0d6f0816c7791544c2a580ad0124039105f37c4fffc494ae04f7ffe7 media_type: application/xml permitted_routes: @@ -2612,13 +2612,13 @@ content: destination: /var/ossec/integrations source: name: techvault-wazuh-integrations - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-wazuh-integrations-requirement explicitness: exact exact_artifact: artifact_id: techvault-wazuh-integrations - version: 0.1.0 + version: 0.1.1 digest: sha256:7c6afe833433bd6674b390cf09d23808bd7b0427927bcb533b067d674d08e417 media_type: application/x-tar permitted_routes: @@ -2631,13 +2631,13 @@ content: path: /etc/suricata/suricata.yaml source: name: techvault-suricata-config - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-suricata-config-requirement explicitness: exact exact_artifact: artifact_id: techvault-suricata-config - version: 0.1.0 + version: 0.1.1 digest: sha256:d1bf43326da10781b8b20c10c78ad2bbbc25a64c50019fd7933a56bb52b42471 media_type: application/yaml permitted_routes: @@ -2654,13 +2654,13 @@ content: path: /etc/suricata/rules/local.rules source: name: techvault-suricata-local-rules - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-suricata-local-rules-requirement explicitness: exact exact_artifact: artifact_id: techvault-suricata-local-rules - version: 0.1.0 + version: 0.1.1 digest: sha256:c453a657ff6aba3bc756432c2300bffb6602532f6099236ddfbd17d091d2add4 media_type: text/plain permitted_routes: @@ -2673,13 +2673,13 @@ content: path: /var/lib/suricata/rules/misp/misp-iocs.rules source: name: techvault-suricata-misp-ioc-rules-seed - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-suricata-misp-ioc-rules-seed-requirement explicitness: exact exact_artifact: artifact_id: techvault-suricata-misp-ioc-rules-seed - version: 0.1.0 + version: 0.1.1 digest: sha256:462aecd67796a9ff9acd80e2bb2e9e597f05bfb05892c0766110bca933a30ede media_type: text/plain permitted_routes: @@ -2692,13 +2692,13 @@ content: path: /var/lib/suricata/rules/misp/misp-md5.list source: name: techvault-suricata-misp-md5-seed - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-suricata-misp-md5-seed-requirement explicitness: exact exact_artifact: artifact_id: techvault-suricata-misp-md5-seed - version: 0.1.0 + version: 0.1.1 digest: sha256:66be1ef4237386fd2e34a978fc245bb2030641fd76409062d72919954830f376 media_type: text/plain permitted_routes: @@ -2711,13 +2711,13 @@ content: path: /var/lib/suricata/rules/misp/misp-sha1.list source: name: techvault-suricata-misp-sha1-seed - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-suricata-misp-sha1-seed-requirement explicitness: exact exact_artifact: artifact_id: techvault-suricata-misp-sha1-seed - version: 0.1.0 + version: 0.1.1 digest: sha256:d91e7c095d162c8efb5ff55389043cf429809899df45f32f931f5d2eae381f0c media_type: text/plain permitted_routes: @@ -2730,13 +2730,13 @@ content: path: /var/lib/suricata/rules/misp/misp-sha256.list source: name: techvault-suricata-misp-sha256-seed - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-suricata-misp-sha256-seed-requirement explicitness: exact exact_artifact: artifact_id: techvault-suricata-misp-sha256-seed - version: 0.1.0 + version: 0.1.1 digest: sha256:b059ca012bd1345811fb9aae5e7a758498b33063887b092956bd083e41fa85dd media_type: text/plain permitted_routes: @@ -2764,13 +2764,13 @@ content: path: /opt/techvault/cortex-analyzers/TechVaultScenarioContext/analyzer.json source: name: techvault-cortex-analyzer-definition - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-cortex-analyzer-definition-requirement explicitness: exact exact_artifact: artifact_id: techvault-cortex-analyzer-definition - version: 0.1.0 + version: 0.1.1 digest: sha256:9c8bfce7a9b41ed10f549e1d841879ec350a3ea1b4b03b6658313255ef435970 media_type: application/json permitted_routes: @@ -2787,13 +2787,13 @@ content: path: /opt/techvault/cortex-analyzers/TechVaultScenarioContext/techvault_scenario_context.py source: name: techvault-cortex-analyzer-executable - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-cortex-analyzer-executable-requirement explicitness: exact exact_artifact: artifact_id: techvault-cortex-analyzer-executable - version: 0.1.0 + version: 0.1.1 digest: sha256:ce6962465bc7bdd6394b4df3785685a8cf32f22689671dfda644540ffc51f152 media_type: text/x-python permitted_routes: @@ -2810,13 +2810,13 @@ content: path: /app/pyproject.toml source: name: techvault-misp-sync-pyproject - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-misp-sync-pyproject-requirement explicitness: exact exact_artifact: artifact_id: techvault-misp-sync-pyproject - version: 0.1.0 + version: 0.1.1 digest: sha256:0e7214cdacc8f396e91360782c9aaf6d8c6523d2fb944cfcd3763c4ac996450f media_type: text/x-toml permitted_routes: @@ -2833,13 +2833,13 @@ content: path: /app/README.md source: name: techvault-misp-sync-readme - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-misp-sync-readme-requirement explicitness: exact exact_artifact: artifact_id: techvault-misp-sync-readme - version: 0.1.0 + version: 0.1.1 digest: sha256:07c3dee4987c47e57bc8f0333073abdc07b832a7e82136c3123577531978231b media_type: text/markdown permitted_routes: @@ -2856,13 +2856,13 @@ content: path: /app/hatch_build.py source: name: techvault-misp-sync-hatch-build - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-misp-sync-hatch-build-requirement explicitness: exact exact_artifact: artifact_id: techvault-misp-sync-hatch-build - version: 0.1.0 + version: 0.1.1 digest: sha256:975022d60fe6f5187b169d3e20932fd6c242dc1658f59232627eab7e75bf713c media_type: text/x-python permitted_routes: @@ -2879,13 +2879,13 @@ content: destination: /app/src source: name: techvault-misp-sync-src - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-misp-sync-src-requirement explicitness: exact exact_artifact: artifact_id: techvault-misp-sync-src - version: 0.1.0 + version: 0.1.1 digest: sha256:c872e56e963934883190f7fed307116504c39d6771a528852a8b4e27682e8b91 media_type: application/x-tar permitted_routes: @@ -2902,13 +2902,13 @@ content: destination: /app source: name: techvault-webapp-app - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-webapp-app-requirement explicitness: exact exact_artifact: artifact_id: techvault-webapp-app - version: 0.1.0 + version: 0.1.1 digest: sha256:521886364d4cb8bf4f6b3be05bf5598cba182b27a7ee4715ae0dc518134f4101 media_type: application/x-tar permitted_routes: @@ -2925,13 +2925,13 @@ content: path: /etc/bind/named.conf source: name: techvault-dns-named-conf - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-dns-named-conf-requirement explicitness: exact exact_artifact: artifact_id: techvault-dns-named-conf - version: 0.1.0 + version: 0.1.1 digest: sha256:3df85c5e388295b0e321598c9932a78bfb18e47315263c6990e9e36cb1b62ee7 media_type: text/plain permitted_routes: @@ -2948,13 +2948,13 @@ content: path: /etc/bind/zones/techvault.local.zone source: name: techvault-dns-forward-zone - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-dns-forward-zone-requirement explicitness: exact exact_artifact: artifact_id: techvault-dns-forward-zone - version: 0.1.0 + version: 0.1.1 digest: sha256:d12de977f09275e342454a58ca004f7909ff808c29143b4c6d4ecb14db611a82 media_type: text/plain permitted_routes: @@ -2971,13 +2971,13 @@ content: path: /etc/bind/zones/172.20.rev source: name: techvault-dns-reverse-zone - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-dns-reverse-zone-requirement explicitness: exact exact_artifact: artifact_id: techvault-dns-reverse-zone - version: 0.1.0 + version: 0.1.1 digest: sha256:ceb577f74bf3841ee10dae1a35e07afb921f9136bd4f9dbbd60d4afd1a4f0a02 media_type: text/plain permitted_routes: @@ -2994,13 +2994,13 @@ content: path: /etc/samba/smb.conf source: name: techvault-fileshare-smb-conf - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-fileshare-smb-conf-requirement explicitness: exact exact_artifact: artifact_id: techvault-fileshare-smb-conf - version: 0.1.0 + version: 0.1.1 digest: sha256:847edd4733cb764eba178c933831bf1af2359cd9042674994f70b91491a289e0 media_type: text/plain permitted_routes: @@ -3023,13 +3023,13 @@ content: destination: /srv/shares source: name: techvault-fileshare-shares - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-fileshare-shares-requirement explicitness: exact exact_artifact: artifact_id: techvault-fileshare-shares - version: 0.1.0 + version: 0.1.1 digest: sha256:342bc178915bd1fc8d84d2a57511175ad386eec08ac2830b9757c8dc2847e726 media_type: application/x-tar permitted_routes: @@ -3050,13 +3050,13 @@ content: destination: /home/dev-user source: name: techvault-workstation-dev-user-home - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-workstation-dev-user-home-requirement explicitness: exact exact_artifact: artifact_id: techvault-workstation-dev-user-home - version: 0.1.0 + version: 0.1.1 digest: sha256:a1a4f93fe5783a0ed1caf7c7bb78c1fae1506d4ab5eef34464f43b4e4884b4b7 media_type: application/x-tar permitted_routes: @@ -3080,13 +3080,13 @@ content: path: /opt/db-init/01-schema.sql source: name: techvault-db-init-schema - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-db-init-schema-requirement explicitness: exact exact_artifact: artifact_id: techvault-db-init-schema - version: 0.1.0 + version: 0.1.1 digest: sha256:7a1748928d6222db2e3877ec8f6599ec7e1aec8c2956d2842b8e49e146c52981 media_type: application/sql permitted_routes: @@ -3103,13 +3103,13 @@ content: path: /opt/db-init/02-seed-data.sql source: name: techvault-db-init-seed - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-db-init-seed-requirement explicitness: exact exact_artifact: artifact_id: techvault-db-init-seed - version: 0.1.0 + version: 0.1.1 digest: sha256:c98ab23427180f604ca9ccec5a00b426dc8d883a4102bbba24e76d5cda0f03dc media_type: application/sql permitted_routes: @@ -3197,13 +3197,13 @@ content: destination: /opt/techvault/mcp source: name: techvault-red-mcp-sources - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-red-mcp-sources-requirement explicitness: exact exact_artifact: artifact_id: techvault-red-mcp-sources - version: 0.1.0 + version: 0.1.1 digest: sha256:3536a2fd58eab9a2bfdc0ad90be4fdfd45bba9db1ef4acb5a54ff76126e7788e media_type: application/x-tar permitted_routes: @@ -3220,13 +3220,13 @@ content: destination: /opt/techvault/mcp source: name: techvault-blue-mcp-sources - version: 0.1.0 + version: 0.1.1 artifact_requirement: requirement_id: techvault-blue-mcp-sources-requirement explicitness: exact exact_artifact: artifact_id: techvault-blue-mcp-sources - version: 0.1.0 + version: 0.1.1 digest: sha256:74e850e04e5e428cc0bb4cd5e4a6480373cd1e9a2a686fb40a0e560cd941f111 media_type: application/x-tar permitted_routes: @@ -3402,7 +3402,6 @@ evidence_requirements: boundary_kind: system_under_test channel: log artifact_role: network_detection_rule_readiness - media_types: [text/plain] sensitivity: plain redaction: redact_sensitive integrity: checksum @@ -3421,7 +3420,6 @@ evidence_requirements: boundary_kind: participant_equivalent channel: log artifact_role: network_detection_alert - media_types: [application/x-ndjson] sensitivity: plain redaction: redact_sensitive integrity: checksum @@ -3438,7 +3436,6 @@ evidence_requirements: window: the full run, from range readiness through teardown channel: participant_output artifact_role: participant_session_transcript - media_types: [text/plain] sensitivity: plain redaction: redact_secrets integrity: chain_of_custody @@ -3495,14 +3492,14 @@ entities: description: Defensive participant operating from the SOC workstation. agents: red-team-operator: - entity: red-team + affiliations: [red-team] description: Red-team participant working from the Kali host. interactive_access: kali-ssh: target_ref: kali channel: ssh blue-team-operator: - entity: blue-team + affiliations: [blue-team] description: Blue-team participant using the defensive stdio MCP tools from the SOC workstation. interactive_access: soc-workstation-ssh: diff --git a/pyproject.toml b/pyproject.toml index 68a85d7..19d6c86 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -23,12 +23,12 @@ classifiers = [ # raes is a hard, exactly-pinned dependency (ADR 0011): SDL is validated # *through RAES* (raes.parse_sdl_file), never a local restatement, and the # gate is fail-closed, so RAES cannot be optional. The pin tracks the latest -# compatibility-tested RAES release -- currently the 5.x SDL contract corpus. +# compatibility-tested RAES release -- currently the 6.x SDL contract corpus. # While those contracts are `stability: draft`, advancing the pin requires # compatibility tests against this package's validator and template, so a # downstream consumer resolves exactly the RAES runtime this release was # validated against. -dependencies = ["PyYAML>=6", "raes==5.0.0", "mcp>=2,<3", "jsonschema>=4", "anyio>=4,<5"] +dependencies = ["PyYAML>=6", "raes==6.0.1", "mcp>=2,<3", "jsonschema>=4", "anyio>=4,<5"] [project.urls] Homepage = "https://github.com/OpenRAE/env-packs" diff --git a/requirements/runtime.txt b/requirements/runtime.txt index 3563369..1bac53e 100644 --- a/requirements/runtime.txt +++ b/requirements/runtime.txt @@ -646,9 +646,9 @@ pyyaml==6.0.3 \ # raes-env-packs (pyproject.toml) # raes # uvicorn -raes==5.0.0 \ - --hash=sha256:4baa4f7addb1c6ed624ee6eeed961e41937a10512dccad86f8345f94d2389840 \ - --hash=sha256:6e36a11dcc05ba1dc4024b8ce927ddb68721b3658730517c9211fd7d7e88489f +raes==6.0.1 \ + --hash=sha256:3e97f42d42564acc1740757157ffd35a8c6373487845e987a314da54388a06c0 \ + --hash=sha256:8ab156fb1b9c1f0b467c08d98c0695403224ad3c6f2b7835e30b570f8741e67f # via raes-env-packs (pyproject.toml) referencing==0.37.0 \ --hash=sha256:381329a9f99628c9069361716891d34ad94af76e461dcb0335825aecc7692231 \ diff --git a/tests/test_distribution.py b/tests/test_distribution.py index 01e7ed8..9121014 100644 --- a/tests/test_distribution.py +++ b/tests/test_distribution.py @@ -6,16 +6,19 @@ import tempfile import unittest +import yaml + from raes_env_packs import distribution as dist from raes_env_packs import release _HERE = os.path.dirname(os.path.abspath(__file__)) _REPO = os.path.dirname(_HERE) _TECHVAULT = os.path.join(_REPO, "packs", "techvault") +with open(os.path.join(_TECHVAULT, "pack.yaml"), encoding="utf-8") as _pack_metadata: + _PACK_VERSION = yaml.safe_load(_pack_metadata)["version"] def _read_set_digest(evidence_dir: str) -> str: - import yaml with open(os.path.join(evidence_dir, "release.yaml"), encoding="utf-8") as fh: profile = yaml.safe_load(fh) return profile["release"]["source_set"]["set_digest"] @@ -30,7 +33,7 @@ def setUpModule() -> None: _STATE["out"] = tempfile.TemporaryDirectory() _meta, failures = release.build_release(_TECHVAULT, _STATE["out"].name, publish=True) assert not failures, failures - _STATE["evidence"] = os.path.join(_STATE["out"].name, "techvault-0.1.0") + _STATE["evidence"] = os.path.join(_STATE["out"].name, f"techvault-{_PACK_VERSION}") def tearDownModule() -> None: @@ -59,7 +62,7 @@ def test_lock_plan_surfaces_the_reproducible_subject(self) -> None: self.assertIn("lock_digest", plan.resolved) def test_publish_plan_classifies_signing_and_registry_effects(self) -> None: - selector = dist.Selector(repository="ghcr.io/openrae/env-packs/techvault", reference="0.1.0") + selector = dist.Selector(repository="ghcr.io/openrae/env-packs/techvault", reference=_PACK_VERSION) plan = dist.plan_publish(self.evidence, selector=selector) kinds = {effect.kind for effect in plan.effects} self.assertIn(dist.EFFECT_SIGNING, kinds) @@ -228,7 +231,7 @@ def test_install_apply_writes_the_target(self) -> None: def test_publish_cli_shows_the_plan(self) -> None: code, text, _ = self._run( ["publish", "--release", self.evidence, - "--repository", "ghcr.io/openrae/env-packs/techvault", "--reference", "0.1.0"]) + "--repository", "ghcr.io/openrae/env-packs/techvault", "--reference", _PACK_VERSION]) self.assertEqual(code, dist.EXIT_OK) self.assertIn("signing", text) diff --git a/tests/test_release_publish.py b/tests/test_release_publish.py index f5b3648..49d2526 100644 --- a/tests/test_release_publish.py +++ b/tests/test_release_publish.py @@ -15,6 +15,8 @@ _HERE = os.path.dirname(os.path.abspath(__file__)) _REPO = os.path.dirname(_HERE) _TECHVAULT = os.path.join(_REPO, "packs", "techvault") +with open(os.path.join(_TECHVAULT, "pack.yaml"), encoding="utf-8") as _pack_metadata: + _PACK_VERSION = yaml.safe_load(_pack_metadata)["version"] class LocalProjectionTests(unittest.TestCase): @@ -25,8 +27,8 @@ def test_local_projection_carries_v2_but_no_evidence(self) -> None: self.assertEqual(metadata["schema_version"], "environment-pack-publication/v2") self.assertNotIn("evidence", metadata) self.assertFalse( - os.path.exists(os.path.join(out, "techvault-0.1.0", - "techvault-0.1.0.cdx.json")) + os.path.exists(os.path.join(out, f"techvault-{_PACK_VERSION}", + f"techvault-{_PACK_VERSION}.cdx.json")) ) @@ -36,7 +38,7 @@ def setUpClass(cls) -> None: cls._out = tempfile.TemporaryDirectory() cls.metadata, cls.failures = release.build_release( _TECHVAULT, cls._out.name, publish=True) - cls.release_root = os.path.join(cls._out.name, "techvault-0.1.0") + cls.release_root = os.path.join(cls._out.name, f"techvault-{_PACK_VERSION}") @classmethod def tearDownClass(cls) -> None: @@ -51,13 +53,13 @@ def test_publish_succeeds_and_emits_evidence_block(self) -> None: self.assertEqual(evidence["builder"]["id"], release._builder_id()) def test_evidence_files_are_written_beside_the_views(self) -> None: - for name in ("techvault-0.1.0.cdx.json", "techvault-0.1.0.provenance.json", + for name in (f"techvault-{_PACK_VERSION}.cdx.json", f"techvault-{_PACK_VERSION}.provenance.json", "release.yaml"): self.assertTrue(os.path.isfile(os.path.join(self.release_root, name)), name) def test_written_sbom_digest_matches_the_evidence_reference(self) -> None: import hashlib - with open(os.path.join(self.release_root, "techvault-0.1.0.cdx.json"), "rb") as fh: + with open(os.path.join(self.release_root, f"techvault-{_PACK_VERSION}.cdx.json"), "rb") as fh: raw = fh.read() self.assertEqual( "sha256:" + hashlib.sha256(raw).hexdigest(), @@ -65,7 +67,7 @@ def test_written_sbom_digest_matches_the_evidence_reference(self) -> None: ) def test_sbom_covers_portable_content_without_backend_images(self) -> None: - with open(os.path.join(self.release_root, "techvault-0.1.0.cdx.json")) as fh: + with open(os.path.join(self.release_root, f"techvault-{_PACK_VERSION}.cdx.json")) as fh: doc = json.load(fh) self.assertEqual(doc["bomFormat"], "CycloneDX") self.assertGreaterEqual(len(doc["components"]), 30) @@ -79,21 +81,21 @@ def test_sbom_covers_portable_content_without_backend_images(self) -> None: self.assertIn("raes:associated-artifact-set-digest", props) def test_written_evidence_passes_its_own_consumer_gate(self) -> None: - with open(os.path.join(self.release_root, "techvault-0.1.0.cdx.json")) as fh: + with open(os.path.join(self.release_root, f"techvault-{_PACK_VERSION}.cdx.json")) as fh: sbom_doc = json.load(fh) - with open(os.path.join(self.release_root, "techvault-0.1.0.provenance.json")) as fh: + with open(os.path.join(self.release_root, f"techvault-{_PACK_VERSION}.provenance.json")) as fh: prov_doc = json.load(fh) set_digest = self.metadata["release"]["source_set"]["set_digest"] refs = frozenset(c["bom-ref"] for c in sbom_doc["components"]) self.assertEqual( sbom_module.validate_sbom_document( - sbom_doc, expected_name="techvault", expected_version="0.1.0", + sbom_doc, expected_name="techvault", expected_version=_PACK_VERSION, expected_set_digest=set_digest, expected_component_refs=refs), [], ) self.assertEqual( release_provenance.validate_release_provenance( - prov_doc, expected_name="techvault", expected_version="0.1.0", + prov_doc, expected_name="techvault", expected_version=_PACK_VERSION, expected_set_digest=set_digest, expected_sbom_digest=self.metadata["evidence"]["sbom"]["digest"]), [], diff --git a/tests/test_techvault_pack.py b/tests/test_techvault_pack.py index 626f045..4ebf10d 100644 --- a/tests/test_techvault_pack.py +++ b/tests/test_techvault_pack.py @@ -50,6 +50,7 @@ _ROOT = pathlib.Path(__file__).resolve().parents[1] _PACK = _ROOT / "packs" / "techvault" +_PACK_VERSION = yaml.safe_load((_PACK / "pack.yaml").read_text(encoding="utf-8"))["version"] _SDL = _PACK / "sdl" / "techvault.sdl.yaml" _BINDINGS = _PACK / "sdl" / "techvault.bindings.json" _SCHEMES = _PACK / "sdl" / "techvault.schemes.json" @@ -2147,7 +2148,7 @@ def test_content_sources_are_exact_resolvable_pack_artifacts(self) -> None: self.assertEqual(requirement["explicitness"], "exact") exact = requirement["exact_artifact"] self.assertEqual(exact["artifact_id"], artifact_id) - self.assertEqual(exact["version"], "0.1.0") + self.assertEqual(exact["version"], _PACK_VERSION) route = requirement["permitted_routes"] self.assertEqual(len(route), 1) @@ -2899,7 +2900,7 @@ def test_red_and_blue_agents_have_separate_workstations(self) -> None: for agent_id, (entity_id, target) in expected.items(): with self.subTest(agent=agent_id): agent = scenario.agents[agent_id] - self.assertEqual(agent.entity, entity_id) + self.assertEqual(agent.affiliations, [entity_id]) self.assertEqual( {(item.target_ref, item.channel.value) for item in agent.interactive_access.values()}, {(target, "ssh")}, @@ -3321,7 +3322,7 @@ def test_red_team_ssh_access_is_declared_not_proxied(self) -> None: scenario = parse_sdl_file(_SDL) self.assertEqual(scenario.entities["red-team"].role.value, "red") operator = scenario.agents["red-team-operator"] - self.assertEqual(operator.entity, "red-team") + self.assertEqual(operator.affiliations, ["red-team"]) self.assertEqual( { (access.target_ref, access.channel.value) diff --git a/tests/test_techvault_study_pack.py b/tests/test_techvault_study_pack.py index 31ea398..d2b568f 100644 --- a/tests/test_techvault_study_pack.py +++ b/tests/test_techvault_study_pack.py @@ -7,8 +7,9 @@ import unittest import yaml -from raes import instantiate_scenario, parse_sdl_file +from raes import admit_instantiated_scenario, instantiate_scenario, parse_sdl_file from raes_processor.compiler import compile_runtime_model +from raes_processor.compiler.time_model import time_model_contract_model from raes_env_packs import validate_pack from raes_env_packs.digest import pack_content_digest @@ -23,6 +24,10 @@ def test_study_pack_is_valid_and_has_distinct_identity(self) -> None: result = validate_pack(_STUDY) self.assertTrue(result.ok, result.errors) self.assertNotEqual(pack_content_digest(_BASE), pack_content_digest(_STUDY)) + for pack in (_BASE, _STUDY): + with self.subTest(pack=pack.name): + metadata = yaml.safe_load((pack / "pack.yaml").read_text()) + self.assertEqual(metadata["version"], "0.1.1") def test_study_preserves_techvault_and_adds_participant_sequence(self) -> None: base = yaml.safe_load((_BASE / "sdl/techvault.sdl.yaml").read_text()) @@ -59,7 +64,9 @@ def test_study_preserves_techvault_and_adds_participant_sequence(self) -> None: study_agents = study.pop("agents") base_agents = base.pop("agents") for name in ("red-team-operator", "blue-team-operator"): - self.assertEqual(study_agents[name]["entity"], base_agents[name]["entity"]) + self.assertEqual( + study_agents[name]["affiliations"], base_agents[name]["affiliations"] + ) self.assertEqual( study_agents[name]["interactive_access"], base_agents[name]["interactive_access"], @@ -96,6 +103,19 @@ def test_study_preserves_techvault_and_adds_participant_sequence(self) -> None: }) self.assertEqual(study, base) + def test_study_agents_use_admitted_affiliations(self) -> None: + scenario = parse_sdl_file( + _STUDY / "sdl/techvault-participant-study.sdl.yaml" + ) + expected = { + "study-controller": "study-control", + "red-team-operator": "red-team", + "blue-team-operator": "blue-team", + } + for name, entity in expected.items(): + with self.subTest(agent=name): + self.assertEqual(scenario.agents[name].affiliations, [entity]) + def test_participant_injects_compile_in_authored_order_for_claude(self) -> None: scenario = parse_sdl_file( _STUDY / "sdl/techvault-participant-study.sdl.yaml" @@ -104,15 +124,23 @@ def test_participant_injects_compile_in_authored_order_for_claude(self) -> None: scenario, {name: f"study-{name}" for name in scenario.variables}, ) + admit_instantiated_scenario(concrete) runtime = compile_runtime_model(concrete) + admitted_time = time_model_contract_model(runtime.time_model) + self.assertIsNotNone(admitted_time) expected = ( - ("red-participant-study", "start", "red-team-operator", "red-participant-start", 1), - ("red-participant-study", "stop", "red-team-operator", "red-participant-stop", 3), - ("blue-participant-study", "start", "blue-team-operator", "blue-participant-start", 5), - ("blue-participant-study", "stop", "blue-team-operator", "blue-participant-stop", 7), + ("red-participant-study", "start", "red-team-operator", + "red-participant-start", "red-participant-study-view", "nodes.kali", 1), + ("red-participant-study", "stop", "red-team-operator", + "red-participant-stop", "red-participant-study-view", "nodes.kali", 3), + ("blue-participant-study", "start", "blue-team-operator", + "blue-participant-start", "blue-participant-study-view", "nodes.soc-workstation", 5), + ("blue-participant-study", "stop", "blue-team-operator", + "blue-participant-stop", "blue-participant-study-view", "nodes.soc-workstation", 7), ) - for spec, delivery, participant, inject, order in expected: + self.assertEqual(len(runtime.participant_inject_deliveries), len(expected)) + for spec, delivery, participant, inject, boundary, scope, order in expected: with self.subTest(spec=spec, delivery=delivery): authored = scenario.behavior_specifications[spec] self.assertEqual( @@ -134,6 +162,26 @@ def test_participant_injects_compile_in_authored_order_for_claude(self) -> None: ) self.assertEqual(compiled.delivery_kind, "external-direction") self.assertEqual(compiled.control_effective_order, order) + self.assertEqual( + compiled.controller_address, "participant.behavior.study-controller" + ) + self.assertEqual(compiled.control_authority_scope_refs, (scope,)) + self.assertEqual( + compiled.observation_boundary_address, + f"participant.observation-boundary.{boundary}", + ) + self.assertEqual( + compiled.audience_scope_ref, f"audience.participant.{participant}" + ) + self.assertEqual(compiled.failure_disposition, "reject-no-delivery") + self.assertIn( + address, + { + subject + for constraint in admitted_time.temporal_constraints.values() + for subject in constraint.subject_addresses + }, + ) script = scenario.scripts["participant-study-sequence"] self.assertEqual( diff --git a/tests/test_verify.py b/tests/test_verify.py index 3318bdf..a391706 100644 --- a/tests/test_verify.py +++ b/tests/test_verify.py @@ -8,11 +8,15 @@ import tempfile import unittest +import yaml + from raes_env_packs import release, verify _HERE = os.path.dirname(os.path.abspath(__file__)) _REPO = os.path.dirname(_HERE) _TECHVAULT = os.path.join(_REPO, "packs", "techvault") +with open(os.path.join(_TECHVAULT, "pack.yaml"), encoding="utf-8") as _pack_metadata: + _PACK_VERSION = yaml.safe_load(_pack_metadata)["version"] _STATE: dict = {} @@ -24,7 +28,7 @@ def setUpModule() -> None: _STATE["out"] = tempfile.TemporaryDirectory() metadata, failures = release.build_release(_TECHVAULT, _STATE["out"].name, publish=True) assert not failures, failures - _STATE["release_dir"] = os.path.join(_STATE["out"].name, "techvault-0.1.0") + _STATE["release_dir"] = os.path.join(_STATE["out"].name, f"techvault-{_PACK_VERSION}") _STATE["evidence"] = verify.load_release_evidence(_STATE["release_dir"]) @@ -107,7 +111,7 @@ def test_missing_evidence_is_absent_and_not_accepted(self) -> None: with tempfile.TemporaryDirectory() as out: release.build_release(_TECHVAULT, out) # publish=False profile, sbom_doc, prov_doc = verify.load_release_evidence( - os.path.join(out, "techvault-0.1.0")) + os.path.join(out, f"techvault-{_PACK_VERSION}")) result = verify.verify_pack_release( _TECHVAULT, release_profile=profile, sbom_document=sbom_doc, provenance_document=prov_doc) diff --git a/uv.lock b/uv.lock index 1201d96..662e747 100644 --- a/uv.lock +++ b/uv.lock @@ -789,7 +789,7 @@ wheels = [ [[package]] name = "raes" -version = "5.0.0" +version = "6.0.1" source = { registry = "https://pypi.org/simple" } dependencies = [ { name = "asyncssh" }, @@ -813,9 +813,9 @@ dependencies = [ { name = "uvicorn", extra = ["standard"] }, { name = "z3-solver" }, ] -sdist = { url = "https://files.pythonhosted.org/packages/0b/e7/fab68f67647683fa59daa12dc54b01ea3e1471e635bbb58582a97f771cf7/raes-5.0.0.tar.gz", hash = "sha256:6e36a11dcc05ba1dc4024b8ce927ddb68721b3658730517c9211fd7d7e88489f", size = 4027545, upload-time = "2026-09-15T17:43:04.163Z" } +sdist = { url = "https://files.pythonhosted.org/packages/d1/a8/8084c4bfbb16ddb55805ad76f4e88da24d910b0996f90f4e42b9212bd055/raes-6.0.1.tar.gz", hash = "sha256:8ab156fb1b9c1f0b467c08d98c0695403224ad3c6f2b7835e30b570f8741e67f", size = 4734196, upload-time = "2026-10-02T05:30:40.629Z" } wheels = [ - { url = "https://files.pythonhosted.org/packages/bd/b0/ee0bf3bc377de6241588465f9b4f0a1a4176c5f9c963206aa972d7cae577/raes-5.0.0-py3-none-any.whl", hash = "sha256:4baa4f7addb1c6ed624ee6eeed961e41937a10512dccad86f8345f94d2389840", size = 3686176, upload-time = "2026-09-15T17:43:02.31Z" }, + { url = "https://files.pythonhosted.org/packages/99/9c/dff37d0c4f3ccf1abe58402dba4bf24e25cd1ed5ed9903765ccf3a64806b/raes-6.0.1-py3-none-any.whl", hash = "sha256:3e97f42d42564acc1740757157ffd35a8c6373487845e987a314da54388a06c0", size = 4298362, upload-time = "2026-10-02T05:30:38.606Z" }, ] [[package]] @@ -836,7 +836,7 @@ requires-dist = [ { name = "jsonschema", specifier = ">=4" }, { name = "mcp", specifier = ">=2,<3" }, { name = "pyyaml", specifier = ">=6" }, - { name = "raes", specifier = "==5.0.0" }, + { name = "raes", specifier = "==6.0.1" }, ] [[package]] From 23996a7bd94beb8afa89a43db610e62be0580c2f Mon Sep 17 00:00:00 2001 From: Brad Edwards Date: Sat, 3 Oct 2026 04:41:39 +0200 Subject: [PATCH 2/2] Fix vulnerable audit dependencies --- requirements/docs.txt | 12 ++++++------ requirements/pip-audit.txt | 6 +++--- requirements/runtime.txt | 6 +++--- uv.lock | 6 +++--- 4 files changed, 15 insertions(+), 15 deletions(-) diff --git a/requirements/docs.txt b/requirements/docs.txt index b0e0557..a2b2639 100644 --- a/requirements/docs.txt +++ b/requirements/docs.txt @@ -124,7 +124,7 @@ docutils==0.21.2 \ furo==2025.12.19 \ --hash=sha256:188d1f942037d8b37cd3985b955839fea62baa1730087dc29d157677c857e2a7 \ --hash=sha256:bb0ead5309f9500130665a26bee87693c41ce4dbdff864dbfb6b0dae4673d24f - # via -r docs.in + # via -r requirements/docs.in idna==3.18 \ --hash=sha256:7f952cbe720b688055e3f87de14f5c3e5fdaa8bc3928985c4077ca689de849a2 \ --hash=sha256:ffb385a7e039654cef1ab9ef32c6fafe283c0c0467bba1d9029738ce4a14a848 @@ -247,7 +247,7 @@ mdurl==0.1.2 \ myst-parser==5.1.0 \ --hash=sha256:9c91c52b3cdb4d94a6506e4fab4e2f296c7623a0da0dcbe6de1565c3dad67a8a \ --hash=sha256:ab69322dc6719dcc7f296479dbb70181b66df6ed315064f92dbc85c0e1bf2f02 - # via -r docs.in + # via -r requirements/docs.in packaging==26.2 \ --hash=sha256:5fc45236b9446107ff2415ce77c807cee2862cb6fac22b8a73826d0693b0980e \ --hash=sha256:ff452ff5a3e828ce110190feff1178bb1f2ea2281fa2075aadb987c2fb221661 @@ -354,7 +354,7 @@ sphinx==9.1.0 \ --hash=sha256:7741722357dd75f8190766926071fed3bdc211c74dd2d7d4df5404da95930ddb \ --hash=sha256:c84fdd4e782504495fe4f2c0b3413d6c2bf388589bb352d439b2a3bb99991978 # via - # -r docs.in + # -r requirements/docs.in # furo # myst-parser # sphinx-basic-ng @@ -390,7 +390,7 @@ typing-extensions==4.16.0 \ --hash=sha256:481caa481374e813c1b176ada14e97f1f67a4539ce9cfeb3f350d78d6370c2e8 \ --hash=sha256:dc983d19a509c94dba722ee6abd33940f7c05a89e243c47e907eb4db6f1a43e5 # via beautifulsoup4 -urllib3==2.7.0 \ - --hash=sha256:231e0ec3b63ceb14667c67be60f2f2c40a518cb38b03af60abc813da26505f4c \ - --hash=sha256:9fb4c81ebbb1ce9531cce37674bbc6f1360472bc18ca9a553ede278ef7276897 +urllib3==2.8.0 \ + --hash=sha256:0cf3cae568d36aa9576b28dfb35f11328f1cb974ca7647d9475ebb86c75ac6e3 \ + --hash=sha256:63bf2ead4c879426ebf22ef2a781eeb4aa3b4ae798a0435506f8687fd5bb9b63 # via requests diff --git a/requirements/pip-audit.txt b/requirements/pip-audit.txt index dc8c2b3..80ab9ea 100644 --- a/requirements/pip-audit.txt +++ b/requirements/pip-audit.txt @@ -419,7 +419,7 @@ typing-extensions==4.16.0 \ --hash=sha256:481caa481374e813c1b176ada14e97f1f67a4539ce9cfeb3f350d78d6370c2e8 \ --hash=sha256:dc983d19a509c94dba722ee6abd33940f7c05a89e243c47e907eb4db6f1a43e5 # via cyclonedx-python-lib -urllib3==2.7.0 \ - --hash=sha256:231e0ec3b63ceb14667c67be60f2f2c40a518cb38b03af60abc813da26505f4c \ - --hash=sha256:9fb4c81ebbb1ce9531cce37674bbc6f1360472bc18ca9a553ede278ef7276897 +urllib3==2.8.0 \ + --hash=sha256:0cf3cae568d36aa9576b28dfb35f11328f1cb974ca7647d9475ebb86c75ac6e3 \ + --hash=sha256:63bf2ead4c879426ebf22ef2a781eeb4aa3b4ae798a0435506f8687fd5bb9b63 # via requests diff --git a/requirements/runtime.txt b/requirements/runtime.txt index 1bac53e..b36a1b9 100644 --- a/requirements/runtime.txt +++ b/requirements/runtime.txt @@ -556,9 +556,9 @@ pygments==2.21.0 \ --hash=sha256:2363c69b61c4a97c838da3b130dcd6468f4848992b21a82f2a63ec34377137d9 \ --hash=sha256:610ca751c9bc2492b38eb9a38a7fbc93edbbb2d7182edaf34e66ae493dee5c8c # via rich -pyjwt==2.14.0 \ - --hash=sha256:77283c83fb56ecf566a886c757a714bc83668e38156de2cce8263302f42e0b86 \ - --hash=sha256:ad0cef71c756a56e74863c2919cf0985f72decbcfcb550ee2f422e7c62b5eedc +pyjwt==2.15.1 \ + --hash=sha256:42d59d631f7768a1028a64c7ff581a9bf7519804daf91fc5b6c56e30eec5e193 \ + --hash=sha256:4f259e80cdfb6b3fc18a7de51fd1ef9ec79652f25019bae68975ca2468a34df8 # via mcp python-dotenv==1.2.3 \ --hash=sha256:904552145e8bfed22162c09dab1c2b9b54fefa7b23ba780f4f26ca0316b0f0d9 \ diff --git a/uv.lock b/uv.lock index 662e747..462e2c9 100644 --- a/uv.lock +++ b/uv.lock @@ -680,11 +680,11 @@ wheels = [ [[package]] name = "pyjwt" -version = "2.13.0" +version = "2.15.1" source = { registry = "https://pypi.org/simple" } -sdist = { url = "https://files.pythonhosted.org/packages/3b/81/58d0ac84e1ef3a3843791d6954d94c0b33d526c75eeb1efbce9d0a4c4077/pyjwt-2.13.0.tar.gz", hash = "sha256:41571c89ca91598c79e8ef18a2d07367d4810fbbd6f637794879baf1b7703423", size = 107515, upload-time = "2026-05-21T19:54:36.618Z" } +sdist = { url = "https://files.pythonhosted.org/packages/43/ea/5194e52748b0da83d71e082d75496eaec6e58f419f5e184786ded517e6a9/pyjwt-2.15.1.tar.gz", hash = "sha256:4f259e80cdfb6b3fc18a7de51fd1ef9ec79652f25019bae68975ca2468a34df8", size = 121252, upload-time = "2026-09-28T18:40:42.598Z" } wheels = [ - { url = "https://files.pythonhosted.org/packages/a3/5e/ecf12fdb62546d64385c158514e9b2b671f7832108ef2ecd2020ce0af2d1/pyjwt-2.13.0-py3-none-any.whl", hash = "sha256:66adcc2aff09b3f1bbd95fc1e1577df8ac8723c978552fd43304c8a290ac5728", size = 31274, upload-time = "2026-05-21T19:54:35.362Z" }, + { url = "https://files.pythonhosted.org/packages/50/ca/44de4e75f8aadc457f0634be3b542815078ded46dca30efb960edeecad6e/pyjwt-2.15.1-py3-none-any.whl", hash = "sha256:42d59d631f7768a1028a64c7ff581a9bf7519804daf91fc5b6c56e30eec5e193", size = 33860, upload-time = "2026-09-28T18:40:41.429Z" }, ] [package.optional-dependencies]