{
  "schemaVersion": 1,
  "generatedAt": "2026-10-05T03:42:15.999Z",
  "passed": 26,
  "total": 26,
  "tests": [
    {
      "id": "P01",
      "description": "Export is denied even before fixing object access",
      "status": "PASS"
    },
    {
      "id": "P02",
      "description": "Missing object authorization exposes plaintext to diagnostics",
      "status": "PASS"
    },
    {
      "id": "P03",
      "description": "Fixed object policy rejects diagnostic reads",
      "status": "PASS"
    },
    {
      "id": "P04",
      "description": "Authorized analysis still reads its data",
      "status": "PASS"
    },
    {
      "id": "P05",
      "description": "Diagnostics may still query allowed status",
      "status": "PASS"
    },
    {
      "id": "P06",
      "description": "A claimed analysis role cannot override an issued diagnostic identity",
      "status": "PASS"
    },
    {
      "id": "P07",
      "description": "An unissued session is rejected",
      "status": "PASS"
    },
    {
      "id": "P08",
      "description": "An A-only principal cannot read project B",
      "status": "PASS"
    },
    {
      "id": "P09",
      "description": "Revocation rejects subsequent requests",
      "status": "PASS"
    },
    {
      "id": "P10",
      "description": "Export remains denied after the access fix",
      "status": "PASS"
    },
    {
      "id": "P11",
      "description": "DEK-A cannot authenticate project-B ciphertext",
      "status": "PASS"
    },
    {
      "id": "P12",
      "description": "Purpose separation changes derived keys",
      "status": "PASS"
    },
    {
      "id": "P13",
      "description": "Routine rewrapping preserves the DEK and data ciphertext",
      "status": "PASS"
    },
    {
      "id": "P14",
      "description": "Changing authenticated wrapper metadata fails",
      "status": "PASS"
    },
    {
      "id": "P15",
      "description": "Changing an authenticated object label fails",
      "status": "PASS"
    },
    {
      "id": "P16",
      "description": "Tampered ciphertext cannot produce an authenticated result",
      "status": "PASS"
    },
    {
      "id": "P17",
      "description": "An exposed DEK still opens copied old ciphertext",
      "status": "PASS"
    },
    {
      "id": "P18",
      "description": "The old DEK does not open data encrypted under a fresh DEK",
      "status": "PASS"
    },
    {
      "id": "P19",
      "description": "A known parent recomputes keys under new public labels",
      "status": "PASS"
    },
    {
      "id": "P20",
      "description": "A replacement chip root does not open the original wrapper",
      "status": "PASS"
    },
    {
      "id": "P21",
      "description": "A pre-existing authorized recovery path permits migration",
      "status": "PASS"
    },
    {
      "id": "P22",
      "description": "Deleting a local reference does not remove recovery capability",
      "status": "PASS"
    },
    {
      "id": "P23",
      "description": "Authentic old policy is rejected by trusted version state",
      "status": "PASS"
    },
    {
      "id": "P24",
      "description": "A compromised authorized program can use its existing rights",
      "status": "PASS"
    },
    {
      "id": "P25",
      "description": "Permission for A does not permit selecting B’s key",
      "status": "PASS"
    },
    {
      "id": "P26",
      "description": "Rewrapping cannot invalidate a stolen old KEK and wrapper",
      "status": "PASS"
    }
  ],
  "limitations": [
    "Synthetic data and random classroom keys only; no malware, production data or hardware.",
    "The harness supplies identity issuance, process isolation, trusted version state and recovery custody. A JavaScript WeakSet is not hardware isolation.",
    "Raw key fixtures exist for test oracles; this does not prove non-exportability, resistance to side channels, physical attacks or secure zeroization.",
    "AES-256-GCM uses a fresh random 96-bit nonce per seal; this is one authenticated wrapping example, not AES-KW / AES-KWP compliance.",
    "A local reference deletion is deliberately shown to be insufficient; memory copies and external backups are not erased."
  ],
  "sourceSha256": "52ad2f8735a7bbdfbbdac5cdc241ca26dc2bbe920d622db66107685b1ad438ae",
  "provenance": "Reconstructed 2026-10-05 from the existing lesson’s 26 named cases; the prior download URLs returned HTML and the original executable could not be found. New results are from this source, not a recovered historical run."
}
