fix: restore constant card and Sigma highlighting

This commit is contained in:
imposter
2026-07-16 19:48:14 -06:00
parent 804429d9d1
commit a935d56d49
4 changed files with 17 additions and 4 deletions
+4 -4
View File
@@ -1879,10 +1879,10 @@ details.emulation-wrapper[open] .emulation-lang::after { content: ''; }
</div><!-- /.cp-page-wrap -->
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/highlight.js/11.10.0/styles/atom-one-dark.min.css" integrity="sha384-oaMLBGEzBOJx3UHwac0cVndtX5fxGQIfnAeFZ35RTgqPcYlbprH9o9PUV/F8Le07" crossorigin="anonymous" referrerpolicy="no-referrer" />
<script src="https://cdnjs.cloudflare.com/ajax/libs/highlight.js/11.10.0/highlight.min.js" integrity="sha384-GdEWAbCjn+ghjX0gLx7/N1hyTVmPAjdC2OvoAA0RyNcAOhqwtT8qnbCxWle2+uJX" crossorigin="anonymous" referrerpolicy="no-referrer"></script>
<script src="https://cdnjs.cloudflare.com/ajax/libs/highlight.js/11.10.0/languages/yaml.min.js" integrity="sha384-bMkvdnz+wPu1ro0fqO3BaDWztc7RzSvw05MQFP6bhJKDcwpkrFYTfTFI9ndkP11l" crossorigin="anonymous" referrerpolicy="no-referrer"></script>
<script src="https://cdnjs.cloudflare.com/ajax/libs/highlight.js/11.10.0/languages/powershell.min.js" integrity="sha384-0u0NM3ve01ej9h9zRzZ/ztDGe1h07d6TStpNoJ4f/50I/vtoCsDHI2PfzDZSYz8q" crossorigin="anonymous" referrerpolicy="no-referrer"></script>
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/highlight.js/11.11.1/styles/atom-one-dark.min.css" integrity="sha384-oaMLBGEzBOJx3UHwac0cVndtX5fxGQIfnAeFZ35RTgqPcYlbprH9o9PUV/F8Le07" crossorigin="anonymous" referrerpolicy="no-referrer" />
<script src="https://cdnjs.cloudflare.com/ajax/libs/highlight.js/11.11.1/highlight.min.js" integrity="sha384-RH2xi4eIQ/gjtbs9fUXM68sLSi99C7ZWBRX1vDrVv6GQXRibxXLbwO2NGZB74MbU" crossorigin="anonymous" referrerpolicy="no-referrer"></script>
<script src="https://cdnjs.cloudflare.com/ajax/libs/highlight.js/11.11.1/languages/yaml.min.js" integrity="sha384-A/iMReLA0Bo3tLydBIoOQXQzYnrwL90jkHYUubrtERUGCbIuU7U0EHge0Xd2s5sr" crossorigin="anonymous" referrerpolicy="no-referrer"></script>
<script src="https://cdnjs.cloudflare.com/ajax/libs/highlight.js/11.11.1/languages/powershell.min.js" integrity="sha384-q/8iVbv95DiFN+l7qeoBwJ0Wju7gozJemMfG3DdxiOR8CfA/2dKvKA3W5t4l/n9t" crossorigin="anonymous" referrerpolicy="no-referrer"></script>
<script>
document.addEventListener('DOMContentLoaded', function() {
hljs.highlightAll();
@@ -16,6 +16,7 @@ Description: >
the trusted host process. Host names, DLL names, directories, and delivery chains
vary, but successful DLL side-loading always produces a host-to-loaded-module
relationship that can be observed with image-load telemetry.
TheConstant: A trusted host must map the attacker-controlled DLL before its code can execute.
LastUpdated: '2026-07-16'
Author: '@iimp0ster'
+3
View File
@@ -63,6 +63,7 @@ def load_chokepoint(repo: Path, slug: str) -> tuple[Path, dict[str, Any]]:
def validate_contract_data(data: dict[str, Any], repo: Path) -> dict[str, str]:
hits = unknown_paths(data)
require(not hits, f"unknown placeholders remain at: {', '.join(hits)}")
require(data.get("TheConstant"), "a promoted chokepoint needs a top-level TheConstant for cards")
variations = data.get("Variations") or []
require(len(variations) >= 2, "a promoted chokepoint needs at least two variations")
@@ -171,6 +172,8 @@ def validate_rendered_page(repo: Path, slug: str, data: dict[str, Any]) -> Path:
require(html.escape(str(variation["Name"])) in rendered, f"rendered page is missing {variation['Name']}")
for pivot in data.get("OsintSources") or []:
require(html.escape(str(pivot["URL"]), quote=True) in rendered, f"rendered page is missing OSINT URL {pivot['URL']}")
require(html.escape(str(data["TheConstant"])) in rendered, "rendered page is missing TheConstant")
require("highlight.js/11.11.1/" in rendered, "rendered page needs Highlight.js 11.11.1 selector fix")
require('id="osint-pivots"' in rendered, "rendered page is missing the OSINT section")
require("<UNKNOWN" not in rendered.upper(), "rendered page contains an unknown placeholder")
return page
+9
View File
@@ -47,6 +47,12 @@ class TrustedBinaryDllSideloadingRegressionTests(unittest.TestCase):
with self.assertRaisesRegex(RegressionError, "at least two variations"):
validate_contract_data(mutated, REPO)
def test_missing_top_level_constant_is_rejected(self) -> None:
mutated = copy.deepcopy(self.data)
mutated.pop("TheConstant")
with self.assertRaisesRegex(RegressionError, "top-level TheConstant"):
validate_contract_data(mutated, REPO)
def test_unknown_placeholder_is_rejected(self) -> None:
mutated = copy.deepcopy(self.data)
mutated["Chokepoints"][0]["WhyCantBypass"] = "<UNKNOWN -- needs evidence>"
@@ -93,6 +99,9 @@ class TrustedBinaryDllSideloadingRegressionTests(unittest.TestCase):
def test_built_site_renders_variations_tiers_and_osint(self) -> None:
page = validate_rendered_page(REPO, SLUG, self.data)
self.assertTrue(page.is_file())
home = (REPO / "_site" / "index.html").read_text(encoding="utf-8")
self.assertIn("THE CONSTANT", home)
self.assertIn(self.data["TheConstant"], home)
if __name__ == "__main__":