From 8d4bd8d5467560be66184269a1f29586b0466b58 Mon Sep 17 00:00:00 2001 From: yhc <1964366186@qq.com> Date: Mon, 10 Aug 2026 20:33:17 +0800 Subject: [PATCH] docs: align field-journal template evidence fields with review_case.py contract (P2-1) - Evidence chain table gains severity/status columns plus a worked example - Add contract-alignment block: E-xxx heading rule, severity/status vocabularies, repro_command requirement, content_hash/artifact_path, linked_workitem, and the --verify-hashes --strict self-check command - Keeps Scope/Evidence/Finding headings so verify-routing-coherence Assert-Fields stays green --- skills/field-journal/_template.md | 20 +++++++++++++++++--- 1 file changed, 17 insertions(+), 3 deletions(-) diff --git a/skills/field-journal/_template.md b/skills/field-journal/_template.md index 20d4033..caf2646 100644 --- a/skills/field-journal/_template.md +++ b/skills/field-journal/_template.md @@ -26,9 +26,23 @@ ## Evidence 链摘要(脱敏) -| E-id | source_type | 可复用命令模式 | 关联 Finding | -|------|-------------|----------------|--------------| -| E-001 | | | F-001 | + +| E-id | severity | status | source_type | 可复用命令模式 | 关联 Finding | +|------|----------|--------|-------------|----------------|--------------| +| E-001 | info | observed | command | `checksec --file=./pwn1` | F-001 | +| E-002 | high | validated | command | `python3 exploit.py REMOTE` | F-001 | + +> **契约对齐(review_case.py)**:若本次 case 产出了独立证据目录(`evidence/E-xxx.md`), +> 每条证据须满足 `skills/case-review/scripts/review_case.py` 的字段契约,否则 `--strict` 校验会 FAIL: +> +> - 标题:`### E-xxx`(须与文件名一致,如 `E-001.md` → `### E-001`) +> - `- severity:` ∈ critical / high / medium / low / info / n/a +> - `- status:` ∈ observed / candidate / validated / false_positive / accepted_risk +> - `- repro_command:` 必填(离线场景在 notes 中注明 offline/离线 可豁免) +> - `- content_hash:` sha256 或 n/a;填 sha256 时配套 `- artifact_path:`(case 内相对路径) +> - `- linked_workitem:` 可选,WI-xxx 必须真实存在 +> +> 自检:`python skills/case-review/scripts/review_case.py --verify-hashes --strict` ## Finding / Path 摘要 - top_finding: