Skip to content

fix(mtmt): restore .tm7 openability and close the ROOT differential - #75

Merged
Hacks4Snacks merged 2 commits into
mainfrom
hacks4snacks/mtmtroot
Jul 26, 2026
Merged

Hacks4Snacks merged 2 commits into
mainfrom
hacks4snacks/mtmtroot

Conversation

@Hacks4Snacks

Copy link
Copy Markdown
Owner

fix(mtmt): restore .tm7 openability and close the ROOT differential (CON-001)

What changed

1. .tm7 exports were unopenable in MTMT (regression, P0). KnowledgeBaseCatalog.AddThreatMetaData
replaced the knowledge base's whole ThreatMetaData block with a single Priority datum. MTMT resolves
six properties by name while loading (Title, UserThreatCategory, UserThreatShortDescription,
UserThreatDescription, StateInformation, InteractionString) and throws
ApplicationException: KnowledgeBase is missing a required Threat Property when any is absent — it
tolerates an absent block and a complete one, but refuses a partial one. New
ThreatMetaDataContract declares the full set mirroring the official template; Tm7ExportPreparer
now defers to a foreign template for all tool-owned properties instead of only Priority.

2. Coordinate normalization only honoured the lower bound. MTMT clamps both ways, and per element
kind: borders to 1890x2090, connector coordinates to 1990x2190. A wide or tall diagram still opened
with the "coordinates are corrupted" correction. NormalizeCoordinates now translates each surface to
satisfy both bounds. A surface larger than the canvas is anchored at the minimum rather than rescaled,
because scaling would move elements relative to the trust boundaries containing them.

3. CON-001 closed. Captured the Windows MTMT oracle and committed root-scope.mtmt.json. Result is
rootThreatCount: 0, not the expected 12 — MTMT cannot fire a ROOT predicate at all
(GetElementTypeChain stops before appending the virtual ROOT type, and the script host's IS
operator tests that chain), so the six migrated (v3) types are inert. The capture also shows the tool
generating strictly once per interaction (Diagram A: 1 connector/21 threats; B: 2/42).

Decision: keep tmforge's per-diagram ROOT sweep as a documented divergence rather than deleting the
six rules. It is coverage the tool lost, it costs nothing on import (a rule that cannot fire in MTMT
contributes no threats to an exported .tm7), and removing it would move persisted threat-register keys
that ANA-001 and THR-002 had just stabilized. Persistent ROOT identities are unchanged.

4. Repaired capture-mtmt-root-scope.ps1, which could not complete a run: Activator::CreateInstance
re-wrapped its argument array and reported LocalFile(string) as missing; ConfigureThreatGeneration
defers to ProcessModelDeferred and NREs without a WPF dispatcher; and ROOT detection matched the
knowledge base's ShortTitle against the rendered Threat.Title, so it would have reported zero
regardless. It now records the per-diagram counts and ROOT declarations, so a zero is evidence the types
were present and did not match.

5. Documented that legacy i:nil connector ports are repaired on save. MTMT refuses such a document
outright; reading and rewriting it through the engine makes it openable.

Why

The export regression silently broke every tmforge convert --to tm7 output — the committed
examples/webshop.tm7 still opened only because it predates the change, which is why nothing caught it.
The remaining items close the last MTMT conformance gate with evidence instead of an assumption.

@Hacks4Snacks Hacks4Snacks linked an issue Jul 26, 2026 that may be closed by this pull request
5 tasks
@Hacks4Snacks
Hacks4Snacks merged commit 8b32461 into main Jul 26, 2026
9 checks passed
@Hacks4Snacks
Hacks4Snacks deleted the hacks4snacks/mtmtroot branch July 26, 2026 23:11
This was referenced Jul 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[CON-001] MTMT ROOT differential closure

1 participant