fix(mtmt): restore .tm7 openability and close the ROOT differential - #75
Merged
Merged
Conversation
5 tasks
This was referenced Jul 26, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
fix(mtmt): restore .tm7 openability and close the ROOT differential (CON-001)
What changed
1.
.tm7exports were unopenable in MTMT (regression, P0).KnowledgeBaseCatalog.AddThreatMetaDatareplaced the knowledge base's whole
ThreatMetaDatablock with a singlePrioritydatum. MTMT resolvessix properties by name while loading (
Title,UserThreatCategory,UserThreatShortDescription,UserThreatDescription,StateInformation,InteractionString) and throwsApplicationException: KnowledgeBase is missing a required Threat Propertywhen any is absent — ittolerates an absent block and a complete one, but refuses a partial one. New
ThreatMetaDataContractdeclares the full set mirroring the official template;Tm7ExportPreparernow defers to a foreign template for all tool-owned properties instead of only
Priority.2. Coordinate normalization only honoured the lower bound. MTMT clamps both ways, and per element
kind: borders to 1890x2090, connector coordinates to 1990x2190. A wide or tall diagram still opened
with the "coordinates are corrupted" correction.
NormalizeCoordinatesnow translates each surface tosatisfy both bounds. A surface larger than the canvas is anchored at the minimum rather than rescaled,
because scaling would move elements relative to the trust boundaries containing them.
3. CON-001 closed. Captured the Windows MTMT oracle and committed
root-scope.mtmt.json. Result isrootThreatCount: 0, not the expected 12 — MTMT cannot fire a ROOT predicate at all(
GetElementTypeChainstops before appending the virtualROOTtype, and the script host'sISoperator tests that chain), so the six migrated
(v3)types are inert. The capture also shows the toolgenerating strictly once per interaction (Diagram A: 1 connector/21 threats; B: 2/42).
Decision: keep tmforge's per-diagram ROOT sweep as a documented divergence rather than deleting the
six rules. It is coverage the tool lost, it costs nothing on import (a rule that cannot fire in MTMT
contributes no threats to an exported
.tm7), and removing it would move persisted threat-register keysthat ANA-001 and THR-002 had just stabilized. Persistent ROOT identities are unchanged.
4. Repaired
capture-mtmt-root-scope.ps1, which could not complete a run:Activator::CreateInstancere-wrapped its argument array and reported
LocalFile(string)as missing;ConfigureThreatGenerationdefers to
ProcessModelDeferredand NREs without a WPF dispatcher; and ROOT detection matched theknowledge base's
ShortTitleagainst the renderedThreat.Title, so it would have reported zeroregardless. It now records the per-diagram counts and ROOT declarations, so a zero is evidence the types
were present and did not match.
5. Documented that legacy
i:nilconnector ports are repaired on save. MTMT refuses such a documentoutright; reading and rewriting it through the engine makes it openable.
Why
The export regression silently broke every
tmforge convert --to tm7output — the committedexamples/webshop.tm7still opened only because it predates the change, which is why nothing caught it.The remaining items close the last MTMT conformance gate with evidence instead of an assumption.