Skip to content

fix(verify): handle canonical Rekor intoto entries - #175

Merged
wolfv merged 5 commits into
sigstore:mainfrom
wolfv:fix/rekor-intoto-canonical-entry
Aug 19, 2026
Merged

wolfv merged 5 commits into
sigstore:mainfrom
wolfv:fix/rekor-intoto-canonical-entry

Conversation

@wolfv

@wolfv wolfv commented Aug 4, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • model Rekor v1 intoto/0.0.2 canonical entries using payloadHash, payloadType, envelope hash, signatures, and signature public keys instead of requiring the proposed DSSE payload
  • bind the canonical entry payload hash and payload type to the bundle DSSE envelope
  • bind every logged signature and its certificate/public key to the bundle signature and signing certificate
  • recognize intoto/0.0.2 as a Rekor v1 integrated-time source rather than a Rekor v2 entry
  • support SHA-512 in-toto subjects so the existing real sigstore.js@2.0.0 provenance fixture exercises complete verification
  • add positive and tampering tests for payload hash, payload type, signature, and signing certificate bindings

This addresses TOB-SIGSTORE-12.

Regression coverage

Before the model change, the real canonical fixture failed while parsing its Rekor body with missing field payload. The complete verification flow now succeeds with that fixture.

Testing

  • cargo test -p sigstore-rekor -p sigstore-verify
  • cargo clippy -p sigstore-rekor -p sigstore-verify --all-targets -- -D warnings
  • cargo fmt --all -- --check
  • git diff --check

jku
jku previously approved these changes Aug 13, 2026

@jku jku left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I will rubber stamp this but I wonder if we could just drop the intoto support and focus on hashedrekord and dsse?

Anyway, lgtm

Comment thread crates/sigstore-verify/src/verify.rs Outdated
@wolfv
wolfv force-pushed the fix/rekor-intoto-canonical-entry branch from e409be5 to c608246 Compare August 13, 2026 09:39
@wolfv
wolfv enabled auto-merge (squash) August 13, 2026 10:39
@wolfv

wolfv commented Aug 13, 2026

Copy link
Copy Markdown
Collaborator Author

I looked at this alongside the Rekor v2 work. The unfortunate naming is that intoto/0.0.2 is still a legacy Rekor v1 entry type; Rekor v2 DSSE submission is hashedrekord/0.0.2. #176 removes the nonexistent dsse/0.0.2 v2 path, but it does not make this fix obsolete. The regression fixture is a real sigstore.js provenance bundle that otherwise cannot be verified, so I think we should retain read/verification compatibility for historical intoto entries while not implementing an intoto v2 write path.

@wolfv
wolfv requested a review from jku August 13, 2026 11:38
@wolfv
wolfv force-pushed the fix/rekor-intoto-canonical-entry branch 2 times, most recently from 11b0c40 to e7bd916 Compare August 13, 2026 11:51
@wolfv

wolfv commented Aug 13, 2026

Copy link
Copy Markdown
Collaborator Author

@jku I checked this against the Rekor v2 work: intoto/0.0.2 is unfortunately a legacy Rekor v1 entry type; Rekor v2 DSSE submission is hashedrekord/0.0.2. So removing the nonexistent v2 dsse/0.0.2 path does not make this obsolete. The fixture is a real historical sigstore.js provenance bundle, so I think read/verification compatibility is worth keeping. I also pushed managed-key binding so an intoto verifier must match the caller-supplied key.

Comment thread crates/sigstore-verify/src/verify_impl/rekor.rs Outdated

@tnytown tnytown left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks like this behaves correctly, but i have a few code quality nits

Comment thread crates/sigstore-verify/src/verify_impl/rekor.rs Outdated
wolfv added 5 commits August 19, 2026 08:58
Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>
Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>
Pass the caller-supplied public key into Rekor consistency checks so canonical intoto entries remain safely verifiable for managed-key bundles.

Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>
Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>
Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>
@wolfv
wolfv force-pushed the fix/rekor-intoto-canonical-entry branch from 503eb83 to 9541ae4 Compare August 19, 2026 06:59
@wolfv
wolfv merged commit 948c317 into sigstore:main Aug 19, 2026
17 checks passed
@wolfv wolfv mentioned this pull request Aug 19, 2026
@wolfv wolfv mentioned this pull request Sep 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants