Repository navigation
fix(verify): handle canonical Rekor intoto entries - #175
Conversation
jku
left a comment
There was a problem hiding this comment.
I will rubber stamp this but I wonder if we could just drop the intoto support and focus on hashedrekord and dsse?
Anyway, lgtm
e409be5 to
c608246
Compare
|
I looked at this alongside the Rekor v2 work. The unfortunate naming is that intoto/0.0.2 is still a legacy Rekor v1 entry type; Rekor v2 DSSE submission is hashedrekord/0.0.2. #176 removes the nonexistent dsse/0.0.2 v2 path, but it does not make this fix obsolete. The regression fixture is a real sigstore.js provenance bundle that otherwise cannot be verified, so I think we should retain read/verification compatibility for historical intoto entries while not implementing an intoto v2 write path. |
11b0c40 to
e7bd916
Compare
|
@jku I checked this against the Rekor v2 work: |
Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>
Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>
Pass the caller-supplied public key into Rekor consistency checks so canonical intoto entries remain safely verifiable for managed-key bundles. Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>
Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>
Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>
503eb83 to
9541ae4
Compare
Summary
intoto/0.0.2canonical entries usingpayloadHash,payloadType, envelope hash, signatures, and signature public keys instead of requiring the proposed DSSE payloadintoto/0.0.2as a Rekor v1 integrated-time source rather than a Rekor v2 entrysigstore.js@2.0.0provenance fixture exercises complete verificationThis addresses TOB-SIGSTORE-12.
Regression coverage
Before the model change, the real canonical fixture failed while parsing its Rekor body with
missing field payload. The complete verification flow now succeeds with that fixture.Testing
cargo test -p sigstore-rekor -p sigstore-verifycargo clippy -p sigstore-rekor -p sigstore-verify --all-targets -- -D warningscargo fmt --all -- --checkgit diff --check