Skip to content

refactor(types)!: deserialize semantic bundle values eagerly - #193

Merged
wolfv merged 2 commits into
sigstore:stack/rekor-v2-write-pathfrom
wolfv:refactor/deserialize-semantic-types
Aug 27, 2026
Merged

wolfv merged 2 commits into
sigstore:stack/rekor-v2-write-pathfrom
wolfv:refactor/deserialize-semantic-types

Conversation

@wolfv

@wolfv wolfv commented Aug 19, 2026

Copy link
Copy Markdown
Collaborator

Follow-up to #176. This moves validation to deserialization boundaries so downstream code works with semantic values rather than repeatedly parsing wire representations.

  • deserialize bundle media types and supported Rekor kind/version pairs as enums
  • parse checkpoints once while retaining their exact signed envelope bytes
  • deserialize Rekor v1 proof hashes into fixed-size SHA-256 values (removing lossy fallback/filtering)
  • represent in-toto SHA-256 and SHA-512 subject digests as fixed-size types
  • reject malformed or unsupported values while parsing

The temporary base branch mirrors the exact #176 head so this PR shows only the follow-up diff. Once #176 merges, this PR should be retargeted to main and the temporary base deleted.

BREAKING CHANGE: bundle media types, Rekor kind/version pairs, checkpoints, proof hashes, and in-toto subject digests now use semantic types.

@wolfv
wolfv force-pushed the refactor/deserialize-semantic-types branch from 4dbb526 to eae8d14 Compare August 19, 2026 09:31
@wolfv
wolfv force-pushed the stack/rekor-v2-write-path branch from 4490933 to e40fc0a Compare August 19, 2026 09:45
@wolfv
wolfv force-pushed the refactor/deserialize-semantic-types branch from eae8d14 to 4392f32 Compare August 19, 2026 09:45
wolfv added 2 commits August 25, 2026 10:10
Reject unsupported media types and Rekor entry formats while parsing, parse checkpoints once while retaining their signed text, type Rekor v1 proof hashes, and represent in-toto SHA-256/SHA-512 digests with fixed-size values.

BREAKING CHANGE: bundle media types, Rekor kind/version pairs, checkpoints, proof hashes, and in-toto subject digests now use semantic types.

Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>
Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>
@wolfv
wolfv force-pushed the refactor/deserialize-semantic-types branch from 4392f32 to 3067877 Compare August 25, 2026 08:12

@jku jku left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks great

Comment on lines +503 to +504
let sha512 = Sha512Hash::try_from_slice(&sigstore_crypto::sha512(bytes))
.expect("SHA-512 produces a 64-byte digest");

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I guess if we are changing things we could make sha512 return a Sha512Hash now that it exists -- this would match sha256...

Comment on lines 84 to 85
/// bundle format with typed fields. This uses raw strings as returned by the
/// Rekor V1 API (hex-encoded hashes).

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this looks at least partly misleading now

@wolfv
wolfv merged commit 0fc1295 into sigstore:stack/rekor-v2-write-path Aug 27, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants