Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/release-body.md
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ gh attestation verify kaibo-${TAG}-x86_64-unknown-linux-musl.tar.gz -R tobert/ka
gh attestation verify oci://ghcr.io/tobert/kaibo:${VERSION} -R tobert/kaibo
```

Or keyless-verify the signed checksum manifest with cosign ≥ 3 (covers every file it lists, works offline):
Or keyless-verify the signed checksum manifest with cosign ≥ 2.5 (covers every file it lists, works offline):

```sh
cosign verify-blob \
Expand Down
4 changes: 2 additions & 2 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -103,8 +103,8 @@ record. Each later release appends a new section at the top.

### Fixed

- **The README's cosign floor said 3, and 2.5 verifies a release** — the old floor turned
away working installs.
- **The cosign floor said 3, and 2.5 verifies a release** — the old floor turned away
working installs, and the release page repeated it.
- **The explorer's shell no longer drops piped or buffered stdin** across
`read`/`grep`/`cat`, and a loop that exits early keeps what it already printed.

Expand Down
2 changes: 1 addition & 1 deletion docs/releases.md
Original file line number Diff line number Diff line change
Expand Up @@ -59,7 +59,7 @@ publish job, so a `workflow_dispatch` smoke run never mints an OIDC identity (bu
keep `contents: read`; the publish job adds `id-token: write` + `attestations: write`).
The layout, decided with Amy: **one signed aggregate `checksums.txt`** (cosign keyless —
verify once, `sha256sum -c` covers any file it lists; one signature shape, the
self-contained `.sigstore.json` bundle, which verifies offline with cosign ≥ 3; the
self-contained `.sigstore.json` bundle, which verifies offline with cosign ≥ 2.5; the
per-artifact `.sha256` sidecars stay for the README's download one-liner),
**per-artifact SLSA provenance** via `actions/attest-build-provenance` (stored in
GitHub's attestation store — `gh attestation verify <file> -R tobert/kaibo`, zero extra
Expand Down
5 changes: 3 additions & 2 deletions docs/sandbox-probes.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,8 +21,9 @@ What we're verifying, concretely:
1. **No write reaches the project** — every mutation path is refused, and nothing
lands on real disk.
2. **No external command runs** — the host is unreachable from inside the shell.
3. **No read escapes the root** — paths outside the mount (absolute, `..`, or via a
`path` arg) resolve to nothing; adjacent secrets stay unreadable.
3. **No read escapes the root** — a file read outside the mount (absolute, `..`, or via
a `path` arg) resolves to nothing; adjacent secrets stay unreadable. The mount's own
prefix directories list, and only ever name the next component toward it — Battery C.
4. **No secret leaks via the environment** — the sandbox runs with an empty env.

The structural design these probes exercise lives in `src/sandbox.rs` (the four
Expand Down