Repository navigation
trident-acl-agent: 3-tier COSI SHA-384 source (labels, then legacy hash) - #833
Draft
bfjelds (bfjelds) wants to merge 2 commits into
Draft
bfjelds (bfjelds) wants to merge 2 commits into
bfjelds (bfjelds) wants to merge 2 commits into
Conversation
Nebraska manifests can now report the COSI metadata SHA-384 via two
new label-based mechanisms, each falling back to the next:
1. A <labels><label key="cosi.metadata.sha384" value="..."/></labels>
child element on <package>.
2. A labels="{...}" JSON attribute on <package> with the same key.
3. Fallback: the legacy hash attribute (current behavior, Omaha's sha1
field repurposed to carry this value).
Adds wire::Package::cosi_sha384_base64() to resolve the value with
this precedence, used when building PackageFile/PackageHash. A
malformed labels JSON attribute falls through to the next tier
instead of erroring.
Each tier has a dedicated test asserting the real, decoded SHA-384
hex digest (not just the intermediate base64 string), confirming
correctness end-to-end rather than just precedence.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e5c68000-9b71-4be4-8f78-f1da0b1aaae9
|
Azure Pipelines: Successfully started running 1 pipeline(s). There may be pipelines that require an authorized user to comment /azp run to run. |
Contributor
There was a problem hiding this comment.
🟢 Approval recommended
The implementation matches the documented precedence and preserves legacy behavior with focused coverage.
0 open findings
What changed in this PR
Adds explicit, backward-compatible sources for Nebraska COSI metadata SHA-384 values.
Changes:
- Resolves SHA-384 from XML labels, JSON labels, then legacy hash.
- Uses the resolver when constructing package files.
- Adds precedence, fallback, and digest-decoding tests.
| File | Description |
|---|---|
wire.rs |
Parses label sources and implements precedence. |
client.rs |
Uses resolved hashes and tests all tiers. |
🧠 Review effort: Balanced
Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d61c42e7-3c43-4fe5-8c89-89d38ff9528b
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


What
Nebraska manifests can now report the COSI metadata SHA-384 via two new label-based mechanisms, each falling back to the next:
<labels><label key="cosi.metadata.sha384" value="..."/></labels>child element on<package>.labels="{...}"JSON attribute on<package>with the same key.hashattribute (current behavior, Omaha'ssha1field repurposed to carry this value).Why
trident-acl-agentcurrently reads the COSI validation SHA-384 out of a Nebraskasha1field (repurposed by internal convention). This adds two explicit, self-describing label-based ways to supply the same value, without changing existing manifests/behavior.How
wire::Package::cosi_sha384_base64()resolves the value with the above precedence; a malformedlabelsJSON attribute falls through to the next tier rather than erroring.client.rs'sbuild_package_filenow calls this resolver instead of readingpackage.hashdirectly.PackageHash::to_cosi_sha384()), not just the intermediate base64 string.Testing
cargo test -p trident-acl-agent: all passcargo clippy -p trident-acl-agent --all-targets: cleancargo fmt -p trident-acl-agent -- --check: clean