Skip to content

trident-acl-agent: 3-tier COSI SHA-384 source (labels, then legacy hash) - #833

Draft
bfjelds (bfjelds) wants to merge 2 commits into
mainfrom
user/bfjelds/acl-agent-cosi-sha384-labels
Draft

bfjelds (bfjelds) wants to merge 2 commits into
mainfrom
user/bfjelds/acl-agent-cosi-sha384-labels

Conversation

@bfjelds

@bfjelds bfjelds (bfjelds) commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

NOTE: this is 3-tier currently because the final design hasn't been choosen yet; when choosen, this PR should be modified to be 2-tier.

What

Nebraska manifests can now report the COSI metadata SHA-384 via two new label-based mechanisms, each falling back to the next:

  1. A <labels><label key="cosi.metadata.sha384" value="..."/></labels> child element on <package>.
  2. A labels="{...}" JSON attribute on <package> with the same key.
  3. Fallback: the legacy hash attribute (current behavior, Omaha's sha1 field repurposed to carry this value).

Why

trident-acl-agent currently reads the COSI validation SHA-384 out of a Nebraska sha1 field (repurposed by internal convention). This adds two explicit, self-describing label-based ways to supply the same value, without changing existing manifests/behavior.

How

  • wire::Package::cosi_sha384_base64() resolves the value with the above precedence; a malformed labels JSON attribute falls through to the next tier rather than erroring.
  • client.rs's build_package_file now calls this resolver instead of reading package.hash directly.
  • Each tier has a dedicated test asserting the actual decoded SHA-384 hex digest (via PackageHash::to_cosi_sha384()), not just the intermediate base64 string.

Testing

  • cargo test -p trident-acl-agent: all pass
  • cargo clippy -p trident-acl-agent --all-targets: clean
  • cargo fmt -p trident-acl-agent -- --check: clean

Nebraska manifests can now report the COSI metadata SHA-384 via two
new label-based mechanisms, each falling back to the next:

1. A <labels><label key="cosi.metadata.sha384" value="..."/></labels>
   child element on <package>.
2. A labels="{...}" JSON attribute on <package> with the same key.
3. Fallback: the legacy hash attribute (current behavior, Omaha's sha1
   field repurposed to carry this value).

Adds wire::Package::cosi_sha384_base64() to resolve the value with
this precedence, used when building PackageFile/PackageHash. A
malformed labels JSON attribute falls through to the next tier
instead of erroring.

Each tier has a dedicated test asserting the real, decoded SHA-384
hex digest (not just the intermediate base64 string), confirming
correctness end-to-end rather than just precedence.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e5c68000-9b71-4be4-8f78-f1da0b1aaae9
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The implementation matches the documented precedence and preserves legacy behavior with focused coverage.

0 open findings

What changed in this PR

Adds explicit, backward-compatible sources for Nebraska COSI metadata SHA-384 values.

Changes:

  • Resolves SHA-384 from XML labels, JSON labels, then legacy hash.
  • Uses the resolver when constructing package files.
  • Adds precedence, fallback, and digest-decoding tests.
File Description
wire.rs Parses label sources and implements precedence.
client.rs Uses resolved hashes and tests all tiers.

🧠 Review effort: Balanced


Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The implementation matches the declared precedence and is well tested; remaining feedback is documentation-only.

1 open finding

🧠 Review effort: Balanced

Comment thread crates/trident-acl-agent/src/core/nebraska/client.rs

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Invalid higher-priority label values can suppress valid fallback hashes and abort updates.

2 open findings

🧠 Review effort: Balanced

Comment thread crates/trident-acl-agent/src/core/nebraska/wire.rs
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: d61c42e7-3c43-4fe5-8c89-89d38ff9528b

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants