feat(catalog): publish a signed catalog for srelens hosts (srelens/srelens#559) - #3
Merged
Merged
Conversation
…elens#559) srelens hosts from srelens/srelens#559 on no longer read catalog.json. They read catalog.signed.json: a DSSE envelope over the same entries, signed with the catalog key their pinned root names, carrying the publisher delegations, a version they refuse to see go backwards, and an expiry after which they stop offering installs. Nothing published it yet, so those hosts would keep no catalog at all. A new workflow signs catalog.json into catalog.signed.json with the CATALOG_SIGNING_PRIVATE_KEY secret whenever the catalog, a delegation, the root or the scripts change on main, and every Monday, using the signing time as the version and a 30-day expiry. Before committing, verify-catalog.mjs checks the result as a host would: the copied root signs itself at its threshold, the catalog and every delegation are signed by its catalog role, the version is higher than the published one, the expiry is ahead, and the entries are exactly catalog.json's. A catalog it refuses is not published. trust/root.json and scripts/trust.mjs are copies of the pinned root and the signing script in srelens/srelens. publishers/srelens.json delegates org.srelens to the srelens release key. catalog.json and its entries are unchanged, for hosts released before #559.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Publishes
catalog.signed.json, the catalog srelens hosts read from srelens/srelens#559 on (srelens/srelens#745). It is step 2 of that PR's rollout: the key ceremony is done, and the root it produced is pinned in srelens/srelens@43eaace5.What changes
.github/workflows/sign-catalog.ymlsignscatalog.jsonintocatalog.signed.jsonwith theCATALOG_SIGNING_PRIVATE_KEYsecret (already set), then commits it tomain. It runs:catalog.json,publishers/**,trust/**, the scripts or the workflow change onmain;Each signed catalog gets the signing time (Unix seconds) as its
versionand expires 30 days later. The key goes into aumask 077file under$RUNNER_TEMP, which is deleted when the step exits. Runs are serialised, so two runs can't publish out of order.scripts/verify-catalog.mjschecks the result the way a host would, and the workflow publishes nothing it refuses:trust/root.jsonsigns itself at its root threshold;catalog.json's.trust/root.jsonandscripts/trust.mjsare byte-identical copies ofcrates/registry/src/extensions/trust/root.jsonandscripts/extensions/trust.mjsin srelens/srelens.publishers/srelens.jsondelegatesorg.srelensto the srelens release key. It is the same document as the one pinned incrates/registry/src/extensions/trust/publishers.json.README: a "Signed catalog" section.
catalog.jsonandentries/are unchanged. Hosts released before #559 go on reading them.Verification
SharedCatalogunderTrustRoot::from_signed_documentswith that root and delegation), and the host accepted it.python3 -m unittest discover -s testsandpython3 scripts/catalog.py --checkpass.After merge
The push run publishes
catalog.signed.jsontomain. The job asks forcontents: write, because the repository's default token is read-only.mainhas no branch protection, so the bot's push goes through. Once the file is live, the "Extension catalog / live catalog and signatures" check on srelens/srelens#745 should pass on a re-run.Follow-ups
catalog.jsonhas to be frozen and the signed catalog given its own source. Hosts before #559 can read only bare 64-byte signatures. Every release listed today uses that form, so signingcatalog.jsonas-is is safe for now. The Flux and Argo CD workflows switch to key-named signatures only after the host release.docs/extensions/trust.mdon srelens/srelensdev, which exists once #745 merges.Part of srelens/srelens#559.