signing

package
v1.261010.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 10, 2026 License: MIT Imports: 46 Imported by: 0

Documentation

Index

Constants

View Source
const EncryptedArtifactSuffix = ".enc"

EncryptedArtifactSuffix is the on-disk suffix of an encrypted signing artifact. Remote stores keep it so a stored object is never mistaken for plaintext signing material.

View Source
const MaxEncryptedArtifactBytes = maxEncryptedFileSize

MaxEncryptedArtifactBytes is the per-artifact ciphertext limit shared by the encrypted repository and every remote store.

Variables

View Source
var ErrObjectStorageConflict = errors.New("object changed since it was fetched")

ErrObjectStorageConflict reports that an object changed after this store fetched it, so publishing would overwrite ciphertext that was never validated.

Functions

func Decrypt

func Decrypt(data []byte, password string) ([]byte, error)

Decrypt decrypts data encrypted by Encrypt.

func Encrypt

func Encrypt(plaintext []byte, password string) ([]byte, error)

Encrypt encrypts plaintext using AES-256-GCM with a password-derived key. Output format: salt (16 bytes) || nonce (12 bytes) || ciphertext+tag.

func EncryptFile added in v1.260816.0

func EncryptFile(plaintext []byte, password string, metadata EncryptedFileMetadata) ([]byte, error)

EncryptFile encrypts plaintext and authenticates the versioned metadata as AES-GCM additional data. The envelope is magic || metadata length || metadata JSON || salt || nonce || ciphertext+tag.

func EnsureInsideDir

func EnsureInsideDir(baseDir, target string) error

EnsureInsideDir checks that target stays inside baseDir and does not traverse any symlinked parent directories.

func RedactRepoURL added in v1.260813.0

func RedactRepoURL(raw string) string

RedactRepoURL removes credentials embedded in a repository URL so the remote can be named in errors, diagnostics, and structured output without leaking a token or password.

func RejectSymlinkIfExists

func RejectSymlinkIfExists(path string) error

RejectSymlinkIfExists rejects writes through an existing symlink path.

func ValidateArtifactPrefix

func ValidateArtifactPrefix(prefix string) error

ValidateArtifactPrefix checks the short path prefix that scopes signing artifacts inside a shared remote store.

func ValidateEncryptedRepositoryPaths added in v1.260816.0

func ValidateEncryptedRepositoryPaths(paths []string) error

ValidateEncryptedRepositoryPaths rejects path sets that cannot coexist on a Windows case-insensitive or normalization-insensitive macOS checkout. It normalizes canonically equivalent paths before applying the Unicode simple-fold classes behind strings.EqualFold. Exact duplicate canonical paths retain their existing update semantics.

func ValidateObjectStorageOptions

func ValidateObjectStorageOptions(options ObjectStorageOptions) error

ValidateObjectStorageOptions checks the bucket, prefix, region, and endpoint without reading credentials or contacting the network.

Types

type AWSSecretsManagerOptions

type AWSSecretsManagerOptions struct {
	// Region is the AWS region holding the secrets.
	Region string
	// Prefix scopes the artifacts this store owns inside the account.
	Prefix string
	// API overrides the SDK client in tests.
	API SecretsManagerAPI
	// MaxArtifacts bounds how many prefixed artifacts may be transported.
	MaxArtifacts int
	// RequestContext bounds one Secrets Manager request.
	RequestContext RequestContextFunc
}

AWSSecretsManagerOptions configures an experimental AWS Secrets Manager store for already-encrypted signing artifacts.

type AWSSecretsManagerStore

type AWSSecretsManagerStore struct {
	// contains filtered or unexported fields
}

AWSSecretsManagerStore transports encrypted signing artifacts as base64 secret strings. It never receives the sync password and never decrypts an artifact.

func NewAWSSecretsManagerStore

func NewAWSSecretsManagerStore(ctx context.Context, options AWSSecretsManagerOptions) (*AWSSecretsManagerStore, error)

NewAWSSecretsManagerStore validates the locator and resolves credentials from the standard AWS environment when no client is supplied.

func (*AWSSecretsManagerStore) Fetch

Fetch downloads every encrypted artifact under the configured prefix into the local ciphertext store.

func (*AWSSecretsManagerStore) Locator

func (s *AWSSecretsManagerStore) Locator() string

Locator returns a description of the configured store. It contains no credential material.

func (*AWSSecretsManagerStore) Publish

func (s *AWSSecretsManagerStore) Publish(ctx context.Context, store ArtifactStore) error

Publish stores every local encrypted artifact as a base64 secret string. Secrets outside the configured prefix are never inspected, and no secret is ever deleted.

type ArtifactStore

type ArtifactStore interface {
	ListEncryptedFiles() ([]string, error)
	ReadEncryptedArtifact(relPath string) ([]byte, error)
	WriteEncryptedArtifact(relPath string, ciphertext []byte) error
}

ArtifactStore is the ciphertext-only view of a local encrypted signing tree. Remote stores transport artifacts through this interface and never see the sync password or any decrypted byte.

type EncryptedFileMetadata added in v1.260816.0

type EncryptedFileMetadata struct {
	Version           int    `json:"version"`
	Kind              string `json:"kind,omitempty"`
	RelativePath      string `json:"relativePath,omitempty"`
	Sensitive         bool   `json:"sensitive,omitempty"`
	CertificateSHA256 string `json:"certificateSha256,omitempty"`
	TeamID            string `json:"teamId,omitempty"`
	BundleID          string `json:"bundleId,omitempty"`
	ProfileType       string `json:"profileType,omitempty"`
	ProfileResourceID string `json:"profileResourceId,omitempty"`
	ProfileUUID       string `json:"profileUuid,omitempty"`
	ProfilePath       string `json:"profilePath,omitempty"`
	ProfileSHA256     string `json:"profileSha256,omitempty"`
	KDF               string `json:"kdf,omitempty"`
	ScryptN           int    `json:"scryptN,omitempty"`
	ScryptR           int    `json:"scryptR,omitempty"`
	ScryptP           int    `json:"scryptP,omitempty"`
}

EncryptedFileMetadata is authenticated with a versioned encrypted signing artifact. It contains no secret material.

func DecryptFile added in v1.260816.0

func DecryptFile(data []byte, password string) ([]byte, EncryptedFileMetadata, error)

DecryptFile decrypts a versioned envelope. Legacy unversioned ciphertext remains readable and returns zero-valued metadata.

type GitLabSecureFilesOptions

type GitLabSecureFilesOptions struct {
	// Host is an https base URL. It defaults to https://gitlab.com.
	Host string
	// ProjectID is the numeric GitLab project ID.
	ProjectID string
	// Prefix scopes the artifacts this store owns inside the project.
	Prefix string
	// Token authenticates API requests. It is sent only as a request header.
	Token string
	// HTTPClient overrides the default client in tests.
	HTTPClient *http.Client
	// MaxArtifacts bounds how many prefixed artifacts may be transported.
	MaxArtifacts int
	// RequestContext bounds one list, download, or delete request.
	RequestContext RequestContextFunc
	// UploadContext bounds one upload request.
	UploadContext RequestContextFunc
}

GitLabSecureFilesOptions configures an experimental GitLab Secure Files store for already-encrypted signing artifacts.

type GitLabSecureFilesStore

type GitLabSecureFilesStore struct {
	// contains filtered or unexported fields
}

GitLabSecureFilesStore transports encrypted signing artifacts through the GitLab Secure Files API. It never receives the sync password and never decrypts an artifact.

func NewGitLabSecureFilesStore

func NewGitLabSecureFilesStore(options GitLabSecureFilesOptions) (*GitLabSecureFilesStore, error)

NewGitLabSecureFilesStore validates the locator and credentials of a GitLab Secure Files store.

func (*GitLabSecureFilesStore) Fetch

Fetch downloads every encrypted artifact under the configured prefix into the local ciphertext store.

func (*GitLabSecureFilesStore) Locator

func (s *GitLabSecureFilesStore) Locator() string

Locator returns a redacted description of the configured store.

func (*GitLabSecureFilesStore) Publish

func (s *GitLabSecureFilesStore) Publish(ctx context.Context, store ArtifactStore) error

Publish uploads every local encrypted artifact that the remote store does not already hold byte-for-byte. Secure files outside the configured prefix are never inspected, replaced, or deleted.

type GitStore

type GitStore struct {
	RepoURL  string
	LocalDir string
	Branch   string
	// contains filtered or unexported fields
}

GitStore manages an encrypted git repository of signing assets.

func (*GitStore) CheckEncryptedFileParent added in v1.260816.0

func (g *GitStore) CheckEncryptedFileParent(relPath string) error

CheckEncryptedFileParent validates an encrypted artifact's future parent layout without assuming its final profile-specific name is known yet.

func (*GitStore) CheckEncryptedRepositoryPaths added in v1.260816.0

func (g *GitStore) CheckEncryptedRepositoryPaths(planned []string) error

CheckEncryptedRepositoryPaths validates planned paths together with every existing encrypted artifact before a push writes any repository files.

func (*GitStore) CheckNewEncryptedFile added in v1.260816.0

func (g *GitStore) CheckNewEncryptedFile(relPath string) error

CheckNewEncryptedFile performs the rooted, non-mutating destination checks used before publishing a new versioned encrypted artifact.

func (*GitStore) CheckWriteEncryptedFile added in v1.260816.0

func (g *GitStore) CheckWriteEncryptedFile(relPath string) error

CheckWriteEncryptedFile performs the non-mutating rooted checks used before replacing or creating a legacy encrypted signing artifact.

func (*GitStore) Cleanup

func (g *GitStore) Cleanup() error

Cleanup removes the local clone directory.

func (*GitStore) Clone

func (g *GitStore) Clone(ctx context.Context, allowCreate bool) error

Clone clones the git repo. If allowCreate is true (push mode), falls back to initializing an empty repo when the branch doesn't exist. If false (pull mode), fails when the branch is missing.

func (*GitStore) CommitAndPush

func (g *GitStore) CommitAndPush(ctx context.Context, message string) error

CommitAndPush stages all changes, commits, and pushes.

func (*GitStore) EncryptedFileSize added in v1.260816.0

func (g *GitStore) EncryptedFileSize(relPath string) (int64, error)

EncryptedFileSize returns the size of a regular no-follow encrypted artifact.

func (*GitStore) ListEncryptedFiles

func (g *GitStore) ListEncryptedFiles() ([]string, error)

ListEncryptedFiles returns relative paths (without .enc) of all encrypted files.

func (*GitStore) ReadEncryptedArtifact

func (g *GitStore) ReadEncryptedArtifact(relPath string) ([]byte, error)

ReadEncryptedArtifact returns the raw ciphertext of an encrypted artifact without decrypting it.

func (*GitStore) ReadEncryptedFile

func (g *GitStore) ReadEncryptedFile(relPath string, password string) ([]byte, error)

ReadEncryptedFile reads and decrypts a file from the repo. Rejects symlinks to prevent reading outside the clone directory.

func (*GitStore) ReadEncryptedFileWithMetadata added in v1.260816.0

func (g *GitStore) ReadEncryptedFileWithMetadata(relPath string, password string) ([]byte, EncryptedFileMetadata, error)

ReadEncryptedFileWithMetadata reads either a versioned envelope or a legacy encrypted file.

func (*GitStore) ReplaceEncryptedFile added in v1.260831.0

func (g *GitStore) ReplaceEncryptedFile(relPath string, plaintext []byte, password string) error

ReplaceEncryptedFile creates or replaces a legacy encrypted artifact while preserving its existing file mode when present. Replacement is atomic on platforms where rename replaces an existing destination; on Windows, the original is restored if publishing the replacement fails.

func (*GitStore) ReplaceEncryptedFileWithMetadata added in v1.260816.0

func (g *GitStore) ReplaceEncryptedFileWithMetadata(relPath string, plaintext []byte, password string, metadata EncryptedFileMetadata) error

ReplaceEncryptedFileWithMetadata atomically creates or replaces a versioned encrypted artifact after the caller has validated its scope.

func (*GitStore) WriteEncryptedArtifact

func (g *GitStore) WriteEncryptedArtifact(relPath string, ciphertext []byte) error

WriteEncryptedArtifact stores raw ciphertext fetched from a remote store. The bytes are written unchanged so the existing envelope, metadata, and password checks decide whether they are usable.

func (*GitStore) WriteEncryptedFile

func (g *GitStore) WriteEncryptedFile(relPath string, plaintext []byte, password string) error

WriteEncryptedFile writes an encrypted file into the repo. Validates that the resolved path stays inside LocalDir to prevent symlink escapes.

func (*GitStore) WriteEncryptedFileWithMetadata added in v1.260816.0

func (g *GitStore) WriteEncryptedFileWithMetadata(relPath string, plaintext []byte, password string, metadata EncryptedFileMetadata) error

WriteEncryptedFileWithMetadata writes a versioned encrypted file whose non-secret metadata is authenticated with the ciphertext.

type ObjectStorageOptions

type ObjectStorageOptions struct {
	// Bucket names the bucket holding the artifacts.
	Bucket string
	// Prefix optionally scopes the artifacts inside the bucket. One trailing
	// slash is accepted; an empty prefix uses the bucket root.
	Prefix string
	// Region overrides the region from the standard AWS configuration.
	Region string
	// Endpoint optionally selects an S3-compatible HTTPS origin, addressed
	// with path-style requests.
	Endpoint string
	// MaxArtifacts bounds how many prefixed artifacts may be transported.
	MaxArtifacts int
	// RequestContext bounds one object storage request.
	RequestContext RequestContextFunc
}

ObjectStorageOptions configures an experimental S3-compatible object storage store for already-encrypted signing artifacts.

type ObjectStorageRotationReport

type ObjectStorageRotationReport struct {
	// LeftoverStagedKeys lists staged copies that could not be deleted after
	// a successful swap. They are ignored by fetches and safe to delete.
	LeftoverStagedKeys []string
}

ObjectStorageRotationReport describes a completed rotation.

type ObjectStorageStore

type ObjectStorageStore struct {
	// contains filtered or unexported fields
}

ObjectStorageStore transports encrypted signing artifacts as objects laid out exactly like the encrypted Git working tree. It never receives the sync password and never decrypts an artifact.

func NewObjectStorageStore

func NewObjectStorageStore(ctx context.Context, options ObjectStorageOptions) (*ObjectStorageStore, error)

NewObjectStorageStore validates the locator and resolves credentials and the region from the standard AWS configuration chain: environment, shared configuration files, web identity, and container or instance metadata.

func (*ObjectStorageStore) Fetch

func (s *ObjectStorageStore) Fetch(ctx context.Context, store ArtifactStore) error

Fetch downloads every encrypted artifact under the prefix into the local ciphertext store and records each object's generation for later conditional writes.

func (*ObjectStorageStore) Locator

func (s *ObjectStorageStore) Locator() string

Locator returns an s3:// description of the bucket and prefix. It contains no credential material and omits any custom endpoint host.

func (*ObjectStorageStore) Publish

func (s *ObjectStorageStore) Publish(ctx context.Context, store ArtifactStore) error

Publish writes every changed local artifact. A new object is created only if no object exists at its key, and an existing object is replaced only if it still has the generation observed by Fetch, so a concurrent writer's ciphertext is never overwritten. Objects outside the prefix are never inspected, and no object is deleted.

func (*ObjectStorageStore) PublishRotation

func (s *ObjectStorageStore) PublishRotation(ctx context.Context, store ArtifactStore, previous map[string][]byte) (ObjectStorageRotationReport, error)

PublishRotation replaces every fetched artifact with its re-encrypted local ciphertext in three phases:

  1. Stage: every new ciphertext is written to a create-only staged key next to its live key. A failure removes the staged copies and leaves every live artifact unchanged.
  2. Verify: every live object must still have the generation observed by Fetch. A change aborts the rotation before any live write.
  3. Swap: each live object is replaced only if it still has the observed generation. If a swap fails, the already replaced artifacts are restored from previous, again conditionally. If restoration also fails, the staged copies are kept and the error lists which artifacts use the new password and how to finish the rotation.

Staged copies are deleted after a successful swap or a complete rollback. previous must hold the fetched ciphertext of every artifact.

type RequestContextFunc

type RequestContextFunc func(context.Context) (context.Context, context.CancelFunc)

RequestContextFunc bounds one outbound request to a remote store. Commands pass the shared CLI timeout helpers so remote stores obey the same request budget as App Store Connect calls.

type SecretsManagerAPI

SecretsManagerAPI is the subset of AWS Secrets Manager used to transport encrypted signing artifacts. Tests substitute a stub so no test dials AWS.

Directories

Path Synopsis
Package objectstoretest provides an in-process, path-style S3-compatible server for tests that exercise the signing sync object storage backend.
Package objectstoretest provides an in-process, path-style S3-compatible server for tests that exercise the signing sync object storage backend.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL