Documentation
¶
Overview ¶
Package localauthority verifies the experimental protected execution profile. A signature is not root admission. PolicySnapshot must come from a separately protected, current operator policy; no command accepts it from claimant JSON.
Index ¶
- Constants
- Variables
- func BytesDigest(raw []byte) string
- func Canonical(value any) ([]byte, error)
- func Decode(raw []byte, result any) error
- func DecodeDocument(raw []byte, result any, limit int) error
- func Digest(value any) (string, error)
- func SigningBytes(payload Payload) ([]byte, error)
- func ValidateEnrollment(e Enrollment) error
- func Verify(receipt Receipt, expected Enrollment, policy PolicySnapshot, now time.Time) error
- func VerifyFixture(receipt Receipt, expected Enrollment, policy PolicySnapshot, now time.Time) error
- type Binding
- type Check
- type Enrollment
- type Payload
- type PolicySnapshot
- type Receipt
- type Row
Constants ¶
const CheckProfile = "tcq/1-experimental"
const MaxReceiptBytes = 128 << 10
const Profile = "corvint-protected-execution/0"
const SelectionMode = "ALL_SELECTED"
Variables ¶
var ErrInvalid = errors.New("invalid-protected-execution")
Functions ¶
func BytesDigest ¶
func Decode ¶
Decode accepts closed, complete canonical objects only. Re-encoding the typed value rejects absent members, null arrays and duplicate members too.
func DecodeDocument ¶
DecodeDocument applies a profile-owned byte ceiling to the same closed canonical decoder. Receipt/signing callers retain MaxReceiptBytes through Decode.
func SigningBytes ¶
func ValidateEnrollment ¶
func ValidateEnrollment(e Enrollment) error
func Verify ¶
func Verify(receipt Receipt, expected Enrollment, policy PolicySnapshot, now time.Time) error
Verify authenticates a complete execution observation, including PASS or FAIL. It requires independent current admission; authentication does not mean checks passed.
func VerifyFixture ¶
func VerifyFixture(receipt Receipt, expected Enrollment, policy PolicySnapshot, now time.Time) error
VerifyFixture exercises the same relation with explicitly unadmitted test keys. It cannot produce an authoritative result and is never called by the live verifier or command adapter.
Types ¶
type Binding ¶
type Binding struct {
Base string `json:"base"`
Target string `json:"target"`
Tree string `json:"tree"`
CEMSHA256 string `json:"cemSHA256"`
OCMSHA256 string `json:"ocmSHA256"`
SelectionSHA256 string `json:"selectionSHA256"`
SourceSHA256 string `json:"sourceSHA256"`
RecipeSHA256 string `json:"recipeSHA256"`
WasmSHA256 string `json:"wasmSHA256"`
WorkerSHA256 string `json:"workerSHA256"`
}
type Check ¶
type Check struct {
ClaimSelector string `json:"claimSelector"`
ID string `json:"id"`
Profile string `json:"profile"`
DriverSHA256 string `json:"driverSHA256"`
DriverPath string `json:"driverPath"`
DriverUnit string `json:"driverUnit"`
Invocation string `json:"invocation"`
Subject string `json:"subject"`
}
type Enrollment ¶
type Enrollment struct {
RepositoryID string `json:"repositoryId"`
PolicySHA256 string `json:"policySHA256"`
Profile string `json:"profile"`
Nonce string `json:"nonce"`
Audience string `json:"audience"`
RootID string `json:"rootId"`
Epoch string `json:"epoch"`
Generation string `json:"generation"`
IssuedAt string `json:"issuedAt"`
ExpiresAt string `json:"expiresAt"`
Selection string `json:"selection"`
Binding Binding `json:"binding"`
Checks []Check `json:"checks"`
}
type Payload ¶
type Payload struct {
Enrollment Enrollment `json:"enrollment"`
CompletedAt string `json:"completedAt"`
Cleanup string `json:"cleanup"`
ExitCode string `json:"exitCode"`
Rows []Row `json:"rows"`
}
type PolicySnapshot ¶
type PolicySnapshot struct {
RepositoryID string
PolicySHA256 string
Accepted bool
Current bool
Fixture bool
Revoked bool
RootID string
PublicKey ed25519.PublicKey
Epoch string
Generation string
MinimumGeneration string
Audience string
Checks []Check
// Exact terminal digest is read from the protected nonce journal. A nonce
// with no authenticated complete observation or another terminal digest cannot verify.
TerminalSHA256 map[string]string
}
PolicySnapshot is intentionally not a wire document. The consumer obtains it from its protected current-policy store on every read, including idempotent receipt reads. Fixture policies are never admitted by Verify.