Documentation
¶
Overview ¶
Package checkpoint verifies transparency-log checkpoints against a pinned trust policy — the log's origin and the log's note-verifier key — and verifies Merkle proofs against verified checkpoints.
Index ¶
Constants ¶
This section is empty.
Variables ¶
var ( ErrMalformed = errors.New("malformed checkpoint") ErrSignature = errors.New("checkpoint signature verification failed") ErrOrigin = errors.New("checkpoint origin does not match the pinned origin") ErrProof = errors.New("proof verification failed") )
Errors returned by Verify and the proof checks. All of them mean the bytes must not be trusted.
Functions ¶
func VerifyConsistency ¶
func VerifyConsistency(older, newer Checkpoint, hashes [][]byte) error
VerifyConsistency checks that the tree newer commits to is an append-only extension of the tree older commits to. Equal sizes require equal root hashes; a smaller newer tree is a rollback and always fails.
func VerifyInclusion ¶
func VerifyInclusion(cp Checkpoint, index uint64, leafHash []byte, hashes [][]byte) error
VerifyInclusion checks that leafHash is the leaf at index in the tree cp commits to.
Types ¶
type Checkpoint ¶
type Checkpoint struct {
// Raw is the signed note exactly as served.
Raw []byte
// Size is the tree size (leaf count) the checkpoint commits to.
Size uint64
// Hash is the Merkle root hash at Size.
Hash []byte
}
Checkpoint is a checkpoint that passed Verify.
func ParseTrusted ¶
func ParseTrusted(raw []byte, origin string) (Checkpoint, error)
ParseTrusted reads the size and root hash out of a checkpoint WITHOUT verifying its signatures — only for a checkpoint this program verified earlier and stored itself (its signing keys may since have rotated). The origin line must still equal origin.
func (Checkpoint) SameTree ¶
func (c Checkpoint) SameTree(o Checkpoint) bool
SameTree reports whether two verified checkpoints commit to the same tree.
type Policy ¶
type Policy struct {
// Origin is the log's fixed origin line, "axt.anthropic.com/<organization_uuid>".
Origin string
// LogKey is the log's note-verifier key string. Its key name is the origin.
LogKey string
}
Policy is the trust configuration the caller brings: for axt-verify, the key built into the release, or the one --log-key supplies. Nothing in it may be learned from the API being verified.
type Signature ¶
type Signature struct {
// Name is the key name the line carried. On a note that failed
// verification this is attacker-chosen text: print it escaped.
Name string `json:"name"`
// KeyHash is the signing key's 4-byte hash, hex-encoded — what the
// published key table lists.
KeyHash string `json:"key_hash"`
// OK is false for a line that does not parse, where Name and KeyHash
// are empty and the line itself is not worth showing. It stays out of
// the JSON: a reader sees an entry with nothing in it, which is what
// the note gave.
OK bool `json:"-"`
}
Signature is one signature line of a signed note.
func Signatures ¶
Signatures lists the signature lines of a signed note WITHOUT verifying any of them. It exists for one job: after a checkpoint is rejected, show the operator which key hashes the log did sign with, so they can compare them against the published table. The note is untrusted input, so at most maxSignaturesReported lines come back, an over-long or malformed line comes back with OK false rather than as an error, and every name is returned as served for the caller to escape before printing.
type SignatureError ¶
SignatureError is a signature failure carrying the note exactly as it was served. Those bytes did not verify: they are diagnostics — which keys signed the thing the log offered — never something to act on.
func (*SignatureError) Error ¶
func (e *SignatureError) Error() string
func (*SignatureError) Unwrap ¶
func (e *SignatureError) Unwrap() error
type Verifier ¶
type Verifier struct {
// contains filtered or unexported fields
}
Verifier checks checkpoints against one Policy.
func (*Verifier) LogKey ¶
LogKey is the key this verifier requires a checkpoint to be signed by, in the same shape Signatures reports, so a rejected note's key hashes can be held up against it.
func (*Verifier) Verify ¶
func (v *Verifier) Verify(raw []byte) (Checkpoint, error)
Verify accepts raw only if it is a well-formed checkpoint signed by the log key whose origin line is exactly the pinned origin. Signatures by unknown keys are ignored. Every organization's log is signed by the same key, so the origin comparison — not the signature — is what binds a checkpoint to this organization.