Skip to content

feat(extension): add signed remote registries - #3

Closed
ZhiXiao-Lin wants to merge 1 commit into
recovery/builtin-ocr-first-usefrom
recovery/remote-extension-tuf
Closed

ZhiXiao-Lin wants to merge 1 commit into
recovery/builtin-ocr-first-usefrom
recovery/remote-extension-tuf

Conversation

@ZhiXiao-Lin

Copy link
Copy Markdown
Contributor

Summary

  • accept bounded local tar.gz, tgz, and ZIP extension packages with portable path and link protections
  • resolve and download remote extensions through TUF using an out-of-band pinned bootstrap root
  • expose exact review/apply plan digests, signed provenance receipts, and no-download convergence
  • reject modified installed package content before route acquisition and remote convergence
  • add low-level Use CLI support for trusted registry installs and document the registry contract

Security properties

  • HTTPS is required except for loopback development registries
  • bootstrap root bytes must match the configured SHA-256 before they are cached
  • TUF expiration, rollback, target length, and target hash verification are enforced
  • archive traversal, links, duplicates, unsupported entries, excessive expansion, and non-portable paths are rejected
  • signed receipts require an expanded-package digest; execution and convergence recompute it before proceeding

Package verification closes the pre-dispatch integrity gap, but does not claim filesystem immutability against a privileged writer racing the final process spawn.

Validation

  • cargo fmt --all -- --check
  • cargo test --workspace --all-features --locked --offline
  • cargo clippy --workspace --all-targets --all-features --locked --offline -- -D warnings

All checks passed locally.

Stack

This PR is intentionally based on #2. Review #2 first; after it merges, this branch can be retargeted to main without changing this PR head.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant