fix(provenance): validate attestation by shape, not truthiness - #339
Open
rajnisht7 wants to merge 2 commits into
Open
fix(provenance): validate attestation by shape, not truthiness#339rajnisht7 wants to merge 2 commits into
rajnisht7 wants to merge 2 commits into
Conversation
Signed-off-by: rajnisht7 <rajnishtiwari9787@gmail.com>
Signed-off-by: rajnisht7 <rajnishtiwari9787@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this changes
provenance._check_structure()checkedattestationwith truthiness (not attestation/attestation) instead of checking its type and shape. Spec (server-provenance-v1.md §3) saysattestationmust benullunlesskind == "tee-attested", and must match the TRACE v0.2 §3.1runtimeshape when it is.Truthiness doesn't enforce that:
{},[],""are falsy but notnull, so a non-TEE record carrying any of them asattestationbuilt and verified cleanly.tee-attestedrecord withattestation: "hello"or["anything"]passed too.attestationcould nameplatform: "software-only", which is not a hardware claim at all the same contradiction §1 rules out fortee-attested("the server itself, from inside a TEE").Because this check is shared with
verify_record()(#146), a hand-forged, correctly-signed record withattestation: "not-actually-attestation"passed verification.Type of change
Spec section
Not a change to
spec/trace-v0.2.mditself this implements the existingserver-provenance-v1.md§3attestationcontract and TRACE v0.2 §3.1runtimeshape more strictly in code. No wire format or normative text changes.Checklist
git commit -s)CHANGELOG.mdupdated (for any normative change)<!-- CHANGED: #NNN: description -->in spec text