Skip to content

feat: verify externally signed governance artifacts with pinned keys - #113

Merged
ernestprovo23 merged 3 commits into
mainfrom
codex/checkpoint-artifact-trust
Oct 3, 2026
Merged

ernestprovo23 merged 3 commits into
mainfrom
codex/checkpoint-artifact-trust

Conversation

@ernestprovo23

@ernestprovo23 ernestprovo23 commented Oct 3, 2026 •

Copy link
Copy Markdown
Member

The Agent Trust Kernel activation APIs previously required callers to supply their own artifact signature verifier. This change adds an opt-in Ed25519 implementation that accepts only explicitly enrolled public keys and artifact-kind roles under an independently pinned root configuration.

trust prepare validates an existing policy, runtime, adapter or bundle draft and writes unsigned canonical review/signing bytes. trust verify checks the returned detached signature against the pinned roots. The signature frame binds format version, artifact kind, key identity and exact canonical payload; keys authorized for policy cannot silently attest runtime state.

The product contains no private-key loader, key generator or signing command. Signature verification remains separate from activation, freshness and action authorization. Existing artifact/dependency checks and the default evidence gate remain enforced; live guard integration and durable receipts remain dependencies of DSE-717 and DSE-1076.

Validation:

  • 46 new SDK/CLI/integration tests, including real signatures through all four activation paths, role/key/payload substitution, root-pin changes, malformed inputs and dependency drift.
  • 134 focused tests including the existing PDP/PEP/conformance suites.
  • Independent security review APPROVE at 5f91bb31873fbff9f30e90bbf1261d05cdb8255c; symlink-loop error handling includes a real subprocess regression. Ruff, strict MkDocs and desktop/mobile guide QA passed. Final-head CI passed 1,321 tests (2 skipped), 88.80% coverage, and 47 deterministic fuzz tests. All checks are green, including SDK 1.x parity, real Sigstore signing/verification, conformance, hash-locked installation and secret scanning.
  • Dependency lock retains cryptography 50.0.0; only its direct-dependency annotation changes.

Security-specific development authorized in the current owner session. Merge remains subject to final security review and the exact-head release receipt.

@ernestprovo23
ernestprovo23 marked this pull request as ready for review October 3, 2026 10:09
@ernestprovo23
ernestprovo23 merged commit 608ed25 into main Oct 3, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant