feat: verify externally signed governance artifacts with pinned keys - #113
Merged
Merged
Conversation
ernestprovo23
marked this pull request as ready for review
October 3, 2026 10:09
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The Agent Trust Kernel activation APIs previously required callers to supply their own artifact signature verifier. This change adds an opt-in Ed25519 implementation that accepts only explicitly enrolled public keys and artifact-kind roles under an independently pinned root configuration.
trust preparevalidates an existing policy, runtime, adapter or bundle draft and writes unsigned canonical review/signing bytes.trust verifychecks the returned detached signature against the pinned roots. The signature frame binds format version, artifact kind, key identity and exact canonical payload; keys authorized for policy cannot silently attest runtime state.The product contains no private-key loader, key generator or signing command. Signature verification remains separate from activation, freshness and action authorization. Existing artifact/dependency checks and the default evidence gate remain enforced; live guard integration and durable receipts remain dependencies of DSE-717 and DSE-1076.
Validation:
5f91bb31873fbff9f30e90bbf1261d05cdb8255c; symlink-loop error handling includes a real subprocess regression. Ruff, strict MkDocs and desktop/mobile guide QA passed. Final-head CI passed 1,321 tests (2 skipped), 88.80% coverage, and 47 deterministic fuzz tests. All checks are green, including SDK 1.x parity, real Sigstore signing/verification, conformance, hash-locked installation and secret scanning.Security-specific development authorized in the current owner session. Merge remains subject to final security review and the exact-head release receipt.