You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
a canonical encoding that verifiers outside Rust can recompute;
every field signed;
verification against registered keys instead of the key embedded in each
entry.
Motivation
AuditEntry::signing_data (crates/astrid-audit/src/entry.rs:123) is hard to
verify independently:
Encoding: it mixes fixed binary fields with serde_json of the action
and authorization, and silently omits either if serialization fails
(entry.rs:143,146).
Time: it signs whole-second time (entry.rs:126).
Outcome: it reduces the outcome to one success/failure bit, so the
outcome text is not signed.
Position: there is no signed per-chain sequence number.
Keys: verification uses the public key embedded in each entry. Anyone
with write access to the store can therefore re-sign a rewritten chain
under any key and still pass.
Key roles: one runtime key signs audit entries, capability tokens and
build artifacts.
External verification (#1995, #678) and receipts (#693, #1367) need a format
that can be recomputed byte for byte outside Astrid.
Proposed Implementation
EntryV2: a deterministic CBOR positional array hashed with
domain-separated SHA-256 and signed with Ed25519 (verify_strict).
Chain and position fields: chain id bound to the principal UID, per-chain
sequence number and previous hash.
Content fields: nanosecond time, actor (capsule id and wasm hash), full
outcome, salted commitments for sensitive or low-entropy fields.
Migration: v1 chains are closed and kept verifiable as they are; new
entries are v2. External anchoring keeps working across the switch.
Alternatives Considered
Canonicalize JSON (RFC 8785) and keep the layout. Smaller change, but
the one-bit outcome, missing sequence number and embedded-key verification
remain.
Summary
Define a v2 audit entry format:
entry.
Motivation
AuditEntry::signing_data(crates/astrid-audit/src/entry.rs:123) is hard toverify independently:
serde_jsonof the actionand authorization, and silently omits either if serialization fails
(
entry.rs:143,146).entry.rs:126).outcome text is not signed.
with write access to the store can therefore re-sign a rewritten chain
under any key and still pass.
build artifacts.
External verification (#1995, #678) and receipts (#693, #1367) need a format
that can be recomputed byte for byte outside Astrid.
Proposed Implementation
EntryV2: a deterministic CBOR positional array hashed withdomain-separated SHA-256 and signed with Ed25519 (
verify_strict).sequence number and previous hash.
outcome, salted commitments for sensitive or low-entropy fields.
signing, with a key registry chain (genesis and rotations cross-signed).
Verifiers reject entries signed by unregistered keys. This relates to feat(cli): astrid keys — runtime key inspection, rotation, pubkey export for trust setup #683.
entries are v2. External anchoring keeps working across the switch.
Alternatives Considered
the one-bit outcome, missing sequence number and embedded-key verification
remain.
Part of #1997.