betterwithage commited on
Commit
e259128
·
verified ·
1 Parent(s): 86b3a4e

chore(sync): mirror backend .py + Dockerfile to Space (hf-sync-backend)

Browse files

Automated backend sync from szl-holdings/a11oy main via hf-sync-backend.
Updated (differed from the Space): szl_corpus_publish.py
Deleted (gone from the repo + Dockerfile COPY set): (none)

Keeps the Space-built backend (serve.py + the Dockerfile-COPY'd .py
modules) identical to GitHub main so the Space never rebuilds from a
stale backend, new endpoints don't 404 there, and orphaned modules
removed from the repo don't linger in the Space tree.

Files changed (1) hide show
  1. szl_corpus_publish.py +47 -29
szl_corpus_publish.py CHANGED
@@ -119,17 +119,21 @@ def _canon(obj: Any) -> bytes:
119
  # Verify-before-publish gate
120
  # --------------------------------------------------------------------------- #
121
  # The published corpus advertises that every ecdsa-p256-dsse-pae receipt verifies
122
- # against ONE pinned cosign.pub — the same key the CI re-verify guard checks
123
- # (.github/hf-corpus-guards.json -> cosign_pub_pem). Incident #325: two receipts
124
- # signed by a transient/rotated key (matching the live org cosign.pub, not the
125
- # pinned one) were published and could no longer re-verify. To make that
126
- # impossible going forward, the producer now re-verifies each signed envelope
127
- # against the SAME pinned key before publishing; an envelope that does not verify
128
- # is skipped (honestly, like an UNSIGNED one) — never published.
 
 
 
 
129
  #
130
- # The pinned PEM is read from the guard config so producer and guard share one
131
  # source of truth; the embedded copy is only a fallback for a runtime that does
132
- # not ship the .github config. Keep it in sync with that file's cosign_pub_pem.
133
  _CORPUS_COSIGN_PUB_PEM_FALLBACK = (
134
  "-----BEGIN PUBLIC KEY-----\n"
135
  "MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE/Jlv9FnwJ13l4QIZpr4IbTBUtVZ2\n"
@@ -138,26 +142,35 @@ _CORPUS_COSIGN_PUB_PEM_FALLBACK = (
138
  )
139
 
140
 
141
- def _corpus_verify_pub_pem() -> str:
142
- """Return the pinned cosign.pub the corpus re-verifies against. Reads the CI
143
- guard config (single source of truth) and falls back to the embedded copy."""
 
 
144
  cfg_path = os.path.join(
145
  os.path.dirname(os.path.abspath(__file__)),
146
  ".github", "hf-corpus-guards.json")
147
  try:
148
  with open(cfg_path, "r", encoding="utf-8") as fh:
149
- pem = json.load(fh).get("cosign_pub_pem")
150
- if isinstance(pem, str) and "BEGIN PUBLIC KEY" in pem:
151
- return pem
 
 
 
 
 
 
152
  except Exception:
153
  pass
154
- return _CORPUS_COSIGN_PUB_PEM_FALLBACK
155
 
156
 
157
- def _ecdsa_envelope_verifies(env: Dict[str, Any], pub_pem: str) -> bool:
158
  """True iff at least one of the envelope's signatures verifies over its DSSE
159
- PAE against pub_pem. Conservative: any error (incl. missing cryptography)
160
- returns False so an envelope we cannot vouch for is NOT published."""
 
161
  try:
162
  import base64
163
  from cryptography.hazmat.primitives.serialization import load_pem_public_key
@@ -170,14 +183,18 @@ def _ecdsa_envelope_verifies(env: Dict[str, Any], pub_pem: str) -> bool:
170
  body = base64.b64decode(env.get("payload", "") or b"")
171
  pt = str(env.get("payloadType", ""))
172
  pae = b"DSSEv1 %d %s %d %s" % (len(pt.encode()), pt.encode(), len(body), body)
173
- pub = load_pem_public_key(pub_pem.encode("utf-8"))
174
- for s in env.get("signatures") or []:
175
  try:
176
- pub.verify(base64.b64decode(s.get("sig", "") or ""), pae,
177
- ec.ECDSA(hashes.SHA256()))
178
- return True
179
- except InvalidSignature:
180
  continue
 
 
 
 
 
 
 
181
  return False
182
  except Exception:
183
  return False
@@ -185,12 +202,13 @@ def _ecdsa_envelope_verifies(env: Dict[str, Any], pub_pem: str) -> bool:
185
 
186
  def _publishable_against_corpus_key(env: Dict[str, Any], scheme: str) -> bool:
187
  """Verify-before-publish gate. ecdsa-p256-dsse-pae receipts are published only
188
- if they verify against the pinned corpus cosign.pub, so a transient/rotated-key
189
- envelope can never enter the corpus and later fail re-verify. sigstore-keyless
190
- receipts are not gated here (verified via their Fulcio cert at re-verify time)."""
 
191
  if scheme != "ecdsa-p256-dsse-pae":
192
  return True
193
- return _ecdsa_envelope_verifies(env, _corpus_verify_pub_pem())
194
 
195
 
196
  # --------------------------------------------------------------------------- #
 
119
  # Verify-before-publish gate
120
  # --------------------------------------------------------------------------- #
121
  # The published corpus advertises that every ecdsa-p256-dsse-pae receipt verifies
122
+ # against the DOCUMENTED TRUSTED KEYSET the CI re-verify guard checks
123
+ # (.github/hf-corpus-guards.json -> trusted_keys). Incident #325: two receipts
124
+ # signed by a transient ephemeral-pod key (NOT a documented org key) were
125
+ # published and could no longer re-verify. Root cause: the gate verified against
126
+ # a SINGLE pinned key, so during an org cosign-key rotation an envelope signed by
127
+ # any other key could slip in (either wrongly rejected, or — when the pin lagged
128
+ # the rotation — published against a stale pin and then failing re-verify). The
129
+ # gate now re-verifies each signed envelope against the SAME multi-key trust set
130
+ # the guard uses; an envelope that verifies under NONE of the trusted keys is
131
+ # skipped (honestly, like an UNSIGNED one) — never published. This makes a
132
+ # transient/untrusted-key receipt impossible to publish going forward.
133
  #
134
+ # The trusted PEMs are read from the guard config so producer and guard share one
135
  # source of truth; the embedded copy is only a fallback for a runtime that does
136
+ # not ship the .github config. Keep it in sync with that file's trusted_keys.
137
  _CORPUS_COSIGN_PUB_PEM_FALLBACK = (
138
  "-----BEGIN PUBLIC KEY-----\n"
139
  "MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE/Jlv9FnwJ13l4QIZpr4IbTBUtVZ2\n"
 
142
  )
143
 
144
 
145
+ def _corpus_trusted_pub_pems() -> List[str]:
146
+ """Return the DOCUMENTED trusted-key PEMs the corpus re-verifies against.
147
+ Reads the CI guard config (single source of truth): the multi-key
148
+ trusted_keys set, falling back to the legacy single cosign_pub_pem, then to
149
+ the embedded copy. A receipt must verify under one of these to publish."""
150
  cfg_path = os.path.join(
151
  os.path.dirname(os.path.abspath(__file__)),
152
  ".github", "hf-corpus-guards.json")
153
  try:
154
  with open(cfg_path, "r", encoding="utf-8") as fh:
155
+ cfg = json.load(fh)
156
+ pems = [k.get("pem") for k in (cfg.get("trusted_keys") or [])
157
+ if isinstance(k, dict) and isinstance(k.get("pem"), str)
158
+ and "BEGIN PUBLIC KEY" in k.get("pem")]
159
+ if pems:
160
+ return pems
161
+ single = cfg.get("cosign_pub_pem")
162
+ if isinstance(single, str) and "BEGIN PUBLIC KEY" in single:
163
+ return [single]
164
  except Exception:
165
  pass
166
+ return [_CORPUS_COSIGN_PUB_PEM_FALLBACK]
167
 
168
 
169
+ def _ecdsa_envelope_verifies(env: Dict[str, Any], pub_pems: List[str]) -> bool:
170
  """True iff at least one of the envelope's signatures verifies over its DSSE
171
+ PAE against at least one of the trusted pub_pems. Conservative: any error
172
+ (incl. missing cryptography) returns False so an envelope we cannot vouch for
173
+ is NOT published."""
174
  try:
175
  import base64
176
  from cryptography.hazmat.primitives.serialization import load_pem_public_key
 
183
  body = base64.b64decode(env.get("payload", "") or b"")
184
  pt = str(env.get("payloadType", ""))
185
  pae = b"DSSEv1 %d %s %d %s" % (len(pt.encode()), pt.encode(), len(body), body)
186
+ for pub_pem in pub_pems:
 
187
  try:
188
+ pub = load_pem_public_key(pub_pem.encode("utf-8"))
189
+ except Exception:
 
 
190
  continue
191
+ for s in env.get("signatures") or []:
192
+ try:
193
+ pub.verify(base64.b64decode(s.get("sig", "") or ""), pae,
194
+ ec.ECDSA(hashes.SHA256()))
195
+ return True
196
+ except InvalidSignature:
197
+ continue
198
  return False
199
  except Exception:
200
  return False
 
202
 
203
  def _publishable_against_corpus_key(env: Dict[str, Any], scheme: str) -> bool:
204
  """Verify-before-publish gate. ecdsa-p256-dsse-pae receipts are published only
205
+ if they verify against the DOCUMENTED trusted keyset (historical + current org
206
+ keys), so a transient/rotated/untrusted-key envelope can never enter the
207
+ corpus and later fail re-verify. sigstore-keyless receipts are not gated here
208
+ (verified via their Fulcio cert at re-verify time)."""
209
  if scheme != "ecdsa-p256-dsse-pae":
210
  return True
211
+ return _ecdsa_envelope_verifies(env, _corpus_trusted_pub_pems())
212
 
213
 
214
  # --------------------------------------------------------------------------- #