Spaces:
Running
Running
chore(sync): mirror backend .py + Dockerfile to Space (hf-sync-backend)
Browse filesAutomated backend sync from szl-holdings/a11oy main via hf-sync-backend.
Updated (differed from the Space): szl_corpus_publish.py
Deleted (gone from the repo + Dockerfile COPY set): (none)
Keeps the Space-built backend (serve.py + the Dockerfile-COPY'd .py
modules) identical to GitHub main so the Space never rebuilds from a
stale backend, new endpoints don't 404 there, and orphaned modules
removed from the repo don't linger in the Space tree.
- szl_corpus_publish.py +47 -29
szl_corpus_publish.py
CHANGED
|
@@ -119,17 +119,21 @@ def _canon(obj: Any) -> bytes:
|
|
| 119 |
# Verify-before-publish gate
|
| 120 |
# --------------------------------------------------------------------------- #
|
| 121 |
# The published corpus advertises that every ecdsa-p256-dsse-pae receipt verifies
|
| 122 |
-
# against
|
| 123 |
-
# (.github/hf-corpus-guards.json ->
|
| 124 |
-
# signed by a transient
|
| 125 |
-
#
|
| 126 |
-
#
|
| 127 |
-
#
|
| 128 |
-
#
|
|
|
|
|
|
|
|
|
|
|
|
|
| 129 |
#
|
| 130 |
-
# The
|
| 131 |
# source of truth; the embedded copy is only a fallback for a runtime that does
|
| 132 |
-
# not ship the .github config. Keep it in sync with that file's
|
| 133 |
_CORPUS_COSIGN_PUB_PEM_FALLBACK = (
|
| 134 |
"-----BEGIN PUBLIC KEY-----\n"
|
| 135 |
"MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE/Jlv9FnwJ13l4QIZpr4IbTBUtVZ2\n"
|
|
@@ -138,26 +142,35 @@ _CORPUS_COSIGN_PUB_PEM_FALLBACK = (
|
|
| 138 |
)
|
| 139 |
|
| 140 |
|
| 141 |
-
def
|
| 142 |
-
"""Return the
|
| 143 |
-
guard config (single source of truth)
|
|
|
|
|
|
|
| 144 |
cfg_path = os.path.join(
|
| 145 |
os.path.dirname(os.path.abspath(__file__)),
|
| 146 |
".github", "hf-corpus-guards.json")
|
| 147 |
try:
|
| 148 |
with open(cfg_path, "r", encoding="utf-8") as fh:
|
| 149 |
-
|
| 150 |
-
|
| 151 |
-
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 152 |
except Exception:
|
| 153 |
pass
|
| 154 |
-
return _CORPUS_COSIGN_PUB_PEM_FALLBACK
|
| 155 |
|
| 156 |
|
| 157 |
-
def _ecdsa_envelope_verifies(env: Dict[str, Any],
|
| 158 |
"""True iff at least one of the envelope's signatures verifies over its DSSE
|
| 159 |
-
PAE against
|
| 160 |
-
returns False so an envelope we cannot vouch for
|
|
|
|
| 161 |
try:
|
| 162 |
import base64
|
| 163 |
from cryptography.hazmat.primitives.serialization import load_pem_public_key
|
|
@@ -170,14 +183,18 @@ def _ecdsa_envelope_verifies(env: Dict[str, Any], pub_pem: str) -> bool:
|
|
| 170 |
body = base64.b64decode(env.get("payload", "") or b"")
|
| 171 |
pt = str(env.get("payloadType", ""))
|
| 172 |
pae = b"DSSEv1 %d %s %d %s" % (len(pt.encode()), pt.encode(), len(body), body)
|
| 173 |
-
|
| 174 |
-
for s in env.get("signatures") or []:
|
| 175 |
try:
|
| 176 |
-
pub
|
| 177 |
-
|
| 178 |
-
return True
|
| 179 |
-
except InvalidSignature:
|
| 180 |
continue
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 181 |
return False
|
| 182 |
except Exception:
|
| 183 |
return False
|
|
@@ -185,12 +202,13 @@ def _ecdsa_envelope_verifies(env: Dict[str, Any], pub_pem: str) -> bool:
|
|
| 185 |
|
| 186 |
def _publishable_against_corpus_key(env: Dict[str, Any], scheme: str) -> bool:
|
| 187 |
"""Verify-before-publish gate. ecdsa-p256-dsse-pae receipts are published only
|
| 188 |
-
if they verify against the
|
| 189 |
-
envelope can never enter the
|
| 190 |
-
|
|
|
|
| 191 |
if scheme != "ecdsa-p256-dsse-pae":
|
| 192 |
return True
|
| 193 |
-
return _ecdsa_envelope_verifies(env,
|
| 194 |
|
| 195 |
|
| 196 |
# --------------------------------------------------------------------------- #
|
|
|
|
| 119 |
# Verify-before-publish gate
|
| 120 |
# --------------------------------------------------------------------------- #
|
| 121 |
# The published corpus advertises that every ecdsa-p256-dsse-pae receipt verifies
|
| 122 |
+
# against the DOCUMENTED TRUSTED KEYSET the CI re-verify guard checks
|
| 123 |
+
# (.github/hf-corpus-guards.json -> trusted_keys). Incident #325: two receipts
|
| 124 |
+
# signed by a transient ephemeral-pod key (NOT a documented org key) were
|
| 125 |
+
# published and could no longer re-verify. Root cause: the gate verified against
|
| 126 |
+
# a SINGLE pinned key, so during an org cosign-key rotation an envelope signed by
|
| 127 |
+
# any other key could slip in (either wrongly rejected, or — when the pin lagged
|
| 128 |
+
# the rotation — published against a stale pin and then failing re-verify). The
|
| 129 |
+
# gate now re-verifies each signed envelope against the SAME multi-key trust set
|
| 130 |
+
# the guard uses; an envelope that verifies under NONE of the trusted keys is
|
| 131 |
+
# skipped (honestly, like an UNSIGNED one) — never published. This makes a
|
| 132 |
+
# transient/untrusted-key receipt impossible to publish going forward.
|
| 133 |
#
|
| 134 |
+
# The trusted PEMs are read from the guard config so producer and guard share one
|
| 135 |
# source of truth; the embedded copy is only a fallback for a runtime that does
|
| 136 |
+
# not ship the .github config. Keep it in sync with that file's trusted_keys.
|
| 137 |
_CORPUS_COSIGN_PUB_PEM_FALLBACK = (
|
| 138 |
"-----BEGIN PUBLIC KEY-----\n"
|
| 139 |
"MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE/Jlv9FnwJ13l4QIZpr4IbTBUtVZ2\n"
|
|
|
|
| 142 |
)
|
| 143 |
|
| 144 |
|
| 145 |
+
def _corpus_trusted_pub_pems() -> List[str]:
|
| 146 |
+
"""Return the DOCUMENTED trusted-key PEMs the corpus re-verifies against.
|
| 147 |
+
Reads the CI guard config (single source of truth): the multi-key
|
| 148 |
+
trusted_keys set, falling back to the legacy single cosign_pub_pem, then to
|
| 149 |
+
the embedded copy. A receipt must verify under one of these to publish."""
|
| 150 |
cfg_path = os.path.join(
|
| 151 |
os.path.dirname(os.path.abspath(__file__)),
|
| 152 |
".github", "hf-corpus-guards.json")
|
| 153 |
try:
|
| 154 |
with open(cfg_path, "r", encoding="utf-8") as fh:
|
| 155 |
+
cfg = json.load(fh)
|
| 156 |
+
pems = [k.get("pem") for k in (cfg.get("trusted_keys") or [])
|
| 157 |
+
if isinstance(k, dict) and isinstance(k.get("pem"), str)
|
| 158 |
+
and "BEGIN PUBLIC KEY" in k.get("pem")]
|
| 159 |
+
if pems:
|
| 160 |
+
return pems
|
| 161 |
+
single = cfg.get("cosign_pub_pem")
|
| 162 |
+
if isinstance(single, str) and "BEGIN PUBLIC KEY" in single:
|
| 163 |
+
return [single]
|
| 164 |
except Exception:
|
| 165 |
pass
|
| 166 |
+
return [_CORPUS_COSIGN_PUB_PEM_FALLBACK]
|
| 167 |
|
| 168 |
|
| 169 |
+
def _ecdsa_envelope_verifies(env: Dict[str, Any], pub_pems: List[str]) -> bool:
|
| 170 |
"""True iff at least one of the envelope's signatures verifies over its DSSE
|
| 171 |
+
PAE against at least one of the trusted pub_pems. Conservative: any error
|
| 172 |
+
(incl. missing cryptography) returns False so an envelope we cannot vouch for
|
| 173 |
+
is NOT published."""
|
| 174 |
try:
|
| 175 |
import base64
|
| 176 |
from cryptography.hazmat.primitives.serialization import load_pem_public_key
|
|
|
|
| 183 |
body = base64.b64decode(env.get("payload", "") or b"")
|
| 184 |
pt = str(env.get("payloadType", ""))
|
| 185 |
pae = b"DSSEv1 %d %s %d %s" % (len(pt.encode()), pt.encode(), len(body), body)
|
| 186 |
+
for pub_pem in pub_pems:
|
|
|
|
| 187 |
try:
|
| 188 |
+
pub = load_pem_public_key(pub_pem.encode("utf-8"))
|
| 189 |
+
except Exception:
|
|
|
|
|
|
|
| 190 |
continue
|
| 191 |
+
for s in env.get("signatures") or []:
|
| 192 |
+
try:
|
| 193 |
+
pub.verify(base64.b64decode(s.get("sig", "") or ""), pae,
|
| 194 |
+
ec.ECDSA(hashes.SHA256()))
|
| 195 |
+
return True
|
| 196 |
+
except InvalidSignature:
|
| 197 |
+
continue
|
| 198 |
return False
|
| 199 |
except Exception:
|
| 200 |
return False
|
|
|
|
| 202 |
|
| 203 |
def _publishable_against_corpus_key(env: Dict[str, Any], scheme: str) -> bool:
|
| 204 |
"""Verify-before-publish gate. ecdsa-p256-dsse-pae receipts are published only
|
| 205 |
+
if they verify against the DOCUMENTED trusted keyset (historical + current org
|
| 206 |
+
keys), so a transient/rotated/untrusted-key envelope can never enter the
|
| 207 |
+
corpus and later fail re-verify. sigstore-keyless receipts are not gated here
|
| 208 |
+
(verified via their Fulcio cert at re-verify time)."""
|
| 209 |
if scheme != "ecdsa-p256-dsse-pae":
|
| 210 |
return True
|
| 211 |
+
return _ecdsa_envelope_verifies(env, _corpus_trusted_pub_pems())
|
| 212 |
|
| 213 |
|
| 214 |
# --------------------------------------------------------------------------- #
|