Skip to content

[Security] Add cryptographically verifiable release artifacts #24

Description

@Rwanbt

Problem

Release integrity currently stops at SHA-256. ainative update verifies the
release archive digest before writing a byte, and docs/DISTRIBUTION-LIFECYCLE.md
section 11 states the boundary precisely: the digest detects corruption or a
substituted archive on the wire, but does not protect against a
compromised release source - whoever controls the release controls both
the archive and its digest.

Expected outcome

Cryptographically verifiable release artifacts, so a client can confirm a
release came from the maintainers, not just that it matches a digest the same
source published.

Acceptance criteria

  • Investigation note comparing: Sigstore/cosign keyless signing, signed Git tags, and GitHub release attestations
  • A chosen mechanism with its key-management story written down (who signs, from where, what recovery looks like)
  • ainative update verifies the new signature and fails closed on mismatch, with a clear error distinct from UPDATE_INTEGRITY_FAILED
  • A stated threat model delta: what attacks are covered after this change that were not covered before
  • Signing is claimed in the docs only after it is actually enforced by the updater

Context

  • Current, accurately stated boundary: docs/DISTRIBUTION-LIFECYCLE.md section 8 ("Integrity, stated precisely") and UPDATING.md
  • The archive path/entry validation and size bounds are independent and stay

Out of scope

  • Implying a current vulnerability: there is none inside the declared threat model - this is hardening against a stronger adversary
  • Repackaging or changing the archive format

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    priority:P2Useful improvementtype:securitySecurity hardening or threat-model work

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions