Problem
Release integrity currently stops at SHA-256. ainative update verifies the
release archive digest before writing a byte, and docs/DISTRIBUTION-LIFECYCLE.md
section 11 states the boundary precisely: the digest detects corruption or a
substituted archive on the wire, but does not protect against a
compromised release source - whoever controls the release controls both
the archive and its digest.
Expected outcome
Cryptographically verifiable release artifacts, so a client can confirm a
release came from the maintainers, not just that it matches a digest the same
source published.
Acceptance criteria
Context
- Current, accurately stated boundary:
docs/DISTRIBUTION-LIFECYCLE.md section 8 ("Integrity, stated precisely") and UPDATING.md
- The archive path/entry validation and size bounds are independent and stay
Out of scope
- Implying a current vulnerability: there is none inside the declared threat model - this is hardening against a stronger adversary
- Repackaging or changing the archive format
Problem
Release integrity currently stops at SHA-256.
ainative updateverifies therelease archive digest before writing a byte, and
docs/DISTRIBUTION-LIFECYCLE.mdsection 11 states the boundary precisely: the digest detects corruption or a
substituted archive on the wire, but does not protect against a
compromised release source - whoever controls the release controls both
the archive and its digest.
Expected outcome
Cryptographically verifiable release artifacts, so a client can confirm a
release came from the maintainers, not just that it matches a digest the same
source published.
Acceptance criteria
ainative updateverifies the new signature and fails closed on mismatch, with a clear error distinct fromUPDATE_INTEGRITY_FAILEDContext
docs/DISTRIBUTION-LIFECYCLE.mdsection 8 ("Integrity, stated precisely") andUPDATING.mdOut of scope