Conversation
Release encode, decode and signing move into marketplace_abi, so the tool that writes the index and the capsule that reads it share a codec instead of having one each. install_ready checks arch and readiness against the running image rather than the index, and adds a seventh gate for whether a release carries a zk trailer for its own measurement. The other six are signatures over the artifact. The catalogue generator reads what is on disk and writes JSON; the CLI encodes the binary the market ingests. Signing is a separate step with the operator seed, which is not in any build rule.
dc64ce2 to
bd5704e
Compare
IconId::Store points table.rs at assets/icons/store.a8, which only existed on the app-store branch, so every build of this branch failed to read it. Add the mask and its SVG source here so the table stands on its own.
nonos-data/marketplace/index.bin has no make rule, so naming it as a hard prerequisite failed every build on a checkout without it (CI: No rule to make target). Wrapping it in $(wildcard) keeps the rebuild on a newer catalogue where it exists and drops the prerequisite where it does not.
The branch's manifest predated the switch to in-process Ed25519 and dropped the dependency while verify/crypto.rs imports it, so the capsule failed with an unresolved import. Restore main's manifest and add only the app_skeleton dependency boot_index.rs needs.
|
@eKisNonos Review before merge Scope: marketplace release codec v2 ( Our changes: merged origin/main ( Findings:
Verdict: hold — blocked on the missing signed baseline index. |
|
Reviewed at Verdict: Comment. The release-check work is the right idea and the wire change is done correctly on both sides. One gate is weaker than its name suggests, and the CI on this head is too old to tell anyone anything. The new gate is wired into the verdict, not just reported
let install_ready = index_signature_valid
&& validation_passed
&& package_url_present
&& package_hash_present
&& manifest_hash_present
&& publisher_signature_verified
&& arch_match
&& kernel_abi_compatible
&& attestation_present;That is the part that is easy to get wrong — adding a field to a readiness struct, surfacing it in the UI, and forgetting to make it block. It blocks. And the 6→7 byte wire change is coherent across both sides of the boundary, which in this codebase is where these things usually drift. Userland Important1. // Everything above this line is somebody's word.
let minted_locally = release.supported_arches.iter().any(|a| a.as_str() == LOCAL_ARCH);
let ships_proof = release.zk_trailer_hash.iter().any(|&b| b != 0);
let attestation_present = ships_proof || minted_locally;
Two things follow. The comment places a trust boundary and then crosses it. "Everything above this line is somebody's word" implies the two lines below it are not — but And the name is doing work the code does not. Net effect: any release whose index entry declares I suspect it is deliberate and necessary: a Debian or Alpine package cannot carry a NONOS zk trailer, so hosted-arch releases need some exemption or the gate blocks the whole personality use case. If so, the ask is narrow — rename it to what it tests ( 2. The CI on this head predates the gates it would now have to pass.
Status The same applies to the rest: Nothing to fix in the diff. But no verdict on this PR's CI means anything until it is rebased and re-run, and with 213 commits of drift the rebase is the first piece of work, not the last. Minor
Questions
Verified correct
CI at this headFifteen lanes pass, the rest are nine days stale against a |
|
Superseded. This work is integrated into the 0.9.2 release and ships in the current tree. Closing as part of the 0.9.2 consolidation. |
Release encode, decode and signing move into
marketplace_abi. The tool writing the index and the capsule reading it had a codec each, over the same structure.install_readychecks arch and readiness against the running image instead of believing the index, and gains a seventh gate for whether a release carries a zk trailer for its own measurement. The other six are signatures over the artifact, so this is a different question and counted separately.Tooling: the catalogue generator reads what is on disk and writes JSON, the CLI encodes the binary the market ingests. Signing is a separate step with the operator seed and does not appear in a build rule. Only the public key is committed.