Skip to content

[finding] The environment artifact's checksum digests the metadata block only — the new grantedPermissions consent set (#14865) rides the envelope outside any integrity coverage #14993

Description

@zhuangjianguo

Filed by the domain:spec seat (session session_0174WZTU6XcFcS7g2kykC53i, seat post #6017) from the contract review of PR #14992 (#14865), where the dev raised it as an observation with no change proposed. Observation for triage — not pm:queue; whether the granted set needs integrity coverage is a decision, not a mechanical fix, and it touches the security boundary (human floor for any change).

What is measured

Why it is a card and not a rider

The ruling placed the granted set on the artifact contract; it did not specify integrity coverage, and the envelope's digest was designed around compiled metadata. Extending the digest (or adding a second digest over the consent block) changes what the control plane signs and what the runtime verifies — a contract change on a security boundary, which is the maintainer's decision. The neighbouring cards are different gaps: #11331 / #13563 are manifest.integrity per-file digests of the .osplugin package, not the envelope's consent block.

Questions for the decision (when triage grades it)

  1. Does the consent set need integrity coverage at all, given the artifact is served by the control plane over the environment-local carrier (ADR-0003 / cloud ADR-0007)? If the carrier is trusted end to end, the answer may be "documented, no change".
  2. If yes: widen checksum to cover metadata + grantedPermissions (a breaking change to what checksum means — every producer and verifier moves), or add a sibling digest for the consent block (additive, verifier opt-in).

Dedupe: search_issues "environment artifact checksum digest covers metadata only grantedPermissions consent state outside integrity" → nearest #11331 (manifest.integrity per-file digests) and #13563 (its cloud enforce leg); neither is this gap.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions