mirror of
https://github.com/garrytan/gstack.git
synced 2026-09-16 18:05:31 +02:00
* feat(cso): add verified audits and replayable repair bundles * fix(cso): harden qualification and setup boundaries * fix(cso): assemble security canaries at runtime * fix(cso): bound release proof and maintenance work Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): require complete evaluation reports Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): replay expired snapshots from supplied source Co-Authored-By: OpenAI Codex <noreply@openai.com> * test(cso): synchronize DNS cancellation assertion Co-Authored-By: OpenAI Codex <noreply@openai.com> * chore(ship): exempt repository owner from liveness proof Co-Authored-By: OpenAI Codex <noreply@openai.com> * test(cso): make recheck retention overlap deterministic Co-Authored-By: OpenAI Codex <noreply@openai.com> * chore: bump version and changelog (v1.85.0.0) Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): pass native release gates Co-Authored-By: OpenAI Codex <noreply@openai.com> * chore: move release to v1.86.0.0 Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): resolve rechecks by finding Co-Authored-By: OpenAI Codex <noreply@openai.com> * chore: move release to v1.87.0.0 Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): pass macOS and Windows release gates Normalize BSD wc output, compare Windows paths by filesystem identity, preserve portable snapshot race coverage, and narrow POSIX-only Windows fixtures. Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): harden native verification gates * fix(cso): refine Windows native diagnostics * test(cso): isolate Windows Git startup failure * test(cso): stabilize Windows native diagnostics * fix(cso): support hardened Git on Windows * fix(cso): close final verification gaps * test(cso): bound cold Docker fixture setup * fix(cso): restore cross-platform free-suite gates --------- Co-authored-by: OpenAI Codex <noreply@openai.com>
182 lines
9.4 KiB
YAML
182 lines
9.4 KiB
YAML
name: Propose CSO Runtime Catalog Promotion
|
|
|
|
# This workflow never deploys a catalog. It converts authenticated
|
|
# same-repository qualification artifacts into an attested candidate, verifies
|
|
# those exact bytes, and opens a normal source-review PR from a protected job.
|
|
on:
|
|
workflow_dispatch:
|
|
inputs:
|
|
qualification_run_id:
|
|
description: Successful protected-main run containing cso-qualified-runtime-statements
|
|
required: true
|
|
type: string
|
|
|
|
permissions:
|
|
contents: read
|
|
actions: read
|
|
|
|
concurrency:
|
|
group: cso-runtime-catalog-promotion
|
|
cancel-in-progress: false
|
|
|
|
jobs:
|
|
propose:
|
|
if: github.ref == 'refs/heads/main' && github.event_name == 'workflow_dispatch'
|
|
runs-on: ubuntu-24.04
|
|
timeout-minutes: 40
|
|
environment: cso-runtime-release
|
|
permissions:
|
|
contents: write
|
|
pull-requests: write
|
|
actions: read
|
|
packages: read
|
|
id-token: write
|
|
attestations: write
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
|
with:
|
|
persist-credentials: true
|
|
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6
|
|
with:
|
|
bun-version: 1.4.0
|
|
- name: Authenticate the completed qualification run
|
|
env:
|
|
GH_TOKEN: ${{ github.token }}
|
|
CSO_QUALIFICATION_RUN: ${{ inputs.qualification_run_id }}
|
|
run: |
|
|
set -euo pipefail
|
|
case "$CSO_QUALIFICATION_RUN" in
|
|
''|*[!0-9]*) echo 'qualification_run_id must be numeric' >&2; exit 1 ;;
|
|
esac
|
|
gh api "repos/$GITHUB_REPOSITORY/actions/runs/$CSO_QUALIFICATION_RUN" > qualification-run.json
|
|
jq -e '
|
|
.status == "completed" and .conclusion == "success" and
|
|
.head_branch == "main" and .event == "repository_dispatch" and
|
|
.path == ".github/workflows/cso-runtime-qualification.yml" and
|
|
(.head_sha | test("^[a-f0-9]{40}$"))
|
|
' qualification-run.json
|
|
mkdir qualification-evidence
|
|
gh run download "$CSO_QUALIFICATION_RUN" --repo "$GITHUB_REPOSITORY" \
|
|
--name cso-qualified-runtime-statements --dir qualification-evidence
|
|
- name: Generate a fail-closed catalog candidate
|
|
env:
|
|
CSO_QUALIFICATION_RUN: ${{ inputs.qualification_run_id }}
|
|
run: |
|
|
set -euo pipefail
|
|
bun run scripts/cso-runtime-promotion.ts \
|
|
--evidence-root qualification-evidence \
|
|
--output runtime-catalog.candidate.json
|
|
source_commit="$(jq -er '.promotion.sourceCommit' runtime-catalog.candidate.json)"
|
|
workflow="$(jq -er '.promotion.workflow' runtime-catalog.candidate.json)"
|
|
test "$workflow" = "https://github.com/$GITHUB_REPOSITORY/actions/runs/$CSO_QUALIFICATION_RUN"
|
|
qualification_head="$(jq -er '.head_sha' qualification-run.json)"
|
|
gh api "repos/$GITHUB_REPOSITORY/compare/$source_commit...$qualification_head" > source-ancestry.json
|
|
jq -e '.status == "ahead" or .status == "identical"' source-ancestry.json
|
|
bun -e '
|
|
import candidate from "./runtime-catalog.candidate.json";
|
|
import {validateRuntimeCatalog} from "./lib/cso/runtime-catalog";
|
|
validateRuntimeCatalog(candidate);
|
|
'
|
|
bun run scripts/cso-runtime-promotion.ts validate-transition \
|
|
lib/cso/runtime-catalog.json runtime-catalog.candidate.json
|
|
- name: Prove the promotion and catalog contracts before signing
|
|
run: |
|
|
set -euo pipefail
|
|
bun install --frozen-lockfile --ignore-scripts
|
|
bun test --max-concurrency 1 test/cso-runtime-promotion.test.ts test/cso-distribution.test.ts
|
|
- name: Recheck public visibility and anonymous pulls before promotion
|
|
env:
|
|
GH_TOKEN: ${{ github.token }}
|
|
run: |
|
|
set -euo pipefail
|
|
mkdir public-image-evidence
|
|
jq -c '.runtimes[]' runtime-catalog.candidate.json | while IFS= read -r runtime; do
|
|
runtime_id="$(printf '%s' "$runtime" | jq -er '.id | select(test("^[a-z0-9][a-z0-9._-]{0,100}$"))')"
|
|
image="$(printf '%s' "$runtime" | jq -er '.image')"
|
|
platform="$(printf '%s' "$runtime" | jq -er '.platform | select(. == "linux/amd64" or . == "linux/arm64")')"
|
|
bun run scripts/cso-public-ghcr.ts verify \
|
|
--image "$image" --platform "$platform" --repository "$GITHUB_REPOSITORY" \
|
|
--output "public-image-evidence/$runtime_id.json" --remove-after
|
|
done
|
|
- name: Attest the exact review candidate
|
|
uses: actions/attest@f7c74d28b9d84cb8768d0b8ca14a4bac6ef463e6
|
|
with:
|
|
subject-path: runtime-catalog.candidate.json
|
|
- name: Verify and record the exact candidate attestation
|
|
env:
|
|
GH_TOKEN: ${{ github.token }}
|
|
CSO_QUALIFICATION_RUN: ${{ inputs.qualification_run_id }}
|
|
run: |
|
|
set -euo pipefail
|
|
candidate_sha256="sha256:$(sha256sum runtime-catalog.candidate.json | cut -d ' ' -f 1)"
|
|
subject_sha256="${candidate_sha256#sha256:}"
|
|
signer="https://github.com/$GITHUB_REPOSITORY/.github/workflows/cso-runtime-promote.yml@refs/heads/main"
|
|
verified=0
|
|
for attempt in 1 2 3; do
|
|
if gh attestation verify runtime-catalog.candidate.json --repo "$GITHUB_REPOSITORY" \
|
|
--cert-identity "$signer" --source-ref refs/heads/main --source-digest "$GITHUB_SHA" \
|
|
--deny-self-hosted-runners --predicate-type https://slsa.dev/provenance/v1 \
|
|
--format json > candidate-attestation-verification.tmp; then
|
|
mv candidate-attestation-verification.tmp candidate-attestation-verification.json
|
|
verified=1
|
|
break
|
|
fi
|
|
rm -f candidate-attestation-verification.tmp
|
|
if test "$attempt" -lt 3; then sleep "$((attempt * 5))"; fi
|
|
done
|
|
test "$verified" -eq 1
|
|
statement_set_digest="$(bun run scripts/cso-attestation-evidence.ts digest \
|
|
candidate-attestation-verification.json https://slsa.dev/provenance/v1 "$subject_sha256")"
|
|
test "$candidate_sha256" = "sha256:$(sha256sum runtime-catalog.candidate.json | cut -d ' ' -f 1)"
|
|
jq -n --arg candidateSha256 "$candidate_sha256" \
|
|
--arg statementSetDigest "$statement_set_digest" --arg signer "$signer" \
|
|
--arg sourceCommit "$GITHUB_SHA" --arg qualificationRun "$CSO_QUALIFICATION_RUN" \
|
|
'{schemaVersion:1,candidateSha256:$candidateSha256,verifiedStatementSetDigest:$statementSetDigest,signer:$signer,sourceCommit:$sourceCommit,qualificationRun:$qualificationRun}' \
|
|
> candidate-attestation-evidence.json
|
|
- name: Commit the exact verified candidate and open its review PR
|
|
env:
|
|
GH_TOKEN: ${{ github.token }}
|
|
CSO_QUALIFICATION_RUN: ${{ inputs.qualification_run_id }}
|
|
run: |
|
|
set -euo pipefail
|
|
expected_candidate_sha256="$(jq -er '.candidateSha256 | select(test("^sha256:[a-f0-9]{64}$"))' candidate-attestation-evidence.json)"
|
|
test "$expected_candidate_sha256" = "sha256:$(sha256sum runtime-catalog.candidate.json | cut -d ' ' -f 1)"
|
|
bun run scripts/cso-runtime-promotion.ts validate-transition \
|
|
lib/cso/runtime-catalog.json runtime-catalog.candidate.json
|
|
cp runtime-catalog.candidate.json lib/cso/runtime-catalog.json
|
|
cmp runtime-catalog.candidate.json lib/cso/runtime-catalog.json
|
|
bun -e '
|
|
import candidate from "./lib/cso/runtime-catalog.json";
|
|
import {validateRuntimeCatalog} from "./lib/cso/runtime-catalog";
|
|
validateRuntimeCatalog(candidate);
|
|
'
|
|
bun run build:cso
|
|
branch="cso-runtime-catalog-$GITHUB_RUN_ID-$GITHUB_RUN_ATTEMPT"
|
|
git switch -c "$branch"
|
|
git config user.name github-actions[bot]
|
|
git config user.email 41898282+github-actions[bot]@users.noreply.github.com
|
|
git add lib/cso/runtime-catalog.json
|
|
git commit -m "Promote qualified CSO runtime catalog"
|
|
git show HEAD:lib/cso/runtime-catalog.json > committed-runtime-catalog.json
|
|
cmp runtime-catalog.candidate.json committed-runtime-catalog.json
|
|
test "$expected_candidate_sha256" = "sha256:$(sha256sum committed-runtime-catalog.json | cut -d ' ' -f 1)"
|
|
git push --set-upstream origin "$branch"
|
|
cat > pr-body.md <<EOF
|
|
Promotes the complete CSO runtime catalog from authenticated qualification run $CSO_QUALIFICATION_RUN. The protected promotion workflow verified the exact candidate attestation and committed those same bytes after a previous-revision compare-and-swap.
|
|
|
|
Validation: runtime promotion contracts, distribution contracts, compiled CSO helper build, candidate attestation verification, and exact committed-byte comparison.
|
|
EOF
|
|
gh pr create --base main --head "$branch" --title "Promote qualified CSO runtime catalog" --body-file pr-body.md
|
|
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
|
|
with:
|
|
name: cso-runtime-catalog-candidate
|
|
path: |
|
|
runtime-catalog.candidate.json
|
|
candidate-attestation-verification.json
|
|
candidate-attestation-evidence.json
|
|
committed-runtime-catalog.json
|
|
qualification-run.json
|
|
source-ancestry.json
|
|
if-no-files-found: error
|
|
retention-days: 30
|