Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
24 commits
Select commit Hold shift + click to select a range
3ea088b
Model signed device redemption for approvals: APNs, Secure Enclave, A…
Sep 18, 2026
a5d322f
Merge wise-owl-628
Sep 18, 2026
df5a582
Device redemption admission fold, stateless challenge, assertion verd…
Sep 18, 2026
d51fd6a
Signed device redemption, lane A: P-256 ECDSA verify and the ES256 AP…
Sep 18, 2026
3dc42b2
Address #11585 reviews: sole-constructed admission and enrolment, inj…
Sep 18, 2026
da8e3a6
Merge revised #11585 seams: ByteSize sizes, provider token and ECDSA …
Sep 18, 2026
bdd8e15
Optional value is none, not Absent (resolve failure found by lane A);…
Sep 18, 2026
33575e6
Merge #11585 fix-ups
Sep 18, 2026
c492190
Emit the cross-language wire vectors (gunbc.auth.approval_device_rede…
Sep 18, 2026
9aa8fb7
Rename the frontier to its remaining subject: app_attest_verification…
Sep 18, 2026
bdf846f
apns_provider_token takes EpochSecs; the negative-iat refusal is unwr…
Sep 18, 2026
f998bfd
Address reviews 67602/67620/67625 and side-chat round 2
Sep 18, 2026
307a21d
Merge #11585 f998bfd
Sep 18, 2026
df7fa53
List join via concat, not the ambiguous bare concat_lists (found by l…
Sep 18, 2026
7123b08
§4c: drop the prose-only *_note data rows (review 67593); the // bloc…
Sep 18, 2026
cbf5a06
review 67668: register the wire vectors as a generated artifact; CAS …
Sep 18, 2026
48685eb
Import platform_wire and EnrolmentSlotUnreadable explicitly (review 6…
Sep 18, 2026
38705b4
Enrolment codes are issued only by the operator over SSH as the store…
Sep 18, 2026
1cf415f
Merge #11585 df7fa53 (concat_lists fix)
Sep 18, 2026
77cef72
Regenerate witnesses.yml: heal stages the new registered vectors arti…
Sep 18, 2026
cc51797
wip-regrain
Sep 18, 2026
2ab413e
Merge #11585 latest
Sep 18, 2026
7da0a5e
Sign at the raw-signature grain: p256_ecdsa_sign_b64url replaces es25…
Sep 18, 2026
8c6e454
Merge main
Sep 18, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,7 @@ ROADMAP.md merge=generated-artifact
dag/gunbc/stage0/stage0_crate_layout_generated.dag merge=generated-artifact
dag/gunbc/stage0/stage0_crate_partition_generated.dag merge=generated-artifact
dag/gunbc/stage0/stage0_executable_assembly_generated.dag merge=generated-artifact
dag/test/fixture/approval_device_redemption/vectors.json merge=generated-artifact
docs/design-rung-drops.md merge=generated-artifact
docs/onboarding.md merge=generated-artifact
docs/plans/blackjack-onboarding.md merge=generated-artifact
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/witnesses.yml
Original file line number Diff line number Diff line change
Expand Up @@ -552,6 +552,7 @@ jobs:
if [ -e "tools/fabric_ci_fci1_bounded_execution_context.env" ]; then git add "tools/fabric_ci_fci1_bounded_execution_context.env"; else echo "chore-heal: registered generated artifact absent on this tree, not staging: tools/fabric_ci_fci1_bounded_execution_context.env"; fi
if [ -e "src/v1/stage0/src/gunbc_file_transport_generated.rs" ]; then git add "src/v1/stage0/src/gunbc_file_transport_generated.rs"; else echo "chore-heal: registered generated artifact absent on this tree, not staging: src/v1/stage0/src/gunbc_file_transport_generated.rs"; fi
if [ -e "tools/whole_corpus_compile_measured_root_demands.json" ]; then git add "tools/whole_corpus_compile_measured_root_demands.json"; else echo "chore-heal: registered generated artifact absent on this tree, not staging: tools/whole_corpus_compile_measured_root_demands.json"; fi
if [ -e "dag/test/fixture/approval_device_redemption/vectors.json" ]; then git add "dag/test/fixture/approval_device_redemption/vectors.json"; else echo "chore-heal: registered generated artifact absent on this tree, not staging: dag/test/fixture/approval_device_redemption/vectors.json"; fi
if [ -e "provisioning/srv1/gunbc-ghrunner.sudoers" ]; then git add "provisioning/srv1/gunbc-ghrunner.sudoers"; else echo "chore-heal: registered generated artifact absent on this tree, not staging: provisioning/srv1/gunbc-ghrunner.sudoers"; fi
if [ -e "provisioning/srv2/gunbc-ghrunner.sudoers" ]; then git add "provisioning/srv2/gunbc-ghrunner.sudoers"; else echo "chore-heal: registered generated artifact absent on this tree, not staging: provisioning/srv2/gunbc-ghrunner.sudoers"; fi
if [ -e "provisioning/srv3/gunbc-ghrunner.sudoers" ]; then git add "provisioning/srv3/gunbc-ghrunner.sudoers"; else echo "chore-heal: registered generated artifact absent on this tree, not staging: provisioning/srv3/gunbc-ghrunner.sudoers"; fi
Expand Down
187 changes: 187 additions & 0 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

34 changes: 34 additions & 0 deletions dag/extdeps/android/key_attestation.dag
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
module extdeps.android.key_attestation

import std.types { NonEmptyStr, List }
import extdeps.external_authority { ExternalAuthority }
import extdeps.uri { Uri, Https }

// Android Keystore hardware-backed key attestation. A key generated with setAttestationChallenge
// yields an X.509 chain carrying the KeyDescription extension (OID 1.3.6.1.4.1.11129.2.1.17). The
// verifier must NOT assume the extension sits in the leaf: it reads the first occurrence in the
// chain that chains to a trusted root, checks every certificate against Google's revocation list,
// and trusts the CURRENT set of Google attestation roots (more than one; the page lists them). The
// extension carries:
// the attestation challenge, security level (Software / TrustedEnvironment / StrongBox), and the key's
// authorization list (purpose, userAuthenticationType, per-operation auth, attestationApplicationId
// naming the package and signing-certificate digests).
data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority {
uri: Uri {
scheme: Https
locator: "source.android.com/docs/security/features/keystore/attestation"
}
}

data key_description_extension_oid: NonEmptyStr = "1.3.6.1.4.1.11129.2.1.17"

type KeymasterSecurityLevel
= SecurityLevelSoftware
| SecurityLevelTrustedEnvironment
| SecurityLevelStrongBox

// Unlike App Attest, Android attests THE DECISION KEY ITSELF, including whether its use requires
// per-operation biometric authorization -- so no second key is needed to bind app to key.
type AndroidAttestationChain {
certificates_der_b64: List<NonEmptyStr>
}
Loading
Loading