feat(distribution): complete PP-M8 package trust - #50
Merged
Merged
Conversation
Accept ADR-0005 to fix the detached DSSE and Ed25519 envelope, host-owned publisher trust, independent permission decisions, anti-rollback state, and explicit rollback semantics before implementation. Refs: PP-M8, PP-G2, PP-G3, PP-G10, NFR-SEC-02, NFR-LEGAL-01, ADR-0005 Tests: cargo fmt --all -- --check; git diff --check Unverified: cryptographic implementation, trust persistence, install/upgrade integration, Windows/macOS/Linux behavior, license gate
Add bounded detached DSSE envelope parsing, Ed25519 verification, signable package digests, and host-owned publisher key binding in floatile-core. Keep signature trust separate from capability authorization. Refs: PP-M8, PP-G2, PP-G3, PP-G10, NFR-SEC-02, ADR-0005 Tests: cargo test -p floatile-core; cargo check --workspace --all-targets --locked; cargo clippy --workspace --all-targets --locked -- -D warnings; cargo deny --locked check advisories bans sources; cargo fmt --all -- --check; git diff --check Unverified: full workspace test and wasm32-wasip2 check could not complete because the 103G target directory exhausted disk space; license gate remains blocked by the existing Slint/licensing ADR; trust persistence, CLI install integration, anti-rollback, and three-host behavior
Add the append-only v6 migration and transactional store APIs for host-owned publisher keys, publisher/key revocation, and the highest accepted package version and digest. Reject downgrade and same-version replacement without lowering the rollback high-water mark. Refs: PP-M8, PP-G2, PP-G3, PP-G10, NFR-SEC-02, ADR-0005 Tests: cargo test -p floatile-store --locked; cargo clippy -p floatile-store --all-targets --locked -- -D warnings; cargo check --workspace --all-targets --locked; cargo clippy --workspace --all-targets --locked -- -D warnings; cargo fmt --all -- --check; git diff --check Unverified: CLI install policy integration, explicit rollback orchestration, permission diff, Windows/macOS persistence behavior, full workspace tests, license gate
Add the append-only v7 pending installation journal and bounded prepare, finalize, abort, and recovery queries. Preparing does not advance anti-rollback state; finalization rechecks trust and supports cleanup after acceptance committed before journal removal. Refs: PP-M8, PP-G3, PP-G10, NFR-SEC-02, ADR-0005 Tests: cargo test -p floatile-store --locked; cargo clippy -p floatile-store --all-targets --locked -- -D warnings; cargo check --workspace --all-targets --locked; cargo fmt --all -- --check; git diff --check Unverified: CLI filesystem recovery integration, crash injection around rename, Windows/macOS filesystem behavior, full workspace tests, license gate
Add host trust administration, --require-trusted install policy, detached signature and revocation diagnostics, anti-rollback enforcement, and recovery of crash-interrupted staging or renamed installs. Preserve the existing unsigned development path with an explicit trust result. Refs: PP-M8, PP-G2, PP-G3, PP-G10, NFR-SEC-02, ADR-0005 Tests: cargo test -p floatile-core distribution --locked; cargo test -p floatile-store trust::tests --locked; cargo test -p floatile-cli install::tests --locked; cargo test -p floatile-cli trust::tests --locked; cargo clippy --workspace --all-targets --locked -- -D warnings; cargo fmt --all -- --check; git diff --check Unverified: permission diff and confirmation, explicit rollback command, install trust metadata in shell, Windows/macOS crash recovery, full workspace tests, license gate
Build deterministic upgrade plans that reject identity and migration regressions, classify capability additions, removals, expansions, and reductions, and require confirmation whenever candidate authority grows. Refs: PP-M8, PP-G2, PP-G3, NFR-SEC-01, NFR-SEC-02, ADR-0005 Tests: cargo fmt --all -- --check; git diff --check; cargo --config 'build.rustc-wrapper=""' check --workspace --all-targets --locked; RUSTC_WRAPPER= cargo clippy --workspace --all-targets --locked -- -D warnings; RUSTC_WRAPPER= cargo test -p floatile-core --locked Unverified: CLI permission confirmation, Connection binding diff, explicit rollback, Shell trust enforcement, three-host behavior, full workspace tests, and license gate
Compare trusted upgrade candidates with the highest verified installation before staging. Refuse added or expanded authority until the caller passes an explicit acceptance flag, while reporting deterministic permission changes and allowing pure reductions. Refs: PP-M8, PP-G2, PP-G3, NFR-SEC-01, NFR-SEC-02, ADR-0005 Tests: cargo fmt --all -- --check; git diff --check; RUSTC_WRAPPER= cargo test -p floatile-cli install --locked; RUSTC_WRAPPER= cargo test -p floatile-cli --test author_output --locked; RUSTC_WRAPPER= cargo clippy -p floatile-cli --all-targets --locked -- -D warnings; RUSTC_WRAPPER= cargo check --workspace --all-targets --locked Unverified: interactive confirmation UI, Connection binding diff, explicit rollback, Shell trust enforcement, three-host behavior, full workspace tests, and license gate
Rebind stopped instances to a currently trusted historical installation only after digest, signature, identity, migration, and permission checks. Persist the instance change and bounded rollback reason atomically while preserving the anti-rollback high-water mark. Refs: PP-M8, PP-G2, PP-G3, NFR-SEC-01, NFR-SEC-02, ADR-0005 Tests: cargo fmt --all -- --check; git diff --check; RUSTC_WRAPPER= cargo test -p floatile-core distribution --locked; RUSTC_WRAPPER= cargo test -p floatile-store --locked; RUSTC_WRAPPER= cargo test -p floatile-cli explicit_rollback --locked; RUSTC_WRAPPER= cargo clippy --workspace --all-targets --locked -- -D warnings; RUSTC_WRAPPER= cargo check --workspace --all-targets --locked Unverified: Connection binding rollback diff, Shell trust enforcement, three-host behavior, full workspace tests, and license gate
Persist whether an installation used the unsigned development path or the trusted distribution path. Re-verify trusted installations against current publisher and key trust before persistent startup or retry, while preserving a visibly marked backwards-compatible unsigned development path. Refs: PP-M8, PP-G2, PP-G3, NFR-SEC-01, NFR-SEC-02, ADR-0005 Tests: cargo fmt --all -- --check; git diff --check; RUSTC_WRAPPER= cargo test -p floatile-core install --locked; RUSTC_WRAPPER= cargo test -p floatile-cli trusted_install --locked; RUSTC_WRAPPER= cargo test -p floatile-shell plugin_manager --locked; RUSTC_WRAPPER= cargo test -p floatile-shell instance_supervisor --locked; RUSTC_WRAPPER= cargo clippy --workspace --all-targets --locked -- -D warnings; RUSTC_WRAPPER= cargo check --workspace --all-targets --locked Unverified: three-host signed runtime behavior, full workspace tests, and license gate; Cargo reports the pre-existing clock-wasm output filename collision warning
Record the completed automated distribution and trust contract, including signed install recovery, permission-safe upgrades, explicit rollback, runtime trust revalidation, unchanged Connection grants, and the remaining license and cross-platform release boundaries. Refs: PP-M8, PP-G2, PP-G3, NFR-LEGAL-01, ADR-0005 Tests: cargo fmt --all -- --check; git diff --check; RUSTC_WRAPPER= cargo check --workspace --all-targets --locked; RUSTC_WRAPPER= cargo clippy --workspace --all-targets --locked -- -D warnings; RUSTC_WRAPPER= cargo test --workspace --all-targets --locked; RUSTC_WRAPPER= cargo check -p floatile-sdk --target wasm32-wasip2 --locked; RUSTC_WRAPPER= cargo deny --locked check advisories bans sources Unverified: Windows, macOS, and Wayland signed distribution runtime behavior; cargo deny --locked check licenses remains blocked by NFR-LEGAL-01 and rejected Slint/CDLA licenses
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Security boundaries
Signature trust remains independent from PermissionBroker grants. Downgrades and same-version replacements are rejected by default. Explicit rollback does not lower the high-water mark, requires a currently trusted historical Installation, equal storage migration state, no restored authority, and an atomic bounded reason audit. Existing Connection grants remain unchanged; any future rebinding continues through the PP-M5 authorization path.
Verification
The full workspace test required network access for the SDK package test and passed after rerun. cargo-deny reports existing duplicate/yanked warnings but exits successfully for advisories, bans, and sources.
Release boundary
cargo deny --locked check licenses remains intentionally failing for Slint license alternatives and CDLA-Permissive-2.0 under NFR-LEGAL-01. No public distribution artifact is created. Windows, macOS, and Wayland signed-runtime behavior remains unverified and belongs to PP-M10 platform evidence.