Repository navigation
fix(reproducibility): split Witness verification into a FAIL-only step bound to the audited commit (#553) - #565
Merged
mlieberman85 merged 2 commits intoOct 8, 2026
Conversation
…arnitdevorg#553) Witness / in-toto runtime-trace verification moves out of repro_hermetic_build into its own step type with ceiling {fail}, bound to the audited commit and reading only the runtime-trace predicate. A verified empty network log is evidence, not PASS: an absent optional list equals an empty one, and a monitor that does not trace sockets records the same empty log. PASS waits for an allowlist of monitor types. Assisted-by: Claude:claude-opus-5-5 Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
…c_build (darnitdevorg#553) New step type repro_witness_attestation (ceiling {fail}) runs first in RE-02.01. It verifies the attestations of the successful CI runs for the audited commit with a Sigstore policy bound to the repository and that commit, reads network events only from the in-toto runtime-trace v0.1 predicate (monitorLog.network), and keeps the Witness command-run installer scan. Recorded network access concludes FAIL; a verified clean trace is evidence only. Missing prerequisites stay INCONCLUSIVE. repro_hermetic_build no longer calls gh or reads attestations, and verify_witness_attestations moves to the new step. Assisted-by: Claude:claude-opus-5-5 Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
RE-02.01's
repro_hermetic_buildalso fetched and Sigstore-verified Witness / in-toto attestations. It treated a verified, empty network log as a strong PASS signal. #553 proposed splitting that out into its own step type that could conclude PASS. While writing it we found the premise doesn't hold.A verified empty network log is not proof of no network access.
monitorLog.networkrecords tomonitor.typeand itstracePolicy.connectpolicy) has nonetworkfield at all.So this PR does the split, but the new step is FAIL-only:
repro_witness_attestation, ceiling{fail}, runs first in RE-02.01. It verifies attestations from the successful CI runs for the audited commit (git rev-parse HEAD). The signing policy is bound to this repository (GitHubWorkflowRepository) and that commit (GitHubWorkflowSHA). Before, the check took the latest successful run on the default branch.https://in-toto.io/attestation/runtime-trace/v0.1, at the top level or nested in a Witness collection, and onlymonitorLog.networkis read. The old fallbacks accepted anetworkkey on any predicate type. The existing Witnesscommand-runinstaller scan stays as FAIL evidence.gh, no login, no run, no attestation, sigstore not installed) → INCONCLUSIVE with the reason, as today. It's not ERROR: the step can only add FAIL evidence, so a missing optional source shouldn't turn a control's WARN into ERROR.repro_hermetic_buildno longer makes anyghcalls. Theverify_witness_attestationssetting moves to the new step. Under strict step settings, an override that sets it onrepro_hermetic_buildnow fails loading (CHANGELOG, marked BREAKING).Spec changes come first:
framework-design.md3.0.1 and the section 12 table: the step type with its{fail}ceiling and the reason.specs/044-false-pass-paths/contracts/witness-step-addendum-553.md.A PASS from runtime traces needs a built-in allowlist of monitor types whose trace policy records network access, backed by real attestations. That's left for a follow-up.
Refs #553
Type of Change
Framework Changes Checklist
docs/architecture/framework-design.md) if behavior changeduv run python scripts/validate_sync.py --verboseand it passesTesting
uv run pytest tests/ -v): 5252 passed, 26 skippeduv run ruff check .)The reproducibility tests also pass with sigstore installed (338 passed), matching CI's
--all-extras. New tests cover:--commit <sha>and the policy includesGitHubWorkflowSHA(sha); one test uses a real git repo;networkkey on another predicate type is ignored;ghcalls;repro_hermetic_buildmaking noghcalls;{fail}, and the RE-02.01 step order;I also ran a real
darnit audit . -f reproducibilitywith sigstore installed. The step queried runs for the local (unpushed) commit and stayed INCONCLUSIVE ("no successful CI run found for commit …").AI assistance
Claude (Claude Code, claude-opus-5-5) found the in-toto spec issue, and made this change: spec, code, and tests. This description was also drafted with Claude. Commits carry an
Assisted-by: Claude:claude-opus-5-5trailer.Additional Notes
test_no_pass_from_signals._shipped_controlnow deep-copies the cached framework config instead of mutating it. The mutation leaked step settings between tests.🤖 Generated with Claude Code