Skip to content

fix(certforge): patched base image + cryptography 50 for P4 sealing (#22) - #23

Open
echoomegaprime wants to merge 3 commits into
agent/popup-monitor-production-e2efrom
agent/certforge-security-release-20260924
Open

echoomegaprime wants to merge 3 commits into
agent/popup-monitor-production-e2efrom
agent/certforge-security-release-20260924

Conversation

@echoomegaprime

@echoomegaprime echoomegaprime commented Sep 24, 2026 •

Copy link
Copy Markdown
Owner

Closes the release half of #22. Stacked on #20 (agent/popup-monitor-production-e2e). It also carries the P4 contract fix from #21 (cherry-picked as b30cf97) because P4 sealing needs it.

What changed

  • Patched base image. The six role images, the sandbox DEFAULT_IMAGE and run_p4_gate.sh now pin python:3.12-alpine@sha256:4c47124a8391cb7a9f571164147d154777cf012a4ece5f86097130d7a4478111. Trivy reports 0 HIGH/CRITICAL findings on the new base. scripts/verify_p4.py keeps the historical digest, because it verifies committed evidence from the earlier seal.
  • cryptography 50.0.0, hash-locked in images/requirements.lock with every PyPI artifact hash.
  • deploy_forge.sh
  • P4 harness (d8ad9fd). The hardened worker health probe now sets ECHO_CERTFORGE_DEPLOYMENT_LEDGER=/workspace/state/deployments.sqlite3. Since P6 (bfc2159), the worker app opens its deployment ledger at import time. The default path is on the read-only image root, so every P6-era P4 run stopped as INFRA_FAILED with Read-only file system: '/opt/var'. The last green P4, 9c07eb7, predates P6. tests/test_p4_worker_service_env.py pins every worker state path to the writable workspace, and it fails without the fix.
  • Dogfooding. .echo/certification.json adds a stdlib-only journey (scripts/certforge_journey.py). The journey checks that the manifest pin, the deploy default and the run_worker pin agree, byte-compiles src/, and runs tests/test_release_pins.py and tests/test_deploy_gate.py in the CertForge sandbox.

Evidence at head d8ad9fd881365801354b78a758632d2a31ab6828

Gate Result
P4 hostile acceptance (run_p4_gate.sh, run p4-d8ad9fd-ops-20260924-rel3) PASSED. 12 images built and sealed (manifest 52b7bc67…). 18/18 checks passed, including vulnerability and malware scans on all 6 roles. completed_phase_gate: P4, run_outcome: COMPLETE, report sha256 4001cb03…. New runner image sha256:6424a635ab4ce78c6acfea800409e13d219ae596e7447de34e30ba200761076b.
CI workflow steps, replicated on FORGE in a clean worktree (Python 3.12.3) install, compileall, pytest (679 passed, coverage 80.11%), verify_p1, p6_acceptance and p7_acceptance all exit 0. This replica is not hosted CI evidence.
Current production CertForge merge gate (certforge_merge_gate.py) allowed=True, run cert_5b6eaf3ae172cfdc183f203ab1fd5949bec672bf, STAGING_CERTIFIED (only production E2E outstanding), signed by ed25519:a07f417e….
ECHO Certification Forge check neutral (STAGING-CERTIFIED), run cert_16ba3e7d5073c5956d6c8fd253f4b0ab68bbaac8.
master_acceptance.py dry run P1–P7, SDK and MASTER pass. The run stops at the CI gate only: hosted CI run is not successful.
Hosted CI Blocked. Runs 36053908255 and 36059155489 report "The job was not started because your account is locked due to a billing issue."

Not yet done

The signed product-readiness report needs a green hosted-CI run at this exact SHA. deploy_forge.sh fails closed without that report, so this release is not deployed, and /v1/status remains NOT_READY. Once the account billing is fixed, rerun CI; the remaining steps are then scripted in certforge_release_d8ad9fd.sh on FORGE (readiness, then deploy).

Environment identity

The worker environment identity digest is built from constant labels plus the adapter set, so it does not change with this release. Computed with this head's code against the production adapter bundle: 8e6466d2d285f4e1c8ba3e83258fd097b384d4e9ae7dd723436d449728ccfcb6. The same is true of the runner_image_digest that /v1/status reports (sha256:7e41caae… = sha256 of certforge-worker-env:runner-image). It is a label, not the sandbox image.

🤖 Generated with Claude Code

https://claude.ai/code/session_0152mN1wMwj9vE2YmV2xZF4F

ECHO-OMEGA-PRIME and others added 3 commits September 24, 2026 15:07
Successful hostile acceptance reports omitted the completed_phase_gate field
required by the master collector. Publish P4 only after every core check and
cleanup succeeds, and keep exact-wrapper reports pending until enrichment
returns. Failed verification, malformed capture, interruption and nonzero
exit cannot leave a newly completed report for the master consumer.

Keep master validation, exact-source and signing rules, release verdicts and
historical acceptance reports unchanged. Add producer/wrapper/consumer
integration coverage including pending publication and failure paths.

Validation: 24 focused and adjacent tests pass; full suite 637 pass, 2 skip,
1 existing symlink test blocked by Windows privilege 1314. P1 acceptance
passes all 3 scenarios using a byte-identical source copy outside historical
artifacts. Hosted CI, dual certification and deployment remain pending.
…#22)

Release hardening so the P4 hostile acceptance gate can seal again:

- Bump the pinned python:3.12-alpine base for all six role images, the
  sandbox default image and the P4 gate to
  sha256:4c47124a8391cb7a9f571164147d154777cf012a4ece5f86097130d7a4478111
  (Trivy: 0 HIGH/CRITICAL findings on the new base).
- Bump the hash-locked cryptography pin to 50.0.0 (all PyPI wheel and sdist
  hashes locked).
- deploy_forge.sh: the dispatcher unit uses Wants= instead of Requires= on
  the API service so an API restart no longer tears down in-flight runs; the
  source-fetch git credential helper is configurable
  (CERTFORGE_GIT_CREDENTIAL_HELPER); the trusted manifest default is the
  canonical-JSON digest that run_worker pins (08ba068c...), not the raw
  file-bytes digest.
- Opt the repository into its own CertForge gate with a stdlib-only journey
  (scripts/certforge_journey.py) and pin tests (tests/test_release_pins.py).

The worker environment identity digest is label-derived and does not change
with this release (8e6466d2...).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0152mN1wMwj9vE2YmV2xZF4F
…space (#22)

The fresh P4 hostile-acceptance run for bc1b8ad built and sealed all 12
images and passed the scans, the static and runtime attack matrices and
the custody and anchor service probes. It then stopped as INFRA_FAILED:
the worker container exited before /healthz answered.

Cause: since P6 (bfc2159) the worker app opens its deployment ledger at
import time. Its default path, <package root>/var/deployments.sqlite3,
resolves to /opt/var on the read-only image root, so uvicorn died with
"Read-only file system: '/opt/var'". The last green P4 (9c07eb7) predates
P6, so no P6-era source could pass P4 until now.

Fix: the hardened probe sets ECHO_CERTFORGE_DEPLOYMENT_LEDGER to
/workspace/state/deployments.sqlite3, next to the other state paths.
Only the harness changes; production and the image stay as they are.
Reproduced with the sealed worker image: exit 1 without the variable,
healthy with it. A new test pins every worker state path to the writable
workspace; it fails without this change.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0152mN1wMwj9vE2YmV2xZF4F
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants