Repository navigation
Fix signed CHIRP root ownership and renewal storage paths - #648
Merged
Merged
Conversation
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Program and scope
The new signed ownership envelope only accepted ordinary CDN paths, so valid CHIRP root advertisement creation failed. Renewal also tried to read a nonexistent CDN copy instead of the actual CHIRP root object. Accept the exact root route with the identifier bound to its advertised hash, read the real root during renewal, and extend its committed closure. Inactive or failed CHIRP leases fail closed.
Impact
The existing unpublished Cloud Bucket 0.2.46 candidate contains this correction; latest published image is 0.2.45. No new JSON keys, signatures, wallet schema, storage copy, default network, API endpoint, third-party dependency or deployed image changes in this PR. Normal UHRP CDN ownership and renewal remain supported.
Verification
The added tests fail on the old source: 7 failures across valid CHIRP ownership, advertisement creation and renewal/failure handling. Changed source passes all 17 service suites / 92 tests, build, lint and audit (zero vulnerabilities).
Full workspace build, types, lint, formatting and strict repository health pass. The tests use actual SDK cryptographic signatures and bound ownership metadata with synthetic wallets; only storage, action completion and broadcast are mocked. They cover exact root/hash binding, unrelated root/member paths, query/fragment/credential rejection, ordinary CDN renewal, actual CHIRP object selection, inactive roots and closure/provider failures before acknowledgement.
Security and dependencies
A CHIRP root must be the canonical identifier of the advertised hash and appear twice in the exact root route. Existing credential-free HTTPS, signatures, owner binding, selectors and request bounds remain enforced. An inactive CHIRP commit cannot fall back to unrelated CDN storage.
Release and operations
After green exact-main checks, build through protected Linux/amd64 Infra Release. Validate ordinary UHRP and CHIRP publish/default discovery/full and range download/HEAD/renewal/closure retention in staging before promoting the same verified digest to NanoStore production. No data migration or rollback schema change.
Completion evidence
Exact local head:
96f1d6896b04cc066bba0d4000955b8e1acd8e52.Exact-head hosted CI
36282196293, runtime36282196251, conformance36282196261and CodeQL36282196321passed. Sonar has zero unresolved new issues and zero unreviewed hotspots.