ecluse:ecluse-core
Safe HaskellNone
LanguageGHC2021

Ecluse.Core.Package.Integrity

Description

Digest authority shared by admission and worker verification. The public floor cannot fall below SHA-256. The trusted floor can, because an operator may trust a private source that carries legacy digests. See docsarchitecturesecurity.md for the trust assumptions.

Synopsis

Algorithm strength

assertedAlg :: Hash -> Maybe HashAlg Source #

Resolve an SRI prefix or a raw algorithm tag. An unknown prefix clears no floor.

The authoritative digest of a set

authoritativeDigest :: NonEmpty Hash -> Hash Source #

Select by asserted algorithm, then computability, retaining the last equal-ranked hash.

Integrity floors

class IntegrityFloor floor where Source #

Read a floor's minimum algorithm. Each smart constructor owns its floor's restrictions.

Methods

floorAlgorithm :: floor -> HashAlg Source #

The minimum algorithm this floor requires.

meetsFloor :: IntegrityFloor floor => floor -> HashAlg -> Bool Source #

Whether an algorithm meets a floor: at least as strong as the floor's minimum, by HashAlg Ord. Pass a resolved algorithm from assertedAlg, never a bare SRI.

partitionByFloor :: IntegrityFloor floor => floor -> NonEmpty Artifact -> Either VersionIntegrity (NonEmpty Artifact) Source #

Partition a version's artifacts against a floor, so a release loses the files that clear no tamper-evident fingerprint rather than disappearing whole.

The public-integrity floor (hard-floored at SHA-256)

data MinIntegrity Source #

A public admission floor that cannot fall below SHA-256.

mkMinIntegrity :: HashAlg -> Either Text MinIntegrity Source #

Reject algorithms below SHA-256, whose collisions permit substitution of public bytes.

parseMinIntegrity :: Text -> Either Text MinIntegrity Source #

Parse an algorithm name, distinguishing unknown names from a floor below SHA-256.

unMinIntegrity :: MinIntegrity -> HashAlg Source #

The floor algorithm.

The trusted-integrity floor (loosenable below SHA-256)

data MinTrustedIntegrity Source #

A trusted admission floor that may fall below SHA-256 for an operator's private source.

mkMinTrustedIntegrity :: HashAlg -> Either Text MinTrustedIntegrity Source #

Build a MinTrustedIntegrity. It accepts any known algorithm, including the broken SHA-1 and MD5, and rejects the bare SRI wrapper, which names no algorithm of its own.

parseMinTrustedIntegrity :: Text -> Either Text MinTrustedIntegrity Source #

Parse an algorithm name. Unlike parseMinIntegrity it accepts a sub-SHA-256 one.

unMinTrustedIntegrity :: MinTrustedIntegrity -> HashAlg Source #

The trusted floor algorithm.

Version admissibility

data VersionIntegrity Source #

Whether a version carries any digest that clears an admission floor.

Constructors

MeetsFloor

At least one digest asserts an algorithm at or above the floor: admissible.

BelowFloor

Digests are present, but none clears the floor.

NoIntegrity

No artifact carries a digest.

classifyArtifacts :: IntegrityFloor floor => floor -> NonEmpty Artifact -> VersionIntegrity Source #

Distinguish a floor-clearing version from one carrying only weak digests or none.