| Safe Haskell | None |
|---|---|
| Language | GHC2021 |
Ecluse.Core.Package.Integrity
Description
Digest authority shared by admission and worker verification.
The public floor cannot fall below SHA-256. The trusted floor can, because an
operator may trust a private source that carries legacy digests.
See docsarchitecturesecurity.md for the trust assumptions.
Synopsis
- assertedAlg :: Hash -> Maybe HashAlg
- authoritativeDigest :: NonEmpty Hash -> Hash
- class IntegrityFloor floor where
- floorAlgorithm :: floor -> HashAlg
- meetsFloor :: IntegrityFloor floor => floor -> HashAlg -> Bool
- partitionByFloor :: IntegrityFloor floor => floor -> NonEmpty Artifact -> Either VersionIntegrity (NonEmpty Artifact)
- data MinIntegrity
- mkMinIntegrity :: HashAlg -> Either Text MinIntegrity
- parseMinIntegrity :: Text -> Either Text MinIntegrity
- unMinIntegrity :: MinIntegrity -> HashAlg
- data MinTrustedIntegrity
- mkMinTrustedIntegrity :: HashAlg -> Either Text MinTrustedIntegrity
- parseMinTrustedIntegrity :: Text -> Either Text MinTrustedIntegrity
- unMinTrustedIntegrity :: MinTrustedIntegrity -> HashAlg
- data VersionIntegrity
- classifyArtifacts :: IntegrityFloor floor => floor -> NonEmpty Artifact -> VersionIntegrity
Algorithm strength
assertedAlg :: Hash -> Maybe HashAlg Source #
Resolve an SRI prefix or a raw algorithm tag. An unknown prefix clears no floor.
The authoritative digest of a set
authoritativeDigest :: NonEmpty Hash -> Hash Source #
Select by asserted algorithm, then computability, retaining the last equal-ranked hash.
Integrity floors
class IntegrityFloor floor where Source #
Read a floor's minimum algorithm. Each smart constructor owns its floor's restrictions.
Instances
| IntegrityFloor MinIntegrity Source # | |
Defined in Ecluse.Core.Package.Integrity Methods floorAlgorithm :: MinIntegrity -> HashAlg Source # | |
| IntegrityFloor MinTrustedIntegrity Source # | |
Defined in Ecluse.Core.Package.Integrity Methods | |
meetsFloor :: IntegrityFloor floor => floor -> HashAlg -> Bool Source #
Whether an algorithm meets a floor: at least as strong as the floor's minimum, by
HashAlg Ord. Pass a resolved algorithm from assertedAlg, never a bare SRI.
partitionByFloor :: IntegrityFloor floor => floor -> NonEmpty Artifact -> Either VersionIntegrity (NonEmpty Artifact) Source #
Partition a version's artifacts against a floor, so a release loses the files that clear no tamper-evident fingerprint rather than disappearing whole.
The public-integrity floor (hard-floored at SHA-256)
data MinIntegrity Source #
A public admission floor that cannot fall below SHA-256.
Instances
| IntegrityFloor MinIntegrity Source # | |
Defined in Ecluse.Core.Package.Integrity Methods floorAlgorithm :: MinIntegrity -> HashAlg Source # | |
| Show MinIntegrity Source # | |
Defined in Ecluse.Core.Package.Integrity Methods showsPrec :: Int -> MinIntegrity -> ShowS # show :: MinIntegrity -> String # showList :: [MinIntegrity] -> ShowS # | |
| Eq MinIntegrity Source # | |
Defined in Ecluse.Core.Package.Integrity | |
mkMinIntegrity :: HashAlg -> Either Text MinIntegrity Source #
Reject algorithms below SHA-256, whose collisions permit substitution of public bytes.
parseMinIntegrity :: Text -> Either Text MinIntegrity Source #
Parse an algorithm name, distinguishing unknown names from a floor below SHA-256.
unMinIntegrity :: MinIntegrity -> HashAlg Source #
The floor algorithm.
The trusted-integrity floor (loosenable below SHA-256)
data MinTrustedIntegrity Source #
A trusted admission floor that may fall below SHA-256 for an operator's private source.
Instances
| IntegrityFloor MinTrustedIntegrity Source # | |
Defined in Ecluse.Core.Package.Integrity Methods | |
| Show MinTrustedIntegrity Source # | |
Defined in Ecluse.Core.Package.Integrity Methods showsPrec :: Int -> MinTrustedIntegrity -> ShowS # show :: MinTrustedIntegrity -> String # showList :: [MinTrustedIntegrity] -> ShowS # | |
| Eq MinTrustedIntegrity Source # | |
Defined in Ecluse.Core.Package.Integrity Methods (==) :: MinTrustedIntegrity -> MinTrustedIntegrity -> Bool # (/=) :: MinTrustedIntegrity -> MinTrustedIntegrity -> Bool # | |
mkMinTrustedIntegrity :: HashAlg -> Either Text MinTrustedIntegrity Source #
Build a MinTrustedIntegrity. It accepts any known algorithm, including the broken
SHA-1 and MD5, and rejects the bare SRI wrapper, which names no algorithm of its own.
parseMinTrustedIntegrity :: Text -> Either Text MinTrustedIntegrity Source #
Parse an algorithm name. Unlike parseMinIntegrity it accepts a sub-SHA-256 one.
unMinTrustedIntegrity :: MinTrustedIntegrity -> HashAlg Source #
The trusted floor algorithm.
Version admissibility
data VersionIntegrity Source #
Whether a version carries any digest that clears an admission floor.
Constructors
| MeetsFloor | At least one digest asserts an algorithm at or above the floor: admissible. |
| BelowFloor | Digests are present, but none clears the floor. |
| NoIntegrity | No artifact carries a digest. |
Instances
| Show VersionIntegrity Source # | |
Defined in Ecluse.Core.Package.Integrity Methods showsPrec :: Int -> VersionIntegrity -> ShowS # show :: VersionIntegrity -> String # showList :: [VersionIntegrity] -> ShowS # | |
| Eq VersionIntegrity Source # | |
Defined in Ecluse.Core.Package.Integrity Methods (==) :: VersionIntegrity -> VersionIntegrity -> Bool # (/=) :: VersionIntegrity -> VersionIntegrity -> Bool # | |
classifyArtifacts :: IntegrityFloor floor => floor -> NonEmpty Artifact -> VersionIntegrity Source #
Distinguish a floor-clearing version from one carrying only weak digests or none.