Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 10 additions & 6 deletions deny.toml
Original file line number Diff line number Diff line change
Expand Up @@ -14,14 +14,18 @@ ignore = [
# RUSTSEC-2026-0249: `smartstring` 1.0.1 is unmaintained and has no patched
# release. Its safe `From<String>` conversion has reported undefined
# behavior (bodil/smartstring#49), also reproduced through Rhai's
# `ImmutableString` (rhaiscript/rhai#816). Rhai 1.25.1 pulls it into
# `ImmutableString` (rhaiscript/rhai#816). Rhai 1.26.1 pulls it into
Comment thread
jeremi marked this conversation as resolved.
# Evidence, its authoring tools, and the shared language server exposed
# through `relayctl`, where the affected owned-string conversion is
# reachable. This ignore records accepted residual risk, not a fix.
# Reviewed 2026-08-13. Review when Rhai replaces `smartstring`, if a
# maintained patched release appears, after changes to Evidence's Rhai
# string flow, before accepting untrusted scripts, or if upstream publishes
# further security findings.
# reachable. Evidence accepts governed, hash-covered scripts only and
# bounds adapter strings, arrays, and maps before converting them for Rhai;
# these controls limit exposure but do not remove the reported unsoundness.
# This ignore records accepted residual risk, not a fix. Reviewed 2026-09-22
# after selector-aware extraction added another bounded conversion path.
# Review by 2026-10-06, when Rhai replaces `smartstring`, if a maintained
# patched release appears, after further changes to Evidence's Rhai string
# flow, before accepting untrusted scripts, or if upstream publishes further
# security findings.
"RUSTSEC-2026-0249",
# The following advisories all arrive through the Typst rendering tree
# (`typst`/`typst-pdf`/`krilla`/`typst-library`), which
Expand Down
92 changes: 75 additions & 17 deletions products/relay-v2/security/advisory-baseline.json
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@
"sha256:7db505d90756626f425c6c5468eca565c82f589b144ecaa4f411ad9bbf79e614"
],
"application_layer_ids": [
"sha256:f71bab192b90d68c1ef78bbd58c68f163b3077f59129ed8af45cb0a03fa8e274",
"sha256:302066fd41cf1075eb0e8bf16aa8467461330d1e777219b472cd11665246800a",
"sha256:5f70bf18a086007016e948b04aed3b82103a36bea41755b6cddfaf10ace3c6ef"
],
"config": {
Expand Down Expand Up @@ -64,7 +64,7 @@
],
"stop_signal": ""
},
"definition_digest": "sha256:5c707fcf1de482143d5789562f3691260d2519333f51cfb50fec0089153981c2"
"definition_digest": "sha256:3a722bfd7ce830c3f482a867b937980075230ec96ebaa2e5e9c32c16df16c4b1"
},
"policies": [
{
Expand All @@ -87,7 +87,7 @@
"severity": "High",
"status": "accepted_risk",
"owner": "@jeremi",
"rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The reviewed v0.32.0 Linux AMD64 Relay local reproduction from rehearsal run 34923868162 imports or dynamically resolves none of the deprecated resolver-printing interfaces, including ns_printrrf, ns_printrr, ns_sprintrrf, ns_sprintrr and fp_nquery. Ordinary resolver initialization does not enter the vulnerable TSIG diagnostic-printing path. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Re-reviewed on 2026-09-22 with the evidence bindings unchanged: the release Dockerfiles still pin the reviewed runtime base, and Debian still records Trixie as vulnerable at this version under its no-DSA minor-issue tag, with a fixed glibc only in forky and sid.",
"rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix. The reviewed v0.33.0 Linux AMD64 Relay local reproduction is exact rehearsal run 35711552030 at source 6a460c2cf66bc9d286cbe4a5454571c392488c05. Its executable imports none of the deprecated resolver-printing interfaces, including ns_printrrf, ns_printrr, ns_sprintrrf, ns_sprintrr and fp_nquery. The one review-required nonconstant dlsym tail jump is SQLite's extension-symbol wrapper; governed SQL rejects load_extension and no first-party runtime caller enables or invokes SQLite C extension loading. Ordinary resolver initialization does not enter the vulnerable TSIG diagnostic-printing path. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-22; Debian still records this Trixie version as vulnerable and fixes only forky and sid.",
"reviewed_at": "2026-09-22",
"expires_at": "2026-10-06",
"invalidation_triggers": [
Expand All @@ -105,14 +105,14 @@
"runtime_config_changed",
"runtime_base_changed"
],
"runtime_definition_digest": "sha256:5c707fcf1de482143d5789562f3691260d2519333f51cfb50fec0089153981c2",
"component_layer_id": "sha256:f71bab192b90d68c1ef78bbd58c68f163b3077f59129ed8af45cb0a03fa8e274",
"runtime_definition_digest": "sha256:3a722bfd7ce830c3f482a867b937980075230ec96ebaa2e5e9c32c16df16c4b1",
"component_layer_id": "sha256:302066fd41cf1075eb0e8bf16aa8467461330d1e777219b472cd11665246800a",
"exposure_assertion": {
"kind": "whole_image_fingerprint_equals",
"reference_image_digest": "sha256:c1fda956208cdba3c5418ca98b6362942abf5124aa7edf4438b47e696e26f034",
"reference_source_revision": "5e6120ad1ec2d17bc4189dfbaf38894cb8f7dbe8",
"reference_image_digest": "sha256:94d9d8439361ffec9fdc2ddd44c54b698632295998d8616276c9abf002d4a52c",
"reference_source_revision": "6a460c2cf66bc9d286cbe4a5454571c392488c05",
"reference_provenance": "local_reproduction",
"runtime_definition_digest": "sha256:5c707fcf1de482143d5789562f3691260d2519333f51cfb50fec0089153981c2",
"runtime_definition_digest": "sha256:3a722bfd7ce830c3f482a867b937980075230ec96ebaa2e5e9c32c16df16c4b1",
"files": [
{
"path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2",
Expand All @@ -132,10 +132,68 @@
},
{
"path": "/usr/local/bin/relay",
"sha256": "sha256:bf8b0c401940e3f37fd280cac28110b648830cc3fe111706927508ac95a674aa"
"sha256": "sha256:e1ead11e4a0a3d748ca85b4fa922854d1fd4ee07a0e1b5fa36444e3ed324ef5c"
}
],
"definition_digest": "sha256:7b8153aea0b91b3929d1afa6022a76e4fe64432b3714850ebe600e34d8ea825d"
"definition_digest": "sha256:5c81770a1cf1343d596783c549a949130db40a93fb0f3545eedd40dc78cb461b"
}
},
{
"vulnerability_id": "CVE-2026-19499",
"package": "libc6",
"installed_version": "2.41-12+deb13u4",
"severity": "High",
"status": "accepted_risk",
"owner": "@jeremi",
"rationale": "Debian classifies the Trixie issue as minor/no-DSA and has no Trixie fix; Grype reports wont-fix. The reviewed v0.33.0 Linux AMD64 Relay local reproduction is exact rehearsal run 35711552030 at source 6a460c2cf66bc9d286cbe4a5454571c392488c05. Its executable neither imports nor contains strfmon or strfmon_l. The one review-required nonconstant dlsym tail jump is SQLite's extension-symbol wrapper; governed SQL rejects load_extension and no first-party runtime caller enables or invokes SQLite C extension loading. No caller-controlled right-justified monetary-format width path was identified. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-22; Debian fixes the issue only in forky and sid.",
"reviewed_at": "2026-09-22",
"expires_at": "2026-10-06",
"invalidation_triggers": [
"candidate_image_identity_mismatch",
"candidate_rootfs_changed",
"component_layer_changed",
"expired",
"exposure_assertion_changed",
"exposure_assertion_false",
"exposure_assertion_unevaluable",
"fix_available",
"material_finding_changed",
"package_version_changed",
"rootfs_evidence_mismatch",
"runtime_config_changed",
"runtime_base_changed"
],
"runtime_definition_digest": "sha256:3a722bfd7ce830c3f482a867b937980075230ec96ebaa2e5e9c32c16df16c4b1",
"component_layer_id": "sha256:302066fd41cf1075eb0e8bf16aa8467461330d1e777219b472cd11665246800a",
"exposure_assertion": {
"kind": "whole_image_fingerprint_equals",
"reference_image_digest": "sha256:94d9d8439361ffec9fdc2ddd44c54b698632295998d8616276c9abf002d4a52c",
"reference_source_revision": "6a460c2cf66bc9d286cbe4a5454571c392488c05",
"reference_provenance": "local_reproduction",
"runtime_definition_digest": "sha256:3a722bfd7ce830c3f482a867b937980075230ec96ebaa2e5e9c32c16df16c4b1",
"files": [
{
"path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2",
"sha256": "sha256:c8438e4fde1934e61c88311633f00949ff645d5c04cdb8671fa3d78164d2f307"
},
{
"path": "/usr/lib/x86_64-linux-gnu/libc.so.6",
"sha256": "sha256:9792e3cbb541c8f44c7acf5f14f4022ea62998ecc787d326bed4d8b6547dfd92"
},
{
"path": "/usr/lib/x86_64-linux-gnu/libm.so.6",
"sha256": "sha256:6d567d53e895273ca14a1f9dc164fc6c8d39aed2f60aa46a733c2784228915f3"
},
{
"path": "/usr/lib/x86_64-linux-gnu/libpthread.so.0",
"sha256": "sha256:85e21f7dba0394411d00959176fd18b470e575b0b05f1f4f41e5636802ce0500"
},
{
"path": "/usr/local/bin/relay",
"sha256": "sha256:e1ead11e4a0a3d748ca85b4fa922854d1fd4ee07a0e1b5fa36444e3ed324ef5c"
}
],
"definition_digest": "sha256:5c81770a1cf1343d596783c549a949130db40a93fb0f3545eedd40dc78cb461b"
}
},
{
Expand All @@ -145,7 +203,7 @@
"severity": "High",
"status": "accepted_risk",
"owner": "@jeremi",
"rationale": "Debian Trixie has no fixed package and Grype reports no fix. The reviewed v0.32.0 Linux AMD64 Relay local reproduction from rehearsal run 34923868162 does not link libz or embed libz.so, gz_vacate, gzwrite, gzfwrite, gzprintf or gzvprintf in its executable. Its reviewed dynamic lookups do not select those functions, so no vulnerable stalled gzip-write followed by formatted-output path was identified. SQLite C extension-loading support is compiled in; its SQL entry point remains disabled and governed SQL explicitly denies load_extension, with no first-party runtime C-API loading or enabling caller identified. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Re-reviewed on 2026-09-22 with the evidence bindings unchanged: the release Dockerfiles still pin the reviewed runtime base, and Debian still lists no fixed zlib package for Trixie.",
"rationale": "Debian Trixie has no fixed package and Grype reports no fix. The reviewed v0.33.0 Linux AMD64 Relay local reproduction is exact rehearsal run 35711552030 at source 6a460c2cf66bc9d286cbe4a5454571c392488c05. Its executable neither links libz nor contains libz.so, gz_vacate, gzwrite, gzfwrite, gzprintf or gzvprintf. The one review-required nonconstant dlsym tail jump is SQLite's extension-symbol wrapper; governed SQL rejects load_extension and no first-party runtime caller enables or invokes SQLite C extension loading. No vulnerable stalled gzip-write followed by formatted-output path was identified. A candidate must retain the complete ordered reference rootfs layers, the production OCI process contract, and the Syft-bound reviewed executable, loader, libc, libm and libpthread file digests. Reviewed on 2026-09-22; Debian still lists no fixed zlib package for Trixie.",
"reviewed_at": "2026-09-22",
"expires_at": "2026-10-06",
"invalidation_triggers": [
Expand All @@ -163,14 +221,14 @@
"runtime_config_changed",
"runtime_base_changed"
],
"runtime_definition_digest": "sha256:5c707fcf1de482143d5789562f3691260d2519333f51cfb50fec0089153981c2",
"runtime_definition_digest": "sha256:3a722bfd7ce830c3f482a867b937980075230ec96ebaa2e5e9c32c16df16c4b1",
"component_layer_id": "sha256:e4ba966d7f0527dfe0fcb559e4e18d4da42c4e6beae924719255e0dedb554ed0",
"exposure_assertion": {
"kind": "whole_image_fingerprint_equals",
"reference_image_digest": "sha256:c1fda956208cdba3c5418ca98b6362942abf5124aa7edf4438b47e696e26f034",
"reference_source_revision": "5e6120ad1ec2d17bc4189dfbaf38894cb8f7dbe8",
"reference_image_digest": "sha256:94d9d8439361ffec9fdc2ddd44c54b698632295998d8616276c9abf002d4a52c",
"reference_source_revision": "6a460c2cf66bc9d286cbe4a5454571c392488c05",
"reference_provenance": "local_reproduction",
"runtime_definition_digest": "sha256:5c707fcf1de482143d5789562f3691260d2519333f51cfb50fec0089153981c2",
"runtime_definition_digest": "sha256:3a722bfd7ce830c3f482a867b937980075230ec96ebaa2e5e9c32c16df16c4b1",
"files": [
{
"path": "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2",
Expand All @@ -190,10 +248,10 @@
},
{
"path": "/usr/local/bin/relay",
"sha256": "sha256:bf8b0c401940e3f37fd280cac28110b648830cc3fe111706927508ac95a674aa"
"sha256": "sha256:e1ead11e4a0a3d748ca85b4fa922854d1fd4ee07a0e1b5fa36444e3ed324ef5c"
}
],
"definition_digest": "sha256:7b8153aea0b91b3929d1afa6022a76e4fe64432b3714850ebe600e34d8ea825d"
"definition_digest": "sha256:5c81770a1cf1343d596783c549a949130db40a93fb0f3545eedd40dc78cb461b"
}
}
]
Expand Down
16 changes: 10 additions & 6 deletions release/scripts/test_check_advisory_baselines.py
Original file line number Diff line number Diff line change
Expand Up @@ -24,15 +24,17 @@
ROOT / "release/security/casework-advisory-baseline.json",
ROOT / "release/security/discovery-advisory-baseline.json",
ROOT / "release/security/evidence-advisory-baseline.json",
ROOT / "release/security/scheduling-advisory-baseline.json",
)
LIVE_REFERENCE_IMAGE_DIGESTS = {
"relay": "sha256:c1fda956208cdba3c5418ca98b6362942abf5124aa7edf4438b47e696e26f034",
"breg": "sha256:9619bde5f36f1efc91b48253735659839366dc816ca4d46f3af286d7f3f44e6a",
"casework": "sha256:d12f62d91c4fb60532f441b4740790608b1fbc59a2f8eb31952f949c294f776b",
"discovery": "sha256:43140226dc11cde1dd1ca322462b891a00f29bf1e7181230a0bc6dd6eeb65b85",
"evidence": "sha256:af402e73cb104ee27039bf6c7b5cc5e7cbf37416449b91ff47086c6463b90483",
"relay": "sha256:94d9d8439361ffec9fdc2ddd44c54b698632295998d8616276c9abf002d4a52c",
"breg": "sha256:9299a1beece6ad8de828a7fbb72cbd109901e5f6f638f71e80fe31f1f78b7a90",
"casework": "sha256:ae50ec47af1b4916ff811bffdc7f928c4ef397e46f6208bb4f36c5ce655a1499",
"discovery": "sha256:26f3686b5b982d1883e83e64509ab30e35a56ece7bc9545d6350435cc72a0d7c",
"evidence": "sha256:ee06a933127294e9c2175de5c0115f651ee748eb1a546faeba0c737f594c5222",
"scheduling": "sha256:74f49c852500729542a73b6e057fe201f13b9f0aae5f51ba775e72a2f4903331",
}
LIVE_REFERENCE_SOURCE_REVISION = "5e6120ad1ec2d17bc4189dfbaf38894cb8f7dbe8"
LIVE_REFERENCE_SOURCE_REVISION = "6a460c2cf66bc9d286cbe4a5454571c392488c05"
# The date the live exceptions below were reviewed against, stated here rather
# than derived from the baselines: deriving it from their own reviewed_at values
# would make the checker's future-dated guard unreachable for the newest
Expand All @@ -44,13 +46,15 @@
"casework": "local_reproduction",
"discovery": "local_reproduction",
"evidence": "local_reproduction",
"scheduling": "local_reproduction",
}
LIVE_EXECUTABLES = {
"relay": "/usr/local/bin/relay",
"breg": "/usr/local/bin/breg",
"casework": "/usr/local/bin/casework",
"discovery": "/usr/local/bin/discovery",
"evidence": "/usr/local/bin/evidence",
"scheduling": "/usr/local/bin/scheduling",
}


Expand Down
Loading
Loading