Skip to content

chore(security): rebind v0.33 advisory evidence to checkout-independent images - #1318

Merged
jeremi merged 1 commit into
mainfrom
chore/renew-v033-advisory-bindings
Sep 22, 2026
Merged

jeremi merged 1 commit into
mainfrom
chore/renew-v033-advisory-bindings

Conversation

@jeremi

@jeremi jeremi commented Sep 22, 2026

Copy link
Copy Markdown
Member

Pull Request

Summary

Release security area. Rebinds all six v0.33.0 image advisory baselines to the
review-only evidence from rehearsal run 35758336494 at source
82c1b813a28d61c322d435ce93c9b022455ddb2b, the first main revision whose
release builder no longer lets vendored build scripts read the checkout git
state (#1317).

The previous bindings came from rehearsal run 35711552030 at 6a460c2cf,
whose BReg executable embedded its own source commit. The candidate built from
125f67b37 therefore failed the whole-image fingerprint for all three BReg
exceptions even though no compiled input had changed.

What moves

Produced by registry-release renew-advisory-baselines --write, which only
moves evidence bindings:

  • BReg: runtime.application_layer_ids[0] eb1c6f6d… -> ebeebcbc…,
    component layer for both libc6 exceptions, /usr/local/bin/breg digest
    61d9835e… -> 1e951595…, and the dependent definition digests. All other
    layers, the OCI process configuration, and the loader, libc, libm and
    libpthread file digests are unchanged.
  • Casework, Discovery, Evidence, Relay, Scheduling: every layer and file
    digest is unchanged. Only reference_image_digest (the OCI revision label
    changes the manifest) and reference_source_revision move, plus the
    assertion definition digests that cover them.
  • Live pins in release/scripts/test_check_advisory_baselines.py:
    LIVE_REFERENCE_IMAGE_DIGESTS and LIVE_REFERENCE_SOURCE_REVISION.
    LIVE_REVIEW_EVALUATION_DATE stays 2026-09-22.

By hand: each of the 18 rationales now cites run 35758336494 and source
82c1b813a instead of the superseded run and source. No rationale claim,
expires_at (2026-10-06), reviewed_at, or accepted finding changed.

Evidence

claim command result
rehearsal built and collected evidence from 82c1b813a run 35758336494 all nine jobs succeeded
no staged release binary embeds the source commit rehearsal logs, four canonical Linux shards no staged binary embeds the source commit 82c1b813a… in each
BReg no longer embeds the commit grep -caF of full and 9-char commit in the extracted /usr/local/bin/breg 0 and 0
renewal accepted the whole roster (review-only collection, digests agree across Grype/Syft/OCI/rootfs, no new blocking finding, strict check passes) renew-advisory-baselines --write wrote 7 files
rationale edits left no binding to move renew-advisory-baselines dry run 0 file(s) would change
live pins agree python3 -m unittest release/scripts/test_check_advisory_baselines.py 49 tests OK, 1 skipped (requires a Linux glibc toolchain, macOS host; runs in CI)
BReg exposure claims still hold exposure/breg.json and string search of the executable NEEDED is only libm, libpthread, libc, ld-linux; no ns_printrr*, ns_sprintrr*, fp_nquery, strfmon*, libz.so or gz* symbols; the one review-required entry is still an address-taken dlsym via GOT beside INTEL_JIT_PROFILER64 and NotifyEvent
other exposure reports match their rationales exposure/*.json Casework, Discovery, Scheduling: no review-required lookup; Evidence and Relay: one non-constant dlsym PLT tail jump each (SQLite extension wrapper)

The convergence proof is the next candidate: its BReg application layer must
equal ebeebcbc…, which it can only do if the build is now commit-independent.

Notes

Security baseline change; needs explicit review. It accepts no new
vulnerability and extends no expiry. It only rebinds existing, already reviewed
risk acceptances to images that differ from the previously reviewed ones solely
in the BReg executable, whose change is the removal of two embedded commit
strings.

DCO

  • Every commit includes a Signed-off-by trailer.
  • I reviewed the submitted changes and am responsible for the contribution.

…nt images

The reviewed image bindings pointed at rehearsal run 35711552030, whose
BReg executable embedded its own source commit through vendored build
scripts. Now that release builds no longer read the checkout git state,
rebind all six baselines to rehearsal run 35758336494 so the candidate
built from any later commit carries the same reviewed bytes.

Only BReg's application layer and executable digest change. The other
five images keep every layer and file digest and move only their
reference image digest and source revision. Exceptions, expiry dates,
review dates and exposure claims are unchanged; the rationales now cite
the run and source that were reviewed.

Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@jeremi
jeremi merged commit 1f6facb into main Sep 22, 2026
45 checks passed
@jeremi
jeremi deleted the chore/renew-v033-advisory-bindings branch September 22, 2026 17:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant