UNPKG

consortium

Version:

Remote control and session sharing CLI for AI coding agents

72 lines (63 loc) • 2.91 kB
#!/usr/bin/env node /** * Release gate for the harness signing trust anchor (#5). * * The pinned OFFICIAL_CONSORTIUM_HARNESS_PUBKEY_PEM in verifySignature.ts is the * ONLY key whose signatures verifyHarnessBinary trusts. If that pinned public * key is the public half of a private key COMMITTED to this repo (i.e. a * dev/test key whose private half anyone can read), then anyone can sign a * malicious harness binary that passes verification. This script fails the build * in that case — so a dev key can never silently become the production anchor. * * Unlike the old `check:no-placeholder-key` (which only grepped for the literal * string "PLACEHOLDER"), this derives the public half of every committed *.pem / * *.key private key and compares it to the pinned key, so it catches the real * dev key (and any future swapped-in one), not just a literal placeholder. */ const fs = require('fs'); const path = require('path'); const crypto = require('crypto'); const ROOT = path.resolve(__dirname, '..'); const VERIFY_SRC = path.join(ROOT, 'src/harness/verifySignature.ts'); function fail(msg) { console.error(`[check-harness-key] FAIL: ${msg}`); process.exit(1); } const src = fs.readFileSync(VERIFY_SRC, 'utf8'); const m = src.match(/-----BEGIN PUBLIC KEY-----[\s\S]*?-----END PUBLIC KEY-----/); if (!m) fail('no pinned PUBLIC KEY block found in verifySignature.ts'); // The pinned key may be embedded as a TS string with escaped newlines. const pinnedPem = m[0].replace(/\\n/g, '\n'); if (pinnedPem.includes('PLACEHOLDER')) fail('pinned pubkey is a PLACEHOLDER'); let pinnedDer; try { pinnedDer = crypto.createPublicKey(pinnedPem).export({ type: 'spki', format: 'der' }); } catch (e) { fail(`pinned pubkey is not a valid public key: ${e.message}`); } function walk(dir, acc) { for (const ent of fs.readdirSync(dir, { withFileTypes: true })) { if (ent.name === 'node_modules' || ent.name === '.git' || ent.name === 'dist') continue; const full = path.join(dir, ent.name); if (ent.isDirectory()) walk(full, acc); else if (/\.(pem|key)$/.test(ent.name)) acc.push(full); } return acc; } for (const pemFile of walk(ROOT, [])) { const content = fs.readFileSync(pemFile, 'utf8'); if (!/-----BEGIN [A-Z ]*PRIVATE KEY-----/.test(content)) continue; let pub; try { pub = crypto.createPublicKey(crypto.createPrivateKey(content)).export({ type: 'spki', format: 'der' }); } catch { continue; } if (Buffer.compare(pub, pinnedDer) === 0) { fail( `pinned harness pubkey is the public half of a COMMITTED private key (${path.relative(ROOT, pemFile)}). ` + `Swap the pin in verifySignature.ts to the KMS/production public key before any release.`, ); } } console.log('[check-harness-key] OK: pinned harness pubkey is not a committed or placeholder key');