consortium
Version:
Remote control and session sharing CLI for AI coding agents
72 lines (63 loc) • 2.91 kB
JavaScript
/**
* Release gate for the harness signing trust anchor (#5).
*
* The pinned OFFICIAL_CONSORTIUM_HARNESS_PUBKEY_PEM in verifySignature.ts is the
* ONLY key whose signatures verifyHarnessBinary trusts. If that pinned public
* key is the public half of a private key COMMITTED to this repo (i.e. a
* dev/test key whose private half anyone can read), then anyone can sign a
* malicious harness binary that passes verification. This script fails the build
* in that case — so a dev key can never silently become the production anchor.
*
* Unlike the old `check:no-placeholder-key` (which only grepped for the literal
* string "PLACEHOLDER"), this derives the public half of every committed *.pem /
* *.key private key and compares it to the pinned key, so it catches the real
* dev key (and any future swapped-in one), not just a literal placeholder.
*/
const fs = require('fs');
const path = require('path');
const crypto = require('crypto');
const ROOT = path.resolve(__dirname, '..');
const VERIFY_SRC = path.join(ROOT, 'src/harness/verifySignature.ts');
function fail(msg) {
console.error(`[check-harness-key] FAIL: ${msg}`);
process.exit(1);
}
const src = fs.readFileSync(VERIFY_SRC, 'utf8');
const m = src.match(/-----BEGIN PUBLIC KEY-----[\s\S]*?-----END PUBLIC KEY-----/);
if (!m) fail('no pinned PUBLIC KEY block found in verifySignature.ts');
// The pinned key may be embedded as a TS string with escaped newlines.
const pinnedPem = m[0].replace(/\\n/g, '\n');
if (pinnedPem.includes('PLACEHOLDER')) fail('pinned pubkey is a PLACEHOLDER');
let pinnedDer;
try {
pinnedDer = crypto.createPublicKey(pinnedPem).export({ type: 'spki', format: 'der' });
} catch (e) {
fail(`pinned pubkey is not a valid public key: ${e.message}`);
}
function walk(dir, acc) {
for (const ent of fs.readdirSync(dir, { withFileTypes: true })) {
if (ent.name === 'node_modules' || ent.name === '.git' || ent.name === 'dist') continue;
const full = path.join(dir, ent.name);
if (ent.isDirectory()) walk(full, acc);
else if (/\.(pem|key)$/.test(ent.name)) acc.push(full);
}
return acc;
}
for (const pemFile of walk(ROOT, [])) {
const content = fs.readFileSync(pemFile, 'utf8');
if (!/-----BEGIN [A-Z ]*PRIVATE KEY-----/.test(content)) continue;
let pub;
try {
pub = crypto.createPublicKey(crypto.createPrivateKey(content)).export({ type: 'spki', format: 'der' });
} catch {
continue;
}
if (Buffer.compare(pub, pinnedDer) === 0) {
fail(
`pinned harness pubkey is the public half of a COMMITTED private key (${path.relative(ROOT, pemFile)}). ` +
`Swap the pin in verifySignature.ts to the KMS/production public key before any release.`,
);
}
}
console.log('[check-harness-key] OK: pinned harness pubkey is not a committed or placeholder key');