consortium
Version:
Remote control and session sharing CLI for AI coding agents
47 lines (42 loc) • 2.28 kB
JavaScript
/**
* Generate a LOCAL, throwaway Ed25519 harness signing key for development.
*
* Replaces the old committed `src/harness/dev-signing-key.pem`. The private
* half of the harness trust anchor must never live in the repo: if the pinned
* `OFFICIAL_CONSORTIUM_HARNESS_PUBKEY_PEM` were the public half of a committed
* private key, anyone could sign a malicious harness binary that passes
* verification (`scripts/check-harness-key.cjs` blocks exactly that at release).
*
* This script writes a fresh private key to the git-ignored
* `src/harness/dev-signing-key.pem` and prints the matching public key. Pin the
* public half for local dev/tests by exporting it as
* `CONSORTIUM_DEV_HARNESS_PUBKEY_PEM` — `verifySignature.harnessTrustAnchorPem`
* honors that override ONLY outside production, so a shipped CLI is unaffected.
*
* Usage:
* node scripts/generate-dev-signing-key.cjs # write pem + print pubkey
* node scripts/generate-dev-signing-key.cjs --print-env-only # just the export line
*
* Tests do NOT depend on this file — they mint an ephemeral keypair in-process.
* This script exists for a local dev harness-signing workflow (mock publisher).
*/
const fs = require('fs');
const path = require('path');
const crypto = require('crypto');
const PRINT_ENV_ONLY = process.argv.includes('--print-env-only');
const OUT_PATH = path.resolve(__dirname, '..', 'src', 'harness', 'dev-signing-key.pem');
const { publicKey, privateKey } = crypto.generateKeyPairSync('ed25519', {
publicKeyEncoding: { type: 'spki', format: 'pem' },
privateKeyEncoding: { type: 'pkcs8', format: 'pem' },
});
if (!PRINT_ENV_ONLY) {
fs.writeFileSync(OUT_PATH, privateKey, { mode: 0o600 });
try { fs.chmodSync(OUT_PATH, 0o600); } catch { /* best-effort on non-POSIX */ }
console.error(`[generate-dev-signing-key] wrote private key -> ${OUT_PATH} (git-ignored, mode 0600)`);
console.error('[generate-dev-signing-key] public key (pin via CONSORTIUM_DEV_HARNESS_PUBKEY_PEM):\n');
console.error(publicKey);
}
// A single-line, shell-exportable form so a dev can do:
// export CONSORTIUM_DEV_HARNESS_PUBKEY_PEM="$(node scripts/generate-dev-signing-key.cjs --print-env-only)"
process.stdout.write(publicKey.trimEnd());