UNPKG

consortium

Version:

Remote control and session sharing CLI for AI coding agents

47 lines (42 loc) • 2.28 kB
#!/usr/bin/env node /** * Generate a LOCAL, throwaway Ed25519 harness signing key for development. * * Replaces the old committed `src/harness/dev-signing-key.pem`. The private * half of the harness trust anchor must never live in the repo: if the pinned * `OFFICIAL_CONSORTIUM_HARNESS_PUBKEY_PEM` were the public half of a committed * private key, anyone could sign a malicious harness binary that passes * verification (`scripts/check-harness-key.cjs` blocks exactly that at release). * * This script writes a fresh private key to the git-ignored * `src/harness/dev-signing-key.pem` and prints the matching public key. Pin the * public half for local dev/tests by exporting it as * `CONSORTIUM_DEV_HARNESS_PUBKEY_PEM` — `verifySignature.harnessTrustAnchorPem` * honors that override ONLY outside production, so a shipped CLI is unaffected. * * Usage: * node scripts/generate-dev-signing-key.cjs # write pem + print pubkey * node scripts/generate-dev-signing-key.cjs --print-env-only # just the export line * * Tests do NOT depend on this file — they mint an ephemeral keypair in-process. * This script exists for a local dev harness-signing workflow (mock publisher). */ const fs = require('fs'); const path = require('path'); const crypto = require('crypto'); const PRINT_ENV_ONLY = process.argv.includes('--print-env-only'); const OUT_PATH = path.resolve(__dirname, '..', 'src', 'harness', 'dev-signing-key.pem'); const { publicKey, privateKey } = crypto.generateKeyPairSync('ed25519', { publicKeyEncoding: { type: 'spki', format: 'pem' }, privateKeyEncoding: { type: 'pkcs8', format: 'pem' }, }); if (!PRINT_ENV_ONLY) { fs.writeFileSync(OUT_PATH, privateKey, { mode: 0o600 }); try { fs.chmodSync(OUT_PATH, 0o600); } catch { /* best-effort on non-POSIX */ } console.error(`[generate-dev-signing-key] wrote private key -> ${OUT_PATH} (git-ignored, mode 0600)`); console.error('[generate-dev-signing-key] public key (pin via CONSORTIUM_DEV_HARNESS_PUBKEY_PEM):\n'); console.error(publicKey); } // A single-line, shell-exportable form so a dev can do: // export CONSORTIUM_DEV_HARNESS_PUBKEY_PEM="$(node scripts/generate-dev-signing-key.cjs --print-env-only)" process.stdout.write(publicKey.trimEnd());