Skip to content

No adapter from a cosign bundle into KeylessSignature — wsc can export its own signatures but cannot ingest the ecosystem's #260

Description

@avrabe

SigstoreBundle (container/bundle.rs on main) has from_keyless_signature, to_json and from_json — it can emit wsc's own signatures in bundle form, but there is no path from an existing cosign-produced bundle back into a KeylessSignature that the verifiers accept.

That makes wsc's verification usable only on artifacts wsc itself signed.

Why varve hits this

varve's release pipeline already produces cosign bundles today — SHA256SUMS.txt.cosign.bundle, keyless, GitHub OIDC, exactly the Sigstore shape wsc's verifiers understand. We wanted to verify those with wsc::airgapped rather than shelling out to cosign verify-blob.

We can't. The bundle has rekorBundle.{SignedEntryTimestamp, Payload} and a cert chain — all the inputs verify_signature needs — but nothing converts them into the struct it takes.

So the practical position is: an org already using cosign (which is most of them) cannot adopt wsc's offline verification without writing this adapter themselves, and each one will write it slightly differently against an internal struct shape.

Ask

A public constructor, roughly:

impl KeylessSignature {
    /// Parse a cosign / Sigstore bundle (protobuf or the legacy JSON shape)
    pub fn from_sigstore_bundle(json: &str) -> Result<Self, WSError>;
}

Two details worth deciding deliberately rather than discovering:

  • Both bundle shapes exist in the wild. The legacy rekorBundle JSON (what cosign v2.4.x writes, and what varve's release currently carries) and the newer protobuf bundle.sigstore.dev/v0.3 media type. Supporting only one will surprise someone.
  • Round-trip fidelity. from_sigstore_bundle → from_keyless_signature → to_json should be lossless, or the difference should be documented. A verifier that silently drops a field it did not model is how a check stops checking.

If it would help, varve's v0.28.0 bundle is a real, public, keyless-signed GitHub-OIDC artifact you can use as a fixture — and a negative control is easy to derive from it by flipping a byte of the digest.

Found while evaluating wsc for varve (DD-026). Related: sigil#256 (sign_digest), sigil#257 (0.11.0 unpublished), sigil#259 (stale embedded root).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions