Skip to content

fix: added status validation to ear_appraisal - #53

Merged
setrofim merged 1 commit into
veraison:mainfrom
inf3112-hsworms:appraisal_validation
Sep 16, 2026
Merged

setrofim merged 1 commit into
veraison:mainfrom
inf3112-hsworms:appraisal_validation

Conversation

@inf3112-hsworms

Copy link
Copy Markdown

Contributes towards fixing veraison/services#430. Adds functionality to ear_appraisal.Validate() to check that the appraisal conforms to draft-fv-rats-ear-04. Thus, it is checked that:

  • status is one of the four defined trust tiers
  • status is larger than or equal to the trust tier of each element of the trust vector (= of no higher trustworthiness than the trust vector)

Additionally:

  • adds minimal unit tests to Validate() and UpdateStatusFromTrustVector()
  • adds not-nil check for trust vector to UpdateStatusFromTrustVector()
  • exports ear_appraisal.Validate(), such that it could be called when policies are validated

@THS-on
THS-on requested a review from setrofim September 7, 2026 07:44
Comment thread ear_appraisal.go Outdated
Comment thread go.mod Outdated
module github.com/veraison/ear

go 1.23.0
go 1.26

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we need the minimum version to be 1.26?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Any reason not to? Services runs also on 1.26 and I would move it to 1.26 in #58 also

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I changed it for some debugging thing and did not undo the change when making the pull request. Either way is fine with me

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Any reason not to? Services runs also on 1.26 and I would move it to 1.26

This is the minimum version; so there isn't really a reason to align with services. The only objection I see to bumping it is that it will force everyone depending on this to bump their version too (the reason services is at 1.26 is because nowandlater (used by corim-store) required 1.26, not because we needed any of the newer features). On the other hand, bumping the version usually isn't a huge issue, so this is not too much of a problem.

However, if we bump it we need to do so in the CI flows as well, and (looking at the latest results) we need to update golangci-lint installation, as the currently installed version was built with 1.24 and doesn't seem to like code build with a later version.

@inf3112-hsworms please undo the change in this pull request, as it's unrelated to the main issue being addressed. We can do the minimum version bump in a separate pull if needed.

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I have used statements like new(TrustTier(2)) in the tests, those are only introduced in go1.26. I'll change those back to variable references to fix the linter issues

@setrofim

setrofim commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

@inf3112-hsworms please sign off the latest commit; or, better yet, squash it into the previous commit, since it's only fixes up thing in this pull request, and does not need to exist on its own.

EDIT: Please also update the tests (again, please fix up existing commit, do not create new ones).

@inf3112-hsworms

Copy link
Copy Markdown
Author

ah yeah. My internship has ended, so I just mindlessly used github to approve the requested change. Sorry for the hassle

@setrofim

Copy link
Copy Markdown
Contributor

@inf3112-hsworms looks like the files now need to be go fmt'd

Partially fixes veraison/services#430. This commit adds functionality
to ear_appraisal.Validate() to check that the appraisal conforms to
draft-fv-rats-ear-04. Thus, it is checked that:
 - status is one of the four defined trust tiers
 - status is larger than or equal to each element of the trust vector
(= of no higher trustworthiness than the trust vector)

Additionally this commit:
 - adds minimal unit tests to Validate() and UpdateStatusFromTrustVector()
 - adds not-nil check for trust vector to UpdateStatusFromTrustVector()
 - exports ear_appraisal.Validate(), such that it could be called when policies
are validated

Co-authored-by: setrofim <setrofim@proton.me>

Signed-off-by: Jeff Schymiczek <jeff.schymiczek@helsinki.fi>
@setrofim
setrofim merged commit 2a5ee37 into veraison:main Sep 16, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants