fix: added status validation to ear_appraisal - #53
Conversation
86fe62f to
2c955ff
Compare
| module github.com/veraison/ear | ||
|
|
||
| go 1.23.0 | ||
| go 1.26 |
There was a problem hiding this comment.
Do we need the minimum version to be 1.26?
There was a problem hiding this comment.
Any reason not to? Services runs also on 1.26 and I would move it to 1.26 in #58 also
There was a problem hiding this comment.
I changed it for some debugging thing and did not undo the change when making the pull request. Either way is fine with me
There was a problem hiding this comment.
Any reason not to? Services runs also on 1.26 and I would move it to 1.26
This is the minimum version; so there isn't really a reason to align with services. The only objection I see to bumping it is that it will force everyone depending on this to bump their version too (the reason services is at 1.26 is because nowandlater (used by corim-store) required 1.26, not because we needed any of the newer features). On the other hand, bumping the version usually isn't a huge issue, so this is not too much of a problem.
However, if we bump it we need to do so in the CI flows as well, and (looking at the latest results) we need to update golangci-lint installation, as the currently installed version was built with 1.24 and doesn't seem to like code build with a later version.
@inf3112-hsworms please undo the change in this pull request, as it's unrelated to the main issue being addressed. We can do the minimum version bump in a separate pull if needed.
There was a problem hiding this comment.
I have used statements like new(TrustTier(2)) in the tests, those are only introduced in go1.26. I'll change those back to variable references to fix the linter issues
|
@inf3112-hsworms please sign off the latest commit; or, better yet, squash it into the previous commit, since it's only fixes up thing in this pull request, and does not need to exist on its own. EDIT: Please also update the tests (again, please fix up existing commit, do not create new ones). |
9fd1a8a to
21c28ab
Compare
|
ah yeah. My internship has ended, so I just mindlessly used github to approve the requested change. Sorry for the hassle |
21c28ab to
3edf695
Compare
|
@inf3112-hsworms looks like the files now need to be |
Partially fixes veraison/services#430. This commit adds functionality to ear_appraisal.Validate() to check that the appraisal conforms to draft-fv-rats-ear-04. Thus, it is checked that: - status is one of the four defined trust tiers - status is larger than or equal to each element of the trust vector (= of no higher trustworthiness than the trust vector) Additionally this commit: - adds minimal unit tests to Validate() and UpdateStatusFromTrustVector() - adds not-nil check for trust vector to UpdateStatusFromTrustVector() - exports ear_appraisal.Validate(), such that it could be called when policies are validated Co-authored-by: setrofim <setrofim@proton.me> Signed-off-by: Jeff Schymiczek <jeff.schymiczek@helsinki.fi>
3edf695 to
5575052
Compare
Contributes towards fixing veraison/services#430. Adds functionality to ear_appraisal.Validate() to check that the appraisal conforms to draft-fv-rats-ear-04. Thus, it is checked that:
Additionally: