Skip to content

T-112: enforce cross-toolchain integrity in the build path - #6

Merged
machinavitalis merged 1 commit into
mainfrom
T-112-toolchain-integrity
Jul 13, 2026
Merged

machinavitalis merged 1 commit into
mainfrom
T-112-toolchain-integrity

Conversation

@machinavitalis

Copy link
Copy Markdown
Owner

The attestation pitch leans on toolchain provenance, but verify_toolchain_integrity was exported and never called by any build — the manifest silently implied a check that never ran.

What

  • resolve_toolchain_integrity(target) — the build-path policy. Real pin → verify the installed binary; a mismatch (or missing binary) raises ToolchainError and aborts the build. Unverified sentinel → record "unverified" and continue (loud, not silent — invariant 7).
  • Wired into cross_build_for_target: a verify-stage build-log entry + a toolchain-integrity:<binary> key in Manifest.toolchain_versions, so a verifier can tell whether provenance covers toolchain integrity.
  • Doc-drift: CLAIMS gains the integrity claim; KNOWN_GAPS' placeholder-SHA entry is now honest (verified path wired + enforced; real hashes still unpinned).

Tests

resolve_toolchain_integrity over unverified / pinned-match / pinned-mismatch (hard-fail). Pinning the real Arm hashes stays a documented gap (host-specific per release).

🤖 Generated with Claude Code

The attestation story leans on toolchain provenance, but the SHA-256
integrity check (verify_toolchain_integrity) was exported and never
called by any build — so the manifest silently implied a check that
never ran.

- Add resolve_toolchain_integrity(target): the build-path policy.
  Real pin -> verify the installed binary; a mismatch (or missing
  binary) raises ToolchainError and aborts the build. Unverified
  sentinel -> record "unverified" and continue (loud, not silent).
- Wire it into cross_build_for_target: a "verify"-stage build-log entry
  plus a toolchain-integrity:<binary> key in Manifest.toolchain_versions,
  so a verifier can tell whether provenance covers toolchain integrity.
- Doc-drift: CLAIMS gains the integrity-status claim; KNOWN_GAPS updates
  the (now honest) placeholder-SHA entry.

Tests: resolve_toolchain_integrity over unverified / pinned-match /
pinned-mismatch. Pinning the real Arm hashes stays a gap (host-specific).
@machinavitalis
machinavitalis merged commit b1156fb into main Jul 13, 2026
8 checks passed
@machinavitalis
machinavitalis deleted the T-112-toolchain-integrity branch July 13, 2026 00:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant