feat: sign the release checksum list

SHA256SUMS.txt sat beside the artifacts it vouches for, so whoever could
rewrite a release rewrote the list with it. The packs were already
reproducible, which answers corruption and lets a third party rebuild an
archive byte for byte; nothing answered a rewritten release.

The list is now signed with an ed25519 key kept for this alone, and the
public half is allowed_signers at the repository root, so verification
does not go through the release page: ssh-keygen -Y verify against the
committed file, then sha256sum --check. Rehearsed on all three outcomes:
a good signature, a tampered pack caught by the sums, a rewritten list
caught by the signature.

The release steps sign and upload the signature, the README points a
downloader at the procedure, and the reproducibility section says what
each half proves. Rotation keeps retired lines so past releases stay
verifiable. Three tests hold the trust root, the signing step and the
documented principal in agreement.
This commit is contained in:
Abdessamad Derraz committed 2026-09-04 14:01:05 +02:00
1 parent 5587c25675
commit 1a96853aee
7 files changed
+104 -3

No files matched your search

+6
View File
@@ -292,6 +292,12 @@ def generate_readme(db: dict, platforms_dir: str) -> str:
" (`cat Pack.zip.0* > Pack.zip`, or"
" `copy /b Pack.zip.001+Pack.zip.002 Pack.zip` on Windows).",
"",
"Every release ships `SHA256SUMS.txt` and a detached signature of it,"
" checkable against `allowed_signers` in this repository:"
" [verifying a release]"
"(https://abdess.github.io/retrobios/wiki/release-process/"
"#verifying-a-release).",
"",
"| Platform | Extracted size | Extract to | Download |",
"|----------|---------------:|-----------|----------|",
]