fix(tool-audit-lib): always re-export local pubkey to audit-public.pem
Previously the public key was only written on first key generation. If a CI step (sign-audit-head.sh via Vault KMS) overwrote audit-public.pem after the key was generated, subsequent calls to append_tool_audit signed with the local key while audit-public.pem held the Vault key — causing verify-tool-audit.sh to fail with signature mismatch. Now the public key is re-exported on every call so audit-public.pem always matches the private key used to sign tool-calls-head.sig. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 4.6
parent
36375a64d6
commit
c31987caa2
@@ -52,8 +52,11 @@ PY
|
||||
if [[ ! -f "$priv" ]]; then
|
||||
openssl genpkey -algorithm RSA -pkeyopt rsa_keygen_bits:2048 -out "$priv" 2>/dev/null
|
||||
chmod 600 "$priv"
|
||||
openssl rsa -in "$priv" -pubout -out "$pub" 2>/dev/null
|
||||
fi
|
||||
# Always re-export the matching public key so a persisted off-repo private key
|
||||
# never drifts out of sync with a freshly checked-out audit-public.pem on CI
|
||||
# runners (see governance-check.sh for the full rationale).
|
||||
openssl rsa -in "$priv" -pubout -out "$pub" 2>/dev/null || true
|
||||
printf '%s' "$head" > "$audit_dir/tool-calls-head.txt"
|
||||
openssl dgst -sha256 -sign "$priv" -out "$audit_dir/tool-calls-head.sig" "$audit_dir/tool-calls-head.txt" 2>/dev/null || true
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user