#!/usr/bin/env bash set -uo pipefail # CASAN Plan-16 SEC-25 (SC-07, offline) — build-artifact attestation (tested==deployed). # # Proves (no network): # * an artifact attested + verified passes (tested == deployed), # * modifying the artifact after attestation -> MISMATCH (deployed != tested) REFUSED, # * a forged attestation (signed by a different key) is REFUSED, # * a missing or UNSIGNED attestation fails CLOSED. # # Deterministic; hermetic; uses openssl (skip-aware). SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" source "$SCRIPT_DIR/../scripts/bash/casan-paths.sh" PROJECT_ROOT="$(cd "$SCRIPT_DIR/../.." && pwd)" AA="$CASAN_HARNESS_ROOT/scripts/bash/artifact-attest.sh" WORK="$(mktemp -d)" trap 'rm -rf "$WORK"' EXIT PASS=0; FAIL=0 pass() { echo "PASS: $1"; PASS=$((PASS + 1)); } fail() { echo "FAIL: $1"; FAIL=$((FAIL + 1)); } rc_of() { set +e; "$@" >/dev/null 2>&1; echo $?; set -e 2>/dev/null || true; } command -v openssl >/dev/null 2>&1 || { echo "SKIP: openssl unavailable"; exit 0; } echo "===== Plan-16 SEC-25: build-artifact attestation (offline) =====" openssl genrsa -out "$WORK/build.priv.pem" 2048 2>/dev/null openssl rsa -in "$WORK/build.priv.pem" -pubout -out "$WORK/build.pub.pem" 2>/dev/null openssl genrsa -out "$WORK/atk.priv.pem" 2048 2>/dev/null printf 'tested release artifact v1\n' > "$WORK/app.tar" # --- attest + verify -> OK --- bash "$AA" attest "$WORK/app.tar" "$WORK/build.priv.pem" >/dev/null 2>&1 [[ "$(rc_of bash "$AA" verify "$WORK/app.tar" "$WORK/app.tar.att" "$WORK/build.pub.pem")" -eq 0 ]] \ && pass "attested artifact verifies (tested==deployed)" || fail "attested artifact rejected" # --- deployed != tested -> MISMATCH --- cp "$WORK/app.tar" "$WORK/app2.tar" bash "$AA" attest "$WORK/app2.tar" "$WORK/build.priv.pem" >/dev/null 2>&1 printf 'SWAPPED malicious artifact\n' > "$WORK/app2.tar" # different deploy than tested [[ "$(rc_of bash "$AA" verify "$WORK/app2.tar" "$WORK/app2.tar.att" "$WORK/build.pub.pem")" -eq 2 ]] \ && pass "swapped artifact (deployed!=tested) REFUSED" || fail "artifact swap not detected" # --- forged attestation (wrong key) -> REFUSED --- cp "$WORK/app.tar" "$WORK/app3.tar" bash "$AA" attest "$WORK/app3.tar" "$WORK/atk.priv.pem" >/dev/null 2>&1 # signed by attacker [[ "$(rc_of bash "$AA" verify "$WORK/app3.tar" "$WORK/app3.tar.att" "$WORK/build.pub.pem")" -eq 2 ]] \ && pass "forged attestation (wrong key) REFUSED" || fail "forged attestation accepted" # --- missing attestation -> fail-closed --- printf 'unattested\n' > "$WORK/app4.tar" [[ "$(rc_of bash "$AA" verify "$WORK/app4.tar" "$WORK/app4.tar.att" "$WORK/build.pub.pem")" -eq 3 ]] \ && pass "missing attestation fails CLOSED" || fail "missing attestation not refused" # --- unsigned attestation -> fail-closed --- cp "$WORK/app.tar" "$WORK/app5.tar" bash "$AA" attest "$WORK/app5.tar" "$WORK/build.priv.pem" >/dev/null 2>&1 rm -f "$WORK/app5.tar.att.sig" # strip signature [[ "$(rc_of bash "$AA" verify "$WORK/app5.tar" "$WORK/app5.tar.att" "$WORK/build.pub.pem")" -eq 3 ]] \ && pass "UNSIGNED attestation fails CLOSED" || fail "unsigned attestation not refused" echo "" echo "===== SEC-25 SUMMARY: PASS=$PASS FAIL=$FAIL =====" [[ "$FAIL" -eq 0 ]] || exit 1