Files
CASAN/AINative_OKR_CASAN5/.specify/scripts/bash/telemetry-integrity.sh
T
thanhnvandClaude Opus 4.8 7e998f67c2 feat(h5-h6-hardening): Plan-07 Track A — A4 telemetry integrity, A5 cost controls
A4 (V9): telemetry-integrity.sh binds provider-usage.jsonl + cost/metrics.jsonl
  to a signed manifest head. Tampering a token flips the head (MISMATCH); an
  attacker who rewrites the head cannot re-sign it (SIGNATURE_INVALID) without
  the off-repo key. sign-audit-head.sh now also signs telemetry (best-effort).
  Supports CASAN_AUDIT_PRIV/PUB overrides for self-contained verification.
A5 (V12/V13/V14): cost-spike-detect.sh adds an absolute per-call cap
  (CASAN_COST_ABSOLUTE_MAX_TOKENS, enforced from record #1 → catches slow-boil
  and cold-start) and a cumulative budget (CASAN_COST_CUMULATIVE_BUDGET_TOKENS →
  catches under-threshold spray), keeping the existing median×mult spike test.
  Backward compatible: <3 records with no caps still exits 3.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-03 22:25:00 +09:00

108 lines
4.1 KiB
Bash
Executable File

#!/usr/bin/env bash
set -uo pipefail
# CASAN H5 — Telemetry integrity proof (Track A, V9).
#
# Token/cost telemetry (provider-usage.jsonl, cost/metrics.jsonl) previously sat
# OUTSIDE the signed audit chain, so a forger could rewrite token counts to hide
# cost abuse and nothing would detect it. This binds those files to a signed
# manifest: any byte change flips the manifest head hash, and because the head
# is RSA-signed with an off-repo key, a forger cannot re-sign a rewritten head.
#
# Usage:
# telemetry-integrity.sh sign — hash telemetry files, write + sign manifest head
# telemetry-integrity.sh verify — recompute, compare head, verify signature
#
# Key resolution (sign): CASAN_AUDIT_PRIV, else level5/central-governance/audit-private.pem
# Key resolution (verify): CASAN_AUDIT_PUB, else level5/central-governance/audit-public.pem
#
# Outputs (under .specify/logs/level5/):
# telemetry-manifest.json — {basename: sha256} for each telemetry file
# telemetry-head.txt — sha256 over the canonical manifest text
# telemetry-head.sig — RSA signature of telemetry-head.txt (when a key exists)
#
# Exit: 0 ok, 1 tamper/mismatch/invalid-signature, 64 usage.
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
PROJECT_ROOT="$(cd "$SCRIPT_DIR/../../.." && pwd)"
L5_DIR="$PROJECT_ROOT/.specify/logs/level5"
COST_DIR="$PROJECT_ROOT/.specify/logs/cost"
mkdir -p "$L5_DIR"
CMD="${1:-}"
MANIFEST="$L5_DIR/telemetry-manifest.json"
HEAD_FILE="$L5_DIR/telemetry-head.txt"
HEAD_SIG="$L5_DIR/telemetry-head.sig"
AUDIT_PRIV="${CASAN_AUDIT_PRIV:-$PROJECT_ROOT/.specify/level5/central-governance/audit-private.pem}"
AUDIT_PUB="${CASAN_AUDIT_PUB:-$PROJECT_ROOT/.specify/level5/central-governance/audit-public.pem}"
# Telemetry files to bind. Missing files hash to the literal "MISSING" so the
# manifest is stable and a deletion is itself a detectable change.
TELEMETRY_FILES=(
"$L5_DIR/provider-usage.jsonl"
"$COST_DIR/metrics.jsonl"
)
compute_head() {
# Prints: manifest-json on line 1, head-hash on line 2.
python - "$@" <<'PY'
import hashlib, json, os, sys
files = sys.argv[1:]
manifest = {}
for path in files:
name = os.path.basename(path)
if os.path.isfile(path):
with open(path, "rb") as f:
manifest[name] = hashlib.sha256(f.read()).hexdigest()
else:
manifest[name] = "MISSING"
canonical = json.dumps(manifest, sort_keys=True, separators=(",", ":"))
head = hashlib.sha256(canonical.encode()).hexdigest()
print(canonical)
print(head)
PY
}
case "$CMD" in
sign)
OUT="$(compute_head "${TELEMETRY_FILES[@]}")"
CANON="$(printf '%s' "$OUT" | sed -n '1p')"
HEAD="$(printf '%s' "$OUT" | sed -n '2p')"
printf '%s' "$CANON" > "$MANIFEST"
printf '%s' "$HEAD" > "$HEAD_FILE"
if [[ -f "$AUDIT_PRIV" ]] && command -v openssl >/dev/null 2>&1; then
openssl dgst -sha256 -sign "$AUDIT_PRIV" -out "$HEAD_SIG" "$HEAD_FILE"
echo "TELEMETRY_INTEGRITY_SIGNED head=$HEAD anchor=signed files=${#TELEMETRY_FILES[@]}"
else
rm -f "$HEAD_SIG"
echo "TELEMETRY_INTEGRITY_SIGNED head=$HEAD anchor=unsigned files=${#TELEMETRY_FILES[@]} (no private key)"
fi
;;
verify)
if [[ ! -f "$HEAD_FILE" ]]; then
echo "TELEMETRY_INTEGRITY_MISSING no telemetry-head.txt (run: telemetry-integrity.sh sign)" >&2
exit 1
fi
OUT="$(compute_head "${TELEMETRY_FILES[@]}")"
HEAD_NOW="$(printf '%s' "$OUT" | sed -n '2p')"
HEAD_STORED="$(cat "$HEAD_FILE")"
if [[ "$HEAD_NOW" != "$HEAD_STORED" ]]; then
echo "TELEMETRY_INTEGRITY_MISMATCH computed=$HEAD_NOW stored=$HEAD_STORED" >&2
exit 1
fi
if [[ -f "$HEAD_SIG" && -f "$AUDIT_PUB" ]] && command -v openssl >/dev/null 2>&1; then
if ! openssl dgst -sha256 -verify "$AUDIT_PUB" -signature "$HEAD_SIG" "$HEAD_FILE" >/dev/null 2>&1; then
echo "TELEMETRY_INTEGRITY_SIGNATURE_INVALID head=$HEAD_STORED" >&2
exit 1
fi
echo "TELEMETRY_INTEGRITY_VALID anchor=signed head=$HEAD_STORED"
else
echo "TELEMETRY_INTEGRITY_VALID anchor=unsigned head=$HEAD_STORED"
fi
;;
*)
echo "Usage: telemetry-integrity.sh {sign|verify}" >&2
exit 64
;;
esac