fix: artifact verify mints a fresh audit key on hosts without one, turning clean receipts into false TAMPERED verdicts - #4581
Conversation
|
VERDICT: request-changes Blocking findings1.
|
|
VERDICT: request-changes Unresolved findings
Made by bernstein v3.18.0 - unattended review run |
…ipyourdrink-ltd#4595) Two changes merged without a release-notes fragment, so neither is discoverable from the release notes: - **sipyourdrink-ltd#4473** — plan rendering is deterministic and carries a SHA-256 of the rendered form. - **sipyourdrink-ltd#4581** — `bernstein artifact verify` no longer mints a fresh audit key on a host without one; it previously recomputed every HMAC against the wrong key and reported clean receipts as `TAMPERED`. The review flagged the missing fragment on both at the time.
Closes #4532
Problem
bernstein artifact verifygives a third-party verifier a false TAMPERED verdict instead of the designed "HMAC leg skipped" degradation.Change
Housekeeping, not what this pull request is about:
53b89b4)754d956)55dcccf)Verification
Provenance
sha256:6b63c12686b42be868f6a581a9077b30458d148867d5d2e2542bde248d3cfdabb68cc703ed23c3ad9b6c61dd0a3babfb4d010b115cec9eb983bbadcfadec72bcbernstein review-receipt verify --pr <this PR> --issue <issue.md> --diff <pr.diff>Generated from Bernstein session
1787702276.bernstein-session-id: 1787702276
Made by bernstein v3.18.0 - unattended run
run-20260825T233445p360736Z, no operator in the loop.