Plugin signing and verifying - #6
Closed
scottrigby wants to merge 78 commits into
Closed
scottrigby wants to merge 78 commits into
scottrigby wants to merge 78 commits into
Conversation
…mand type flag Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
…e postrender Signed-off-by: Scott Rigby <scott@r6by.com>
…mplete: // NOTE(thomastaylor312): I am leaving this code commented out here. During // the implementation of post-render, it was brought up that if we are // relying on plugins, we should actually use the plugin system so it can // properly handle multiple OSs. This will be a feature add in the future, // so I left this code for reference. It can be deleted or reused once the // feature is implemented Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
… unmarshall strict Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
…pe (legacy plugins are either cli or download) Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
fix nil pointer dereference for tests Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
…subprocess and Wasm). Move fields to the applicable config structs. TODO update tests and testdata YAML to match Signed-off-by: Scott Rigby <scott@r6by.com>
…tch, and update tests to match Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
…t but with the wrong value. Give better error instead Signed-off-by: Scott Rigby <scott@r6by.com>
…plugin.yaml fully if they set apiVersion to v1 Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
… it's consistent) Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
… way to preserve file mode for executables Signed-off-by: Scott Rigby <scott@r6by.com>
…update plugin OCI installer accordingly Signed-off-by: Scott Rigby <scott@r6by.com>
OCI plugin installer
…cy_downloader_convert Fix legacy metadata downloader convert
Signed-off-by: Scott Rigby <scott@r6by.com> fix plugin HTTP tarball support Signed-off-by: Scott Rigby <scott@r6by.com> fix plugin local tarball support Signed-off-by: Scott Rigby <scott@r6by.com> Plugin signing and provenance support Signed-off-by: Scott Rigby <scott@r6by.com> Add verify flag to plugin install Signed-off-by: Scott Rigby <scott@r6by.com> Add installed plugin provenance tracking, with errors, warnings, and info during plugin commands Signed-off-by: Scott Rigby <scott@r6by.com> Allow plugin verify cmd to verify directories for installed signed plugins Signed-off-by: Scott Rigby <scott@r6by.com> Replace tarball-based hashing with idempotent directory-based hashing Signed-off-by: Scott Rigby <scott@r6by.com> Fix plugin package --sign case where tarball was created even if no signing key was found Signed-off-by: Scott Rigby <scott@r6by.com> update plugin package command to sign by default. bypass with --sign=false. emit warning if so Signed-off-by: Scott Rigby <scott@r6by.com> Fix TestIsRemoteHTTPArchive caused by optimization added in commit 00cbd42 that changed the behavior of isRemoteHTTPArchive Signed-off-by: Scott Rigby <scott@r6by.com> Fix TestExtractPluginInSubdirectory test failure The test was failing with "destination already exists" error because it was calling installer.Install() directly without going through the InstallWithOptions wrapper that checks for existing installations. Added cleanup of the destination directory before installation to match the behavior of the wrapper function. Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
scottrigby
force-pushed
the
plugin-signing
branch
from
August 13, 2025 07:47
4c3a918 to
b8ed27f
Compare
Signed-off-by: Scott Rigby <scott@r6by.com>
gjenkins8
reviewed
Aug 13, 2025
| shouldVerify := o.verify | ||
|
|
||
| // Check if this is a local directory installation (for development) | ||
| if localInst, ok := i.(*installer.LocalInstaller); ok && !localInst.SupportsVerification() { |
Collaborator
There was a problem hiding this comment.
should we skip verification for legacy plugins too?
Owner
Author
There was a problem hiding this comment.
the new codebase can sign legacy plugins too. I think we should encourage this with all plugins including legacy. Right now --verify defaults to true (users can bypass it with --verify=false and they get a warning).
gjenkins8
reviewed
Aug 13, 2025
| } | ||
|
|
||
| // Also remove the .prov file if it exists | ||
| provFile := p.Dir() + ".prov" |
Collaborator
There was a problem hiding this comment.
Is this needed? The os.RemoveAll(p.Dir()) should clean up everything?
Owner
Author
There was a problem hiding this comment.
ah, no, the .prov file sits next to the plugin dir in the HELM_PLUGINS directory.
truncated example from my laptop now:
% ls -lah $(go run ./cmd/helm env HELM_PLUGINS)
total 8
drwxr-xr-x@ 10 r6by staff 320B Aug 13 05:05 .
drwxr-xr-x@ 3 r6by staff 96B Jan 21 2025 ..
drwxr-xr-x@ 4 r6by staff 128B Aug 13 05:05 example-cli
-rw-r--r--@ 1 r6by staff 897B Aug 13 05:05 example-cli.prov
lrwxr-xr-x@ 1 r6by staff 83B Aug 13 01:54 example-extism-getter -> /Users/r6by/code/github.com/scottrigby/h4-simple-plugin-types/example-extism-getter
lrwxr-xr-x@ 1 r6by staff 76B Aug 13 01:18 example-getter -> /Users/r6by/code/github.com/scottrigby/h4-simple-plugin-types/example-getter
gjenkins8
force-pushed
the
plugin-system
branch
from
August 16, 2025 20:25
584f7c5 to
dd338a8
Compare
scottrigby
force-pushed
the
plugin-system
branch
from
August 16, 2025 22:48
dd338a8 to
9ea7867
Compare
gjenkins8
force-pushed
the
plugin-system
branch
from
August 17, 2025 05:54
a0c50a4 to
bbd1bca
Compare
Owner
Author
|
this is complete in upstream helm/helm |
scottrigby
added a commit
that referenced
this pull request
Aug 13, 2026
…26-6061 backport of helm#32450 updated with: ``` go get google.golang.org/grpc@v1.82.1 go mod tidy ``` example actions failure: https://github.com/helm/helm/actions/runs/31733009013/job/94557780520 ``` Vulnerability #1: GO-2026-6061 Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc More info: https://pkg.go.dev/vuln/GO-2026-6061 Module: google.golang.org/grpc Found in: google.golang.org/grpc@v1.80.0 Fixed in: google.golang.org/grpc@v1.82.1 Example traces found: Error: #1: pkg/repo/repotest/server.go:128:32: repotest.NewOCIServer calls registry.NewRegistry, which eventually calls transport.ClientStream.Close Error: #2: pkg/repo/repotest/server.go:128:32: repotest.NewOCIServer calls registry.NewRegistry, which eventually calls transport.ClientStream.Header Error: #3: pkg/repo/repotest/server.go:128:32: repotest.NewOCIServer calls registry.NewRegistry, which eventually calls transport.ClientStream.Read Error: #4: pkg/repo/repotest/server.go:128:32: repotest.NewOCIServer calls registry.NewRegistry, which eventually calls transport.ClientStream.RecvCompress Error: #5: pkg/repo/repotest/server.go:128:32: repotest.NewOCIServer calls registry.NewRegistry, which eventually calls transport.ClientStream.TrailersOnly Error: #6: pkg/repo/repotest/server.go:128:32: repotest.NewOCIServer calls registry.NewRegistry, which eventually calls transport.ClientStream.Write Error: #7: pkg/action/lazyclient.go:49:17: action.lazyClient.init calls sync.Once.Do, which eventually calls transport.NewHTTP2Client Error: #8: pkg/repo/repotest/server.go:128:32: repotest.NewOCIServer calls registry.NewRegistry, which eventually calls transport.Stream.ReadMessageHeader Error: #9: pkg/action/lazyclient.go:49:17: action.lazyClient.init calls sync.Once.Do, which eventually calls transport.http2Client.Close Error: #10: pkg/action/lazyclient.go:49:17: action.lazyClient.init calls sync.Once.Do, which eventually calls transport.http2Client.GracefulClose Error: #11: pkg/repo/repotest/server.go:128:32: repotest.NewOCIServer calls registry.NewRegistry, which eventually calls transport.http2Client.NewStream ``` Signed-off-by: Scott Rigby <scott@r6by.com>
scottrigby
added a commit
that referenced
this pull request
Aug 13, 2026
…26-6061 (helm#32536) backport of helm#32450 updated with: ``` go get google.golang.org/grpc@v1.82.1 go mod tidy ``` example actions failure: https://github.com/helm/helm/actions/runs/31733009013/job/94557780520 ``` Vulnerability #1: GO-2026-6061 Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc More info: https://pkg.go.dev/vuln/GO-2026-6061 Module: google.golang.org/grpc Found in: google.golang.org/grpc@v1.80.0 Fixed in: google.golang.org/grpc@v1.82.1 Example traces found: Error: #1: pkg/repo/repotest/server.go:128:32: repotest.NewOCIServer calls registry.NewRegistry, which eventually calls transport.ClientStream.Close Error: #2: pkg/repo/repotest/server.go:128:32: repotest.NewOCIServer calls registry.NewRegistry, which eventually calls transport.ClientStream.Header Error: #3: pkg/repo/repotest/server.go:128:32: repotest.NewOCIServer calls registry.NewRegistry, which eventually calls transport.ClientStream.Read Error: #4: pkg/repo/repotest/server.go:128:32: repotest.NewOCIServer calls registry.NewRegistry, which eventually calls transport.ClientStream.RecvCompress Error: #5: pkg/repo/repotest/server.go:128:32: repotest.NewOCIServer calls registry.NewRegistry, which eventually calls transport.ClientStream.TrailersOnly Error: #6: pkg/repo/repotest/server.go:128:32: repotest.NewOCIServer calls registry.NewRegistry, which eventually calls transport.ClientStream.Write Error: #7: pkg/action/lazyclient.go:49:17: action.lazyClient.init calls sync.Once.Do, which eventually calls transport.NewHTTP2Client Error: #8: pkg/repo/repotest/server.go:128:32: repotest.NewOCIServer calls registry.NewRegistry, which eventually calls transport.Stream.ReadMessageHeader Error: #9: pkg/action/lazyclient.go:49:17: action.lazyClient.init calls sync.Once.Do, which eventually calls transport.http2Client.Close Error: #10: pkg/action/lazyclient.go:49:17: action.lazyClient.init calls sync.Once.Do, which eventually calls transport.http2Client.GracefulClose Error: #11: pkg/repo/repotest/server.go:128:32: repotest.NewOCIServer calls registry.NewRegistry, which eventually calls transport.http2Client.NewStream ``` Signed-off-by: Scott Rigby <scott@r6by.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR adds plugin signing, verifying and commands described in HIP 0026
to-do:
--verifyoption to OCI plugin installer #2