Skip to content

feat: optional independent signed catalog authority receipt - #741

Draft
altrudev wants to merge 3 commits into
agentrust-io:mainfrom
altrudev:fix/catalog-authority-bridge-upstream-20261010
Draft

altrudev wants to merge 3 commits into
agentrust-io:mainfrom
altrudev:fix/catalog-authority-bridge-upstream-20261010

Conversation

@altrudev

Copy link
Copy Markdown
Contributor

Summary

Adds an opt-in, independently signed Ed25519 correspondence receipt binding the Agent Manifest signing digest, agent identity, policy bundle hash, complete sealed cMCP catalog hash, and Agent Manifest Merkle root. Preserves upstream #713 native tool projection and verification; no replacement or bypass of SDK validation.

Assurance

  • Domain-separated signed receipt, strict canonical fields and validity interval
  • Fail-closed startup when configured receipt, measurements or signer are invalid
  • Native upstream catalog verification remains mandatory
  • Operator deployment/rotation and limitation documentation
  • Local VPS: pytest -q tests/unit tests/integration: 2382 passed, 6 skipped, 4 deprecation warnings; git diff --check clean
  • Six skips: real Azure SEV-SNP fixture (2), real TDX quote (2), optional Agent Governance Toolkit package (2)

Review requests

Please review whether an independent issuer receipt is useful alongside native Merkle binding; specifically JSON/COSE signing preimages, trust anchor management, optional deployment semantics, and cryptographic canonicalization. This is a draft for independent maintainer review, not a claim of hardware attestation or release approval.

No private keys or proprietary runtime implementation are included.

@github-actions

github-actions Bot commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

🔴 Contributor Check: HIGH

Check Result
Profile HIGH
Credential LOW
Overall HIGH

Automated check by AgenTrust Contributor Check.

@github-actions github-actions Bot added the needs-review:HIGH Contributor check flagged HIGH risk label Oct 10, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-review:HIGH Contributor check flagged HIGH risk

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant