Commit 037d5ce
committed
fix(validate): never emit evidence in --no-cluster dry-run mode
A --no-cluster validate is an offline dry-run that reports every check as
"skipped", yet it still honored spec.validate.evidence.attestation.{out,push}
and built, signed, pushed, and wrote a pointer for a full evidence bundle.
In the UAT flow this made the prep phase's dry-run emit a first signed bundle
to the recipe's evidence OCI repo (content-hash tag) before the authoritative
conformance-phase validate emitted a second, differently-digested signed bundle
to the run-<id> tag. With two independently-signed bundles co-located in one
repo, `aicr evidence verify` (and the downstream Evidence: Ingest job) resolved
a signature whose signed subject no longer matched the pulled run-tagged
artifact, failing with a subject/pulled digest mismatch.
Fix in two layers:
- CLI: evidenceConfigForRunMode drops the recipe-evidence config when
--no-cluster is set, so an offline dry-run can never sign or push an
attestation regardless of config. Emitting evidence over an all-skipped run
attests to nothing.
- UAT: the prep phase validates against a config copy with
spec.validate.evidence stripped (mirroring the readiness-gate strip in the
conformance phase), keeping prep safe even against an older released aicr
that predates the CLI guard.
Documents the behavior on the --no-cluster row of the CLI reference.
Signed-off-by: Nathan Hensley <nhensley@nvidia.com>1 parent 6f9050b commit 037d5ce
5 files changed
Lines changed: 67 additions & 3 deletions
File tree
- docs/user
- pkg/cli
- tests/uat/lib
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
832 | 832 | | |
833 | 833 | | |
834 | 834 | | |
835 | | - | |
| 835 | + | |
836 | 836 | | |
837 | 837 | | |
838 | 838 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
758 | 758 | | |
759 | 759 | | |
760 | 760 | | |
761 | | - | |
| 761 | + | |
762 | 762 | | |
763 | 763 | | |
764 | 764 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
| 19 | + | |
19 | 20 | | |
20 | 21 | | |
21 | 22 | | |
| |||
82 | 83 | | |
83 | 84 | | |
84 | 85 | | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
85 | 105 | | |
86 | 106 | | |
87 | 107 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
189 | 189 | | |
190 | 190 | | |
191 | 191 | | |
| 192 | + | |
| 193 | + | |
| 194 | + | |
| 195 | + | |
| 196 | + | |
| 197 | + | |
| 198 | + | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
| 202 | + | |
| 203 | + | |
| 204 | + | |
| 205 | + | |
| 206 | + | |
| 207 | + | |
| 208 | + | |
| 209 | + | |
| 210 | + | |
| 211 | + | |
| 212 | + | |
| 213 | + | |
| 214 | + | |
| 215 | + | |
| 216 | + | |
| 217 | + | |
| 218 | + | |
| 219 | + | |
| 220 | + | |
| 221 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
170 | 170 | | |
171 | 171 | | |
172 | 172 | | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
| 185 | + | |
173 | 186 | | |
174 | | - | |
| 187 | + | |
175 | 188 | | |
176 | 189 | | |
177 | 190 | | |
| 191 | + | |
178 | 192 | | |
179 | 193 | | |
180 | 194 | | |
| |||
0 commit comments