Skip to content

mirror_worker: sync Chrome cosigner registry - #296

Open
lukevalenta wants to merge 5 commits into
mainfrom
lvalenta/rtg-5259-sync-cosigners
Open

lukevalenta wants to merge 5 commits into
mainfrom
lvalenta/rtg-5259-sync-cosigners

Conversation

@lukevalenta

Copy link
Copy Markdown
Contributor

Implements RTG-5259.

When enable_chrome_cosigners is enabled, an hourly scheduled event fetches Chrome's cosigners.json and public-key bundle. A singleton Durable Object validates and atomically stores the normalized issuer registry, retaining the last-known-good snapshot when synchronization fails.

Chrome issuers are expanded across their recognized issuance-log window and used by add-checkpoint, add-entries, sign-subtree, and metadata. The existing logs map remains available for custom cosigners and takes precedence when an origin appears in both sources.

Registry ingestion verifies exact HTTP responses, response-size limits, relative OIDs, log-number bounds, PEM fingerprint bindings, and pure ML-DSA-44 SPKIs. It also rejects changed content under an unchanged version and parseable timestamp regressions.

Comment thread crates/mirror_worker/src/cleaner_do.rs
Comment thread crates/mirror_worker/wrangler.jsonc Outdated
@lukevalenta lukevalenta self-assigned this Oct 2, 2026
@lukevalenta
lukevalenta marked this pull request as ready for review October 2, 2026 18:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant