Sign and verify manifests in Go with OpenPGP instead of running gpg (closes #181)
check / check (push) Waiting to run

mfer ran the gpg binary to sign, export keys and verify, so signing and
loading signed manifests failed wherever gpg is missing. It now uses
github.com/ProtonMail/go-crypto/openpgp. --sign-key and MFER_SIGN_KEY
name a file holding one version 4 OpenPGP secret key; a protected key's
passphrase comes from MFER_SIGN_KEY_PASSPHRASE or a terminal prompt. gen
and freshen check that the key can sign before they read any file.
Verification keeps the rules of the --require-signature fix: one primary
key in the embedded block, counted from its packets, exactly one
signature, made by that key or a subkey, and signer equal to its
fingerprint. A DSA key is refused, and so is an armored field that is
not one well-formed block.

Model: opus-5-5
This commit is contained in:
2026-10-08 05:21:16 +00:00
committed by sneak
parent c23367c216
commit e00ec787e8
25 changed files with 1585 additions and 1178 deletions
+2 -3
View File
@@ -21,8 +21,8 @@ import (
"sneak.berlin/go/mfer/mfer"
)
// fingerprintHexLen is the length of a full GPG key fingerprint in hex
// characters.
// fingerprintHexLen is the length in hex characters of the fingerprint of
// an OpenPGP version 4 key, the only version mfer signs with.
const fingerprintHexLen = 40
var (
@@ -320,7 +320,6 @@ func (mfa *CLIApp) checkManifestOperation(
log.Infof("checking manifest %s with base %s", manifestPath, basePath)
// Create checker
//nolint:contextcheck // mfer loads a manifest without a context
chk, err := mfer.NewChecker(&mfer.CheckerOptions{
ManifestPath: manifestPath,
BasePath: basePath,