Skip to content

Commit fef448a

Browse files
fix(schema): re-sync trace-v0.2.json with trace-spec (#46)
* fix schema parity resync * fix(schema): sync the current normative confirmation-key constraints Signed-off-by: Imran Siddique <imran.siddique@opaque.co> --------- Signed-off-by: Imran Siddique <imran.siddique@opaque.co> Co-authored-by: Imran Siddique <imran.siddique@opaque.co>
1 parent abe54cd commit fef448a

1 file changed

Lines changed: 43 additions & 3 deletions

File tree

‎schema/trace-v0.2.json‎

Lines changed: 43 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -61,8 +61,8 @@
6161
},
6262
"subject": {
6363
"type": "string",
64-
"description": "Workload identity as a SPIFFE SVID URI or DID URI.",
65-
"pattern": "^(spiffe://|did:)"
64+
"description": "Workload identity as a SPIFFE SVID URI or DID URI. A SPIFFE ID carries a trust domain and a workload path within it; a DID carries a lowercase method name, per DID Core section 3.1, and a method-specific identifier. A prefix alone is not an identity: spiffe://example.org names a trust domain and no workload.",
65+
"pattern": "^(spiffe://[^/]+/.+|did:[a-z0-9]+:.+)$"
6666
},
6767
"model": {
6868
"type": "object",
@@ -119,7 +119,7 @@
119119
"tpm2",
120120
"software-only"
121121
],
122-
"description": "Hardware platform providing the root of trust. software-only marks development-mode records with no hardware backing; they must never be treated as attested evidence."
122+
"description": "Hardware platform providing the root of trust. software-only marks records with no hardware root of trust, for example a development-mode execution, or a record assembled from evidence produced outside the runtime (origin.kind other than self requires this value; see spec 3.1.1). Such records must never be treated as attested evidence."
123123
},
124124
"measurement": {
125125
"type": "string",
@@ -472,6 +472,46 @@
472472
}
473473
}
474474
],
475+
"not": {
476+
"anyOf": [
477+
{
478+
"required": [
479+
"d"
480+
]
481+
},
482+
{
483+
"required": [
484+
"p"
485+
]
486+
},
487+
{
488+
"required": [
489+
"q"
490+
]
491+
},
492+
{
493+
"required": [
494+
"dp"
495+
]
496+
},
497+
{
498+
"required": [
499+
"dq"
500+
]
501+
},
502+
{
503+
"required": [
504+
"qi"
505+
]
506+
},
507+
{
508+
"required": [
509+
"k"
510+
]
511+
}
512+
]
513+
},
514+
"$comment": "RFC 8747 defines cnf as a confirmation key: the public half, present so a verifier can bind the record to the key that signed it. A private member here publishes the signing key inside the signed, self-authenticating, typically anchored record, and the only remedy afterwards is to revoke the identity. Mirrors _JWK_PRIVATE_PARAMS in the reference model, which already refuses these.",
475515
"additionalProperties": {
476516
"$ref": "#/$defs/canonicalizableValue"
477517
}

0 commit comments

Comments
 (0)