Skip to content

M5.7: external restore receipt chain anchors - #33

Merged
pgousdal merged 5 commits into
mainfrom
work/m5.7-receipt-anchor
Sep 8, 2026
Merged

pgousdal merged 5 commits into
mainfrom
work/m5.7-receipt-anchor

Conversation

@pgousdal

@pgousdal pgousdal commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

Adds deterministic external anchors for the M5.6 restore receipt hash chain. GET /api/recording-archive/receipts/anchor downloads a versioned JSON anchor containing only receipt_count and head_hash. POST /api/recording-archive/receipts/anchor/verify strictly validates an uploaded anchor and verifies it against the exact historical chain prefix, so a trusted old anchor remains valid after legitimate later receipts are appended. The verifier first requires the complete local receipt chain to be valid, rejects unsupported versions, malformed hashes, future counts, unknown JSON fields and trailing JSON, and returns match or extended for valid anchors. Includes exact/extended/mismatch/API tests, README and M5.7 docs. No external provider, signing service, API key or automatic network publishing is introduced; the security benefit depends on retaining an independent copy outside the appliance trust boundary.

@pgousdal
pgousdal merged commit 0d3e12b into main Sep 8, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant