Skip to content

Emit boot evidence topology attestation #24

@mdheller

Description

@mdheller

Purpose

Implement boot/session evidence continuity for SourceOS Mutation and Evidence Accountability, anchored to SourceOS spec PR #96:

SourceOS-Linux/sourceos-spec#96

Required work

  • Emit BootEvidenceTopologyAttestation at boot.
  • Generate stable boot_id and session_id values.
  • Attest evidence/log sinks, enabled sensors, disabled sensors, degraded sensors, privilege state, redaction profiles, and retention policies.
  • Record OS deployment identity, kernel build, image digest, symbolication bundle state, measured boot references where available.

Acceptance criteria

  • Every receipt can attach to a boot/session context.
  • Missing or degraded boot evidence prevents high-confidence security clearance.
  • The boot attestation can be consumed by SourceOS Shell and sourceos-devtools validators.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions