WIP: make additional decryption work - #306
mlohvynenko wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Resolve the unregistered diskencryption module dependency and correct crypto member destruction ordering.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
What changed in this PR
Adds local encrypted-layer decryption support to the Service Manager and integrates it with image management.
Changes:
- Adds crypto helper, local key provider, and blob decryptor.
- Initializes decryption components and injects the decryptor into
ImageManager. - Updates the certificate-loader test stub.
| File | Description |
|---|---|
src/sm/app/aoscore.hpp |
Declares decryption dependencies and configuration. |
src/sm/app/aoscore.cpp |
Initializes decryption services and integrates them with image management. |
src/cm/smcontroller/tests/stubs/certloaderstub.hpp |
Implements the expanded certificate-loader interface. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| // installed, so a node with no key provisioned starts up fine and only fails if it's asked to install | ||
| // an encrypted layer. | ||
|
|
||
| err = mLocalDataKeyProvider.Init(mAllocator, mIAMClient, mCertLoader, cLayerEncryptionCertType); |
| constexpr auto cSupportedMediaTypes = std::array { | ||
| oci::cMediaTypeLayerTar, | ||
| oci::cMediaTypeLayerTarGZip, | ||
| oci::cMediaTypeLayerTarGZipEncrypted, |
58397fa to
4963d69
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Encrypted gzip size handling is incomplete, and the required core-library API is unavailable at the configured revision.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
| constexpr auto cSupportedMediaTypes = std::array { | ||
| oci::cMediaTypeLayerTar, | ||
| oci::cMediaTypeLayerTarGZip, | ||
| oci::cMediaTypeLayerTarGZipEncrypted, |
Signed-off-by: Mykhailo Lohvynenko <mykhailo_lohvynenko@epam.com>
4963d69 to
760f747
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Critical external API mismatches prevent compilation, and encrypted gzip handling and helper wiring remain incomplete.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 3
Open (6)
ImageManager::Init call uses unsupported ten-argument API · New Included header is unavailable in the pinned core library · New Core library dependency lacks required OCI encryption APIs Helper initialized but not wired into any SM component · New Handle encrypted gzip layers in GetUnpackedLayerSize Unregistered diskencryption module breaks encrypted-layer installation
|
|
||
| err = mImageManager.Init(mAllocator, mConfig.mImageManager, mSMClient, mImagesSpaceAllocator, mDownloader, | ||
| mFileInfoProvider, mOCISpec, mImageHandler, mDatabase); | ||
| mFileInfoProvider, mOCISpec, mImageHandler, mDatabase, mBlobDecryptor); |
| #include <core/common/monitoring/monitoring.hpp> | ||
| #include <core/common/spaceallocator/spaceallocator.hpp> | ||
| #include <core/common/tools/heapallocator.hpp> | ||
| #include <core/sm/imagemanager/blobdecryptor.hpp> |
| err = mCryptoHelper.Init( | ||
| mAllocator, mIAMClient, mCryptoProvider, mCertLoader, "", mConfig.mIAMClientConfig.mCACert.c_str()); | ||
| AOS_ERROR_CHECK_AND_THROW(err, "can't initialize crypto helper"); |


No description provided.