Skip to content

WIP: make additional decryption work - #306

Open
mlohvynenko wants to merge 1 commit into
aosedge:developfrom
mlohvynenko:feature_decrypt_layer
Open

mlohvynenko wants to merge 1 commit into
aosedge:developfrom
mlohvynenko:feature_decrypt_layer

Conversation

@mlohvynenko

Copy link
Copy Markdown
Member

No description provided.

Copilot AI lite review requested due to automatic review settings September 20, 2026 15:44

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Resolve the unregistered diskencryption module dependency and correct crypto member destruction ordering.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 Medium severity

Open (1)
What changed in this PR

Adds local encrypted-layer decryption support to the Service Manager and integrates it with image management.

Changes:

  • Adds crypto helper, local key provider, and blob decryptor.
  • Initializes decryption components and injects the decryptor into ImageManager.
  • Updates the certificate-loader test stub.
File Description
src/​sm/​app/​aoscore.hpp Declares decryption dependencies and configuration.
src/​sm/​app/​aoscore.cpp Initializes decryption services and integrates them with image management.
src/​cm/​smcontroller/​tests/​stubs/​certloaderstub.hpp Implements the expanded certificate-loader interface.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/sm/app/aoscore.cpp Outdated
// installed, so a node with no key provisioned starts up fine and only fails if it's asked to install
// an encrypted layer.

err = mLocalDataKeyProvider.Init(mAllocator, mIAMClient, mCertLoader, cLayerEncryptionCertType);
Copilot AI review requested due to automatic review settings September 23, 2026 15:34

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Encrypted gzip size handling and regression coverage remain unresolved.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 2 Medium severity

Open (2)

constexpr auto cSupportedMediaTypes = std::array {
oci::cMediaTypeLayerTar,
oci::cMediaTypeLayerTarGZip,
oci::cMediaTypeLayerTarGZipEncrypted,
Copilot AI review requested due to automatic review settings September 25, 2026 14:54

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Encrypted gzip size handling is incomplete, and the required core-library API is unavailable at the configured revision.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 High severity · 2 Medium severity

Open (3)

constexpr auto cSupportedMediaTypes = std::array {
oci::cMediaTypeLayerTar,
oci::cMediaTypeLayerTarGZip,
oci::cMediaTypeLayerTarGZipEncrypted,
Signed-off-by: Mykhailo Lohvynenko <mykhailo_lohvynenko@epam.com>
Copilot AI review requested due to automatic review settings September 25, 2026 15:46

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Critical external API mismatches prevent compilation, and encrypted gzip handling and helper wiring remain incomplete.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 3 High severity · 3 Medium severity

Open (6)

Comment thread src/sm/app/aoscore.cpp

err = mImageManager.Init(mAllocator, mConfig.mImageManager, mSMClient, mImagesSpaceAllocator, mDownloader,
mFileInfoProvider, mOCISpec, mImageHandler, mDatabase);
mFileInfoProvider, mOCISpec, mImageHandler, mDatabase, mBlobDecryptor);
Comment thread src/sm/app/aoscore.hpp
#include <core/common/monitoring/monitoring.hpp>
#include <core/common/spaceallocator/spaceallocator.hpp>
#include <core/common/tools/heapallocator.hpp>
#include <core/sm/imagemanager/blobdecryptor.hpp>
Comment thread src/sm/app/aoscore.cpp
Comment on lines +51 to +53
err = mCryptoHelper.Init(
mAllocator, mIAMClient, mCryptoProvider, mCertLoader, "", mConfig.mIAMClientConfig.mCACert.c_str());
AOS_ERROR_CHECK_AND_THROW(err, "can't initialize crypto helper");
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants