Dstack-TEE / Dstack-TEE/dstack

Adopt RFC 8785 (JCS) for canonical compose hash calculation

Open
#411 1 comment 0 reactions 0 assignees View on GitHub
security security: roadmap
Dominant language
Rust
Stars
544
Forks
96
Avg merge
17h 57m
Merged PRs (30d)
117

Description

## Problem

Right now, the same appcompose can hash differently depending on how the JSON is formatted - whitespace, key order, indentation, you name it. This makes verification a pain for devs trying to prove their docker-compose is actually running in a TEE.

## Proposal

Use [RFC 8785 - JSON Canonicalization Scheme](https://www.rfc-editor.org/rfc/rfc8785) for compose hash calculation.

## Rollout

**Phase 1 - SDK & Docs**
- Add JCS hash calculation to the SDK
- Update docs explaining how it works and how the compose hash is built from each component
- No breaking changes yet

**Phase 2 - Migration**
- Make JCS the default in SDK
- Provide tooling to verify/convert existing files

**Phase 3 - Enforcement**
- Require JCS-canonical hashes in a future release
- Reject non-canonical submissions

## Separate hashes for docker_compose & prelaunch_script

These two should have their own hashes, not just be buried in the final compose hash. Makes debugging way easier - you can tell exactly which part changed when hashes don't match. Plus they're raw strings (YAML/bash), so they don't go through JCS anyway. Keeping them separate gives better traceability.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.