mirror of
https://github.com/apple/container.git
synced 2026-09-22 23:55:34 +00:00
Verify kernel archive integrity (#1703)
Closes https://github.com/apple/container/issues/1687 The default kernel archive is downloaded from a remote release URL during first-run setup and via `container system kernel set --recommended`. Previously, the archive contents were not verified after download, so integrity depended on HTTPS and the release artifact remaining unchanged. This change adds digest verification for kernel archives. The recommended/default kernel now has pinned digest metadata using an algorithm-prefixed value such as `sha256:<hex>`. `container system kernel set --tar` accepts `--digest`; remote tar URLs require it, and local tar archives can also be verified before unpacking and installation. The system config also supports `kernel.digest`, and a custom `kernel.url` must provide a digest for that archive.
This commit is contained in:
@@ -77,6 +77,7 @@ domain = "test"
|
||||
[kernel]
|
||||
binaryPath = "opt/kata/share/kata-containers/vmlinux-6.18.15-186"
|
||||
url = "https://github.com/kata-containers/kata-containers/releases/download/3.28.0/kata-static-3.28.0-arm64.tar.zst"
|
||||
digest = "sha256:f63d54507d1f18635d94475077e4c2330de4d8e05cedf25f7c38f063b0e66a91"
|
||||
|
||||
[network]
|
||||
|
||||
|
||||
Reference in New Issue
Block a user