From 68460dedb51d00efcf7d7981f0f52cf91d21cc0b Mon Sep 17 00:00:00 2001 From: Bugs5382 Date: Thu, 1 Oct 2026 16:27:43 -0400 Subject: [PATCH] refactor!: rename to cryptos-node and own the node API protos The repository is now CryptOS-PKI/cryptos-node and the module path is github.com/CryptOS-PKI/cryptos-node. The node API protos move in from the api repo to proto/cryptos/node/v1, with the proto package renamed from cryptos.v1 to cryptos.node.v1 and the Go stubs generated under gen/go/cryptos/node/v1 (package nodev1) by the pinned plugins (task tools, task generate). The messages, fields and RPCs are unchanged; only the package, and with it the gRPC method paths (/cryptos.node.v1.NodeService/), change. task ci now lints the protos and fails when gen/ is stale, and CI installs a checksum-pinned buf. The api repo's contract tests move to internal/apiconformance next to a new round-trip test that dials the mTLS server with the generated client and checks every NodeService RPC reaches its handler. BREAKING CHANGE: the Go module path, the stub import path and the proto package all change. Clients must call /cryptos.node.v1.NodeService/... Signed-off-by: Bugs5382 --- .github/workflows/ci-go.yml | 19 +- .gitignore | 3 + AGENTS.md | 4 +- CLAUDE.md | 4 +- README.md | 18 +- Taskfile.yml | 77 +- buf.gen.yaml | 16 + buf.yaml | 9 + build/ci/buildinfo.sh | 2 +- build/squashfs/build.sh | 4 +- cmd/cryptos-console/loop.go | 2 +- cmd/cryptos-console/loop_test.go | 2 +- cmd/cryptos-console/main.go | 2 +- cmd/cryptos-console/reset_test.go | 2 +- cmd/cryptos-install/main.go | 2 +- cmd/cryptos-sbkey/main.go | 2 +- cmd/cryptos-switchroot/main.go | 2 +- cmd/cryptosctl/audit.go | 18 +- cmd/cryptosctl/audit_test.go | 16 +- cmd/cryptosctl/ceremony.go | 20 +- cmd/cryptosctl/cli_test.go | 82 +- cmd/cryptosctl/client.go | 6 +- cmd/cryptosctl/config.go | 8 +- cmd/cryptosctl/config_test.go | 6 +- cmd/cryptosctl/configget_test.go | 2 +- cmd/cryptosctl/escrow.go | 6 +- cmd/cryptosctl/get_issued_test.go | 18 +- cmd/cryptosctl/identity.go | 10 +- cmd/cryptosctl/image.go | 22 +- cmd/cryptosctl/image_test.go | 20 +- cmd/cryptosctl/issue_leaf_test.go | 6 +- cmd/cryptosctl/protocols_test.go | 22 +- cmd/cryptosctl/reboot.go | 4 +- cmd/cryptosctl/reboot_test.go | 6 +- cmd/cryptosctl/recertify.go | 6 +- cmd/cryptosctl/recertify_test.go | 10 +- cmd/cryptosctl/reset.go | 6 +- cmd/cryptosctl/reset_test.go | 6 +- cmd/cryptosctl/revocation.go | 22 +- cmd/cryptosctl/rotate.go | 6 +- cmd/cryptosctl/roundtrip_test.go | 18 +- cmd/cryptosctl/scep.go | 18 +- cmd/cryptosctl/scep_test.go | 36 +- cmd/cryptosctl/signcsr_debug.go | 4 +- cmd/cryptosctl/status.go | 16 +- cmd/cryptosctl/subordinate.go | 12 +- cmd/cryptosctl/subordinate_test.go | 4 +- cmd/cryptosctl/trust.go | 2 +- cmd/cryptosctl/trust_test.go | 2 +- cmd/cryptosctl/validity_warning_test.go | 10 +- cmd/cryptosctl/version.go | 6 +- cmd/cryptosctl/version_test.go | 2 +- cmd/init/main.go | 2 +- cmd/init/reboot_linux.go | 2 +- cmd/init/reboot_linux_test.go | 2 +- cmd/init/reboot_other.go | 2 +- docs/audit-log.md | 2 +- docs/image-upgrade.md | 2 +- gen/go/cryptos/node/v1/audit.pb.go | 778 +++ gen/go/cryptos/node/v1/ceremony.pb.go | 1107 ++++ gen/go/cryptos/node/v1/config.pb.go | 3840 ++++++++++++ gen/go/cryptos/node/v1/identity.pb.go | 173 + gen/go/cryptos/node/v1/node.pb.go | 5123 +++++++++++++++++ gen/go/cryptos/node/v1/node_grpc.pb.go | 1890 ++++++ gen/go/cryptos/node/v1/scep.pb.go | 1227 ++++ gen/go/cryptos/node/v1/status.pb.go | 1459 +++++ gen/go/cryptos/node/v1/tsa.pb.go | 338 ++ go.mod | 3 +- go.sum | 2 - internal/acme/server_test.go | 2 +- internal/acme/store.go | 2 +- internal/acme/store_test.go | 2 +- .../apiconformance/audit_contract_test.go | 99 + internal/apiconformance/node_contract_test.go | 80 + .../apiconformance/protocol_contract_test.go | 158 + internal/apiconformance/roundtrip_test.go | 504 ++ internal/apiconformance/scep_contract_test.go | 203 + internal/apiconformance/tsa_contract_test.go | 122 + .../windows_enrollment_contract_test.go | 96 + internal/audit/audit.go | 8 +- internal/audit/audit_test.go | 14 +- internal/audit/describe.go | 8 +- internal/audit/describe_test.go | 36 +- internal/audit/doc.go | 2 +- internal/audit/read.go | 12 +- internal/audit/read_test.go | 52 +- internal/ca/ca_test.go | 2 +- internal/ca/doc.go | 6 +- internal/ceremony/ceremony.go | 62 +- internal/ceremony/ceremony_test.go | 76 +- internal/ceremony/rsa_tpm_test.go | 10 +- internal/ceremony/subject_rdn_test.go | 2 +- internal/config/config.go | 68 +- internal/config/config_test.go | 12 +- internal/config/protocols.go | 26 +- internal/config/protocols_disabled_test.go | 8 +- internal/config/protocols_test.go | 14 +- internal/config/reboot_test.go | 4 +- internal/config/scep.go | 16 +- internal/config/scep_test.go | 6 +- internal/console/client.go | 14 +- internal/console/client_test.go | 20 +- internal/console/confirm_test.go | 2 +- internal/console/console_test.go | 2 +- internal/console/dashboard_test.go | 2 +- internal/console/mgmtcert_test.go | 2 +- internal/console/status.go | 56 +- internal/console/status_test.go | 66 +- internal/console/uptime_linux_test.go | 2 +- internal/e2e/hierarchy_e2e_test.go | 22 +- internal/e2e/kind_acme_e2e_test.go | 12 +- internal/e2e/recertify_e2e_test.go | 38 +- internal/e2e/rsa_chain_e2e_test.go | 6 +- internal/e2e/rsa_revocation_e2e_test.go | 8 +- internal/e2e/tpm_rsa_e2e_test.go | 32 +- internal/est/pkcs7.go | 2 +- internal/grpc/apply_status_test.go | 6 +- internal/grpc/attest.go | 8 +- internal/grpc/attest_test.go | 16 +- internal/grpc/audit.go | 26 +- internal/grpc/audit_test.go | 136 +- internal/grpc/authz.go | 2 +- internal/grpc/authz_test.go | 2 +- internal/grpc/escrow_passphrase_test.go | 12 +- internal/grpc/getconfig.go | 8 +- internal/grpc/getconfig_test.go | 8 +- internal/grpc/imageupgrade.go | 36 +- internal/grpc/imageupgrade_test.go | 74 +- internal/grpc/local_test.go | 14 +- internal/grpc/noconfig_test.go | 10 +- internal/grpc/reboot.go | 12 +- internal/grpc/reboot_test.go | 16 +- internal/grpc/remotereset_test.go | 18 +- internal/grpc/renew_test.go | 24 +- internal/grpc/scep.go | 38 +- internal/grpc/scep_test.go | 52 +- internal/grpc/server.go | 192 +- internal/grpc/server_test.go | 314 +- internal/grpc/setmanagement.go | 8 +- internal/grpc/setmanagement_test.go | 36 +- internal/grpc/signcsr_debug.go | 6 +- internal/grpc/signcsr_stub.go | 4 +- internal/grpc/unserved.go | 6 +- internal/grpc/unserved_test.go | 6 +- internal/init/acme.go | 6 +- internal/init/attest.go | 4 +- internal/init/attest_test.go | 6 +- internal/init/boot.go | 2 +- internal/init/boot_test.go | 2 +- internal/init/configload.go | 2 +- internal/init/configload_test.go | 2 +- internal/init/escrow.go | 14 +- internal/init/escrow_test.go | 8 +- internal/init/est.go | 10 +- internal/init/est_test.go | 4 +- internal/init/imageupgrade.go | 18 +- internal/init/imageupgrade_test.go | 10 +- internal/init/install_protocols_test.go | 20 +- internal/init/kms_protector.go | 4 +- internal/init/kms_protector_test.go | 4 +- internal/init/maintenance.go | 14 +- internal/init/maintenance_installer.go | 10 +- internal/init/maintenance_installer_test.go | 24 +- internal/init/maintenance_status.go | 8 +- internal/init/maintenance_test.go | 2 +- internal/init/mgmtcert.go | 6 +- internal/init/mgmtcert_test.go | 4 +- internal/init/nodekey.go | 4 +- internal/init/nodekey_test.go | 4 +- internal/init/ocsp_responder.go | 4 +- internal/init/ocsp_responder_test.go | 6 +- internal/init/rekey.go | 16 +- internal/init/rekey_test.go | 12 +- internal/init/renew.go | 14 +- internal/init/renew_live_test.go | 12 +- internal/init/renew_test.go | 8 +- internal/init/reprovision.go | 8 +- internal/init/reprovision_test.go | 6 +- internal/init/reset_test.go | 2 +- internal/init/resolv.go | 24 +- internal/init/resolv_test.go | 14 +- internal/init/revocation.go | 28 +- internal/init/revocation_test.go | 4 +- internal/init/rootbackend.go | 4 +- internal/init/run.go | 72 +- internal/init/scep.go | 10 +- internal/init/scep_test.go | 4 +- internal/init/seed_test.go | 4 +- internal/init/servertls.go | 4 +- internal/init/servertls_test.go | 4 +- internal/init/shutdown.go | 2 +- internal/init/shutdown_test.go | 2 +- internal/init/softroot.go | 4 +- internal/init/softroot_test.go | 2 +- internal/init/statekey.go | 2 +- internal/init/statekeymode_test.go | 8 +- internal/init/statekeyreseal.go | 8 +- internal/init/statekeyreseal_test.go | 4 +- internal/init/stateunlock.go | 12 +- internal/init/stateunlock_test.go | 20 +- internal/init/statevolume.go | 2 +- internal/init/statevolume_test.go | 2 +- internal/init/status.go | 16 +- internal/init/status_test.go | 14 +- internal/init/subordinate.go | 8 +- internal/init/subordinate_subject_test.go | 2 +- internal/init/timesync.go | 18 +- internal/init/timesync_test.go | 30 +- internal/init/tpm_rsa_test.go | 10 +- internal/node/apply_statekey_test.go | 8 +- internal/node/apply_validate_test.go | 14 +- internal/node/apply_warnings_test.go | 2 +- internal/node/disks.go | 8 +- internal/node/enroller.go | 10 +- internal/node/enroller_test.go | 4 +- internal/node/node_test.go | 64 +- internal/node/protocols_disabled_test.go | 10 +- internal/node/protocols_test.go | 44 +- internal/node/providers.go | 60 +- internal/node/renew_test.go | 4 +- internal/node/scep_apply_test.go | 18 +- internal/node/signer.go | 4 +- internal/node/signer_ad_test.go | 4 +- internal/node/signer_clockgate_test.go | 2 +- internal/node/signer_keyfloor_test.go | 2 +- internal/node/signer_names_test.go | 2 +- internal/node/signer_request_sans_test.go | 2 +- internal/node/signer_test.go | 4 +- internal/node/signer_validity_test.go | 2 +- internal/node/store.go | 22 +- internal/node/store_test.go | 4 +- internal/node/vmca_subordination_test.go | 4 +- internal/release/release.go | 2 +- internal/reset/reset_test.go | 2 +- internal/revocation/crl_test.go | 2 +- internal/revocation/ocsp_test.go | 2 +- internal/revocation/store.go | 2 +- internal/revocation/store_test.go | 2 +- internal/scep/admin.go | 34 +- internal/scep/admin_test.go | 38 +- internal/scep/fixture_test.go | 18 +- internal/scep/http.go | 2 +- internal/scep/message.go | 2 +- internal/scep/server.go | 14 +- internal/scep/server_test.go | 30 +- internal/scep/sscep_test.go | 6 +- internal/scep/store.go | 2 +- internal/storage/luks/token_test.go | 2 +- internal/timesync/engine.go | 28 +- internal/timesync/engine_test.go | 32 +- proto/cryptos/node/v1/audit.proto | 122 + proto/cryptos/node/v1/ceremony.proto | 129 + proto/cryptos/node/v1/config.proto | 777 +++ proto/cryptos/node/v1/identity.proto | 34 + proto/cryptos/node/v1/node.proto | 707 +++ proto/cryptos/node/v1/scep.proto | 141 + proto/cryptos/node/v1/status.proto | 234 + proto/cryptos/node/v1/tsa.proto | 49 + test/image/build.sh | 2 +- test/image/coverage.sh | 2 +- test/image/run.sh | 2 +- test/integration/integration_test.go | 4 +- 262 files changed, 21258 insertions(+), 1749 deletions(-) create mode 100644 buf.gen.yaml create mode 100644 buf.yaml create mode 100644 gen/go/cryptos/node/v1/audit.pb.go create mode 100644 gen/go/cryptos/node/v1/ceremony.pb.go create mode 100644 gen/go/cryptos/node/v1/config.pb.go create mode 100644 gen/go/cryptos/node/v1/identity.pb.go create mode 100644 gen/go/cryptos/node/v1/node.pb.go create mode 100644 gen/go/cryptos/node/v1/node_grpc.pb.go create mode 100644 gen/go/cryptos/node/v1/scep.pb.go create mode 100644 gen/go/cryptos/node/v1/status.pb.go create mode 100644 gen/go/cryptos/node/v1/tsa.pb.go create mode 100644 internal/apiconformance/audit_contract_test.go create mode 100644 internal/apiconformance/node_contract_test.go create mode 100644 internal/apiconformance/protocol_contract_test.go create mode 100644 internal/apiconformance/roundtrip_test.go create mode 100644 internal/apiconformance/scep_contract_test.go create mode 100644 internal/apiconformance/tsa_contract_test.go create mode 100644 internal/apiconformance/windows_enrollment_contract_test.go create mode 100644 proto/cryptos/node/v1/audit.proto create mode 100644 proto/cryptos/node/v1/ceremony.proto create mode 100644 proto/cryptos/node/v1/config.proto create mode 100644 proto/cryptos/node/v1/identity.proto create mode 100644 proto/cryptos/node/v1/node.proto create mode 100644 proto/cryptos/node/v1/scep.proto create mode 100644 proto/cryptos/node/v1/status.proto create mode 100644 proto/cryptos/node/v1/tsa.proto diff --git a/.github/workflows/ci-go.yml b/.github/workflows/ci-go.yml index ef170c3..595af91 100644 --- a/.github/workflows/ci-go.yml +++ b/.github/workflows/ci-go.yml @@ -1,7 +1,7 @@ name: Go CI (format, lint, vet, test, build) # Go validation on a GitHub-hosted Linux runner. Mirrors `task ci` -# (fmt + lint + vet + test + build). Runs on PRs and pushes to main. +# (fmt + proto lint + generated-code check + lint + vet + test + build). Runs on PRs and pushes to main. # Skip when a change touches only non-Go files (Markdown, docs, the image # build scripts, or issue templates). A mixed change still runs, since @@ -57,6 +57,23 @@ jobs: # built with an older Go panics on newer language/std usage. run: go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@v2.12.2 + - name: Install buf + # task ci lints the node API protos and regenerates gen/go to check it + # is current. The release binary is checked against the SHA-256 its + # release publishes (sha256.txt); bump both together. + env: + BUF_VERSION: 1.73.0 + BUF_SHA256: 8f2986298ad08f0cc1bf999b9797b7c383adf32d7edf0f73d6f1e1a701baeac1 + run: | + set -euo pipefail + bin="$RUNNER_TEMP/bin" + mkdir -p "$bin" + curl -sSfL -o "$bin/buf" \ + "https://github.com/bufbuild/buf/releases/download/v${BUF_VERSION}/buf-Linux-x86_64" + echo "${BUF_SHA256} $bin/buf" | sha256sum -c - + chmod +x "$bin/buf" + echo "$bin" >> "$GITHUB_PATH" + - name: Install swtpm # The TPM-held RSA CA end-to-end test needs a TPM that implements # RSA-3072. The in-process simulator stops at RSA-2048, and the test diff --git a/.gitignore b/.gitignore index d98c9ea..a9c23ff 100644 --- a/.gitignore +++ b/.gitignore @@ -42,3 +42,6 @@ build/out/ # Local design notes (non-tracked). plan/ + +# Pinned protoc plugins (task tools) +.bin/ diff --git a/AGENTS.md b/AGENTS.md index 234df98..c5a050c 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -1,4 +1,4 @@ -# AGENTS.md - cryptos +# AGENTS.md - cryptos-node Guide for AI agents working in this repository. Pair with `CLAUDE.md` (the working agreement and hook-enforced rules). Keep this file current when the build, layout, or public API changes. @@ -10,7 +10,7 @@ Immutable, API-driven, high-assurance PKI operating system. Talos-style: no SSH, -## Using cryptos +## Using cryptos-node