From 28e387868f79fdb1ec177f6a952b42c32709bc72 Mon Sep 17 00:00:00 2001 From: Gabriel Brown Date: Thu, 27 Aug 2026 11:09:50 -0400 Subject: [PATCH] Docs: Record signed Terra bootstrap proof --- setup/provenance/README.md | 66 ++++++++++++++++++++++++++++++++++++++ 1 file changed, 66 insertions(+) diff --git a/setup/provenance/README.md b/setup/provenance/README.md index 866b025..a94e73e 100644 --- a/setup/provenance/README.md +++ b/setup/provenance/README.md @@ -102,3 +102,69 @@ confirm its complete primary fingerprint, update the vendored key and `installers.conf` together, refresh this retrieval record, and add a focused contract case if the verification behavior changes. Until that review lands, verification fails closed and preserves any known-good destination. + +## Container-only Terra 44 signed-bootstrap proof + +On 2026-08-27, a single disposable rootless Podman container proved the Terra +bootstrap path without changing the host package database, host keyring, or +host repository files. Podman reported `rootless=true`, `runtime=crun`, and a +user graph root. The fresh image was +`registry.fedoraproject.org/fedora@sha256:62f199d1eb34170a7bb2277485676d89c0e91aae4086151c4043062cce51c77c` +(`sha256:87d8a4a90c0457689db68624cac1026fb2201cbdc1e99cc5455a8f8876118498`). +The container (`5fc8fa42bb85afb3b57b336ca29b58a32fad50d460583329a4e910cc29fb4d2d`) +had no mounts and was removed automatically after `podman stop`. + +Before copying the only host file admitted to the container, +`keys/terra44.asc`, this exact host check reported the complete primary +fingerprint `AE09157A4DE88B497EA1D5D300CDAB43DE226D6F`: + +```bash +gpg --batch --with-colons --import-options show-only --import setup/provenance/keys/terra44.asc \ + | awk -F: '$1 == "fpr" { print $10; exit }' +``` + +Its SHA-256 was +`3febbaadfa43509c22edc440d58c970705e502cdd0f347a75d5005562fd6b3d8`. +The container commands were: + +```bash +podman create --name panama-terra-proof-20260827 --rm --pull=always \ + registry.fedoraproject.org/fedora:44 sleep infinity +podman cp setup/provenance/keys/terra44.asc \ + panama-terra-proof-20260827:/tmp/terra44.asc +podman start panama-terra-proof-20260827 +podman exec panama-terra-proof-20260827 /bin/bash -lc ' + sha256sum /tmp/terra44.asc + install -Dm0644 /tmp/terra44.asc /etc/pki/rpm-gpg/RPM-GPG-KEY-terra44-panama + dnf install -y --repofrompath terra,https://repos.fyralabs.com/terra44 \ + --setopt=terra.pkg_gpgcheck=1 \ + --setopt=terra.repo_gpgcheck=1 \ + --setopt=terra.gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-terra44-panama \ + terra-release +' +``` + +Inside the container the copied and installed key both had the recorded +SHA-256 before and after installation. `terra-release-44-9.noarch` was +installed. Its effective `terra` configuration reported `gpgcheck = 1`, +`pkg_gpgcheck = 1`, and `repo_gpgcheck = 1`; no GPG-bypass option was used. +The package's own `/etc/yum.repos.d/terra.repo` uses its Terra metalink and +`RPM-GPG-KEY-terra44`. That differs from Panama's deliberately staged local +key/base-URL file in `install-packages`, which replaces the release-generated +file only after this verified bootstrap step. + +Although the command runner returned after 30 seconds while DNF was still +loading metadata, Podman's retained event log records the exact command's +completion. This read-only recovery command was run after container removal: + +```bash +podman events --since '2026-08-27T10:55:00-04:00' --until '2026-08-27T11:02:00-04:00' \ + --filter container=5fc8fa42bb85afb3b57b336ca29b58a32fad50d460583329a4e910cc29fb4d2d \ + --format json +``` + +The first `exec` event, at `timeNano=1787842633591543881`, is the documented +key-install and DNF command. Its matching first `exec_died` event, at +`timeNano=1787842671276003275`, records `ContainerExitCode:0`. The +same-container post-check independently confirmed the installed package and +effective signature settings above; no retry or second container was used.