Repository navigation
Conversation
midego1
force-pushed
the
fix/passport-content-addressed-documents
branch
from
September 4, 2026 07:30
9c83883 to
193a5f5
Compare
…eals a new version
Documents were copied to `publication/{uuid}/{locale}/{field}.{ext}` and
the copy was skipped when that path already existed. Replacing a file
in the catalog therefore changed nothing the publisher could see: the
path was unchanged, so the checksum was unchanged, so no version was
minted, and the new bytes were never written either. The passport kept
serving the previous document with no signal that it had been replaced.
For a declaration of conformity that is a silent compliance failure.
Put the first 16 hex chars of the file's SHA-256 into the path
(`publication/{uuid}/{locale}/{digest}/{field}.{ext}`) and stamp the
full digest into the document entry. A re-issued file lands beside the
old one, the payload changes, and Publisher seals a new version; every
existing version keeps resolving to the exact bytes it attested. The
basename is unchanged, so download filenames are too.
Upgrade note: the first republish of a product with documents after
this change mints one new version per locale, because the path shape
changed. That version is the first whose documents are genuinely
attested, so this is intended.
Tests: builder yields a new path and digest for new bytes while keeping
the old object; the same path for unchanged bytes; and end to end, a
re-issued file mints version n+1 while an unchanged one mints nothing.
midego1
force-pushed
the
fix/passport-content-addressed-documents
branch
from
September 4, 2026 07:31
193a5f5 to
734eebc
Compare
This was referenced Sep 4, 2026
Open
Contributor
Author
|
Context, motivation and suggested review order for this and the related PRs: #683 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
PassportPayloadBuilder::copyToAssetDisk()copies a referenced document topublication/{uuid}/{locale}/{field}.{ext}and skips the copy when that path already exists.Replacing a file in the catalog therefore changes nothing the publisher can see:
Publisher::publish()returnsnulland no version is minted,The passport keeps serving the previous document with no signal that it was replaced. For a re-issued declaration of conformity that is a silent compliance failure, and it also means a sealed version cannot actually guarantee which bytes it attested, since a later publish would have overwritten them at the same path if the guard were removed.
Fix
Content-address the copy. The first 16 hex characters of the file's SHA-256 go into the path:
and the full digest is stamped into the document entry as
sha256.Publisherseals a new version.exists()guard is now correct rather than a bug: an object at that path holds those bytes by construction.The public template and asset controller only read
pathandlabel, so the extrasha256key is inert for them.previewmode is untouched.Upgrade note
The first republish of a product with documents after this change mints one new version per locale, because the path shape changed. That version is the first whose documents are genuinely attested, so this is intended and a one-time effect.
Tests
PassportDocumentReissueTest): re-issuing the source file mints version n+1 pointing at the new bytes while the old version's bytes remain; an unchanged file mints nothing. The second case also pins themeta-excluded checksum behaviour.Related
Companion to #677, which stops pruning the document index of superseded versions. Together they make a sealed version's documents both retained and trustworthy.