From e1465382b09880bee32bd5216fb99981c98c5c3c Mon Sep 17 00:00:00 2001 From: Rafael Winterhalter Date: Sat, 15 Aug 2026 09:46:06 +0200 Subject: [PATCH 1/3] Add Automatic-Module-Name to sigstore-java Declare a stable JPMS automatic module name so consumers building modular applications get a predictable module name instead of one derived from the jar file name. The name matches the jar's root package, dev.sigstore. Only sigstore-java is given a name. The CLIs are shipped as shadowed uber jars, and the Gradle and Maven plugins are loaded by their build tool's own classloader, so none of them are ever resolved on a module path. --- sigstore-java/build.gradle.kts | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/sigstore-java/build.gradle.kts b/sigstore-java/build.gradle.kts index b54461ee..bf617dff 100644 --- a/sigstore-java/build.gradle.kts +++ b/sigstore-java/build.gradle.kts @@ -10,6 +10,13 @@ plugins { description = "A Java client for signing and verifying using Sigstore" +tasks.jar { + manifest { + // Name of the automatic module for JPMS consumers. It must never change once released. + attributes["Automatic-Module-Name"] = "dev.sigstore" + } +} + dependencies { compileOnly("org.immutables:gson:2.12.2") compileOnly("org.immutables:value-annotations:2.12.2") From 3264cbed62626b33a0e5d99b5cfcbd1302d1005a Mon Sep 17 00:00:00 2001 From: Rafael Winterhalter Date: Sat, 15 Aug 2026 15:46:38 +0200 Subject: [PATCH 2/3] Consume google/api protos from proto-google-common-protos sigstore-java compiled its own copies of google/api/{annotations,field_behavior, http}.proto from src/main/proto, emitting com.google.api classes into the jar. Those classes are byte-for-byte duplicates of ones in proto-google-common-protos, which is already on sigstore-java's runtime classpath via grpc-protobuf, so the copies never provided isolation: the fully-qualified names are identical and which one wins is a matter of classpath ordering. On the module path it is a hard failure rather than a silent one: java.lang.module.ResolutionException: Module proto.google.common.protos contains package com.google.api, module dev.sigstore exports package com.google.api to proto.google.common.protos Drop the vendored copies and let protoc resolve those imports from the include path, which proto-google-common-protos already populates. The dependency is now declared explicitly because BundleVerifier and the generated code link against com.google.api directly; it was previously only an undeclared transitive. The README justifying the copies said proto-google-common-protos had gone stale. That is no longer so: it is at 2.74.0, released two weeks ago, and its copies of the three protos are identical to the vendored ones apart from a C++-only cc_enable_arenas option that does not affect Java codegen. Resolves to 2.74.0, above the 2.64.1 grpc-protobuf requests. Its protobuf-java 4.33.6 stays below the BOM-pinned 4.35.1, so the BOM continues to win. --- sigstore-java/build.gradle.kts | 8 +- .../src/main/proto/google/api/README.md | 10 - .../main/proto/google/api/annotations.proto | 31 -- .../proto/google/api/field_behavior.proto | 104 ----- .../src/main/proto/google/api/http.proto | 379 ------------------ 5 files changed, 7 insertions(+), 525 deletions(-) delete mode 100644 sigstore-java/src/main/proto/google/api/README.md delete mode 100644 sigstore-java/src/main/proto/google/api/annotations.proto delete mode 100644 sigstore-java/src/main/proto/google/api/field_behavior.proto delete mode 100644 sigstore-java/src/main/proto/google/api/http.proto diff --git a/sigstore-java/build.gradle.kts b/sigstore-java/build.gradle.kts index bf617dff..f01feae7 100644 --- a/sigstore-java/build.gradle.kts +++ b/sigstore-java/build.gradle.kts @@ -28,9 +28,15 @@ dependencies { implementation("io.github.erdtman:java-json-canonicalization:1.1") - // this requires inclusion of protos is src/main/proto + // the protos in this artifact are compiled into sigstore-java, alongside src/main/proto protobuf("dev.sigstore:protobuf-specs:0.5.0") + // Supplies the google/api protos imported by fulcio.proto and protobuf-specs, both as + // sources on the protoc include path and as the com.google.api classes that generated + // code and BundleVerifier link against. These were previously compiled from copies in + // src/main/proto, which duplicated classes this artifact already provides. + implementation("com.google.api.grpc:proto-google-common-protos:2.74.0") + implementation(platform("com.google.protobuf:protobuf-bom:4.35.1")) implementation("com.google.protobuf:protobuf-java-util") diff --git a/sigstore-java/src/main/proto/google/api/README.md b/sigstore-java/src/main/proto/google/api/README.md deleted file mode 100644 index 4835c306..00000000 --- a/sigstore-java/src/main/proto/google/api/README.md +++ /dev/null @@ -1,10 +0,0 @@ -These files are copied from https://github.com/googleapis/googleapis/ because the pre-compiled -version of these available from https://github.com/googleapis/api-common-protos as -`com.google.api.grpc:proto-google-common-protos` has gone out of date and I can't tell if there's -an intention on keeping up to date. We require `field_behavior.proto` for -`dev.sigstore:protobuf-specs` and {`annotations.proto`, `field_behavior.proto`, `http.proto`} -for `fulcio.proto`. This change is current required to keep our dependencies up to date. Newer -protobuf tools don't work with the very old `proto-google-common-protos` dependency. - -The main issue with including these protos here are that a consumer of `sigstore-java` importing -the same protos from another library might experience some sort of dependency clashing. diff --git a/sigstore-java/src/main/proto/google/api/annotations.proto b/sigstore-java/src/main/proto/google/api/annotations.proto deleted file mode 100644 index 84c48164..00000000 --- a/sigstore-java/src/main/proto/google/api/annotations.proto +++ /dev/null @@ -1,31 +0,0 @@ -// Copyright 2024 Google LLC -// -// Licensed under the Apache License, Version 2.0 (the "License"); -// you may not use this file except in compliance with the License. -// You may obtain a copy of the License at -// -// http://www.apache.org/licenses/LICENSE-2.0 -// -// Unless required by applicable law or agreed to in writing, software -// distributed under the License is distributed on an "AS IS" BASIS, -// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -// See the License for the specific language governing permissions and -// limitations under the License. - -syntax = "proto3"; - -package google.api; - -import "google/api/http.proto"; -import "google/protobuf/descriptor.proto"; - -option go_package = "google.golang.org/genproto/googleapis/api/annotations;annotations"; -option java_multiple_files = true; -option java_outer_classname = "AnnotationsProto"; -option java_package = "com.google.api"; -option objc_class_prefix = "GAPI"; - -extend google.protobuf.MethodOptions { - // See `HttpRule`. - HttpRule http = 72295728; -} diff --git a/sigstore-java/src/main/proto/google/api/field_behavior.proto b/sigstore-java/src/main/proto/google/api/field_behavior.proto deleted file mode 100644 index 2b73d36e..00000000 --- a/sigstore-java/src/main/proto/google/api/field_behavior.proto +++ /dev/null @@ -1,104 +0,0 @@ -// Copyright 2024 Google LLC -// -// Licensed under the Apache License, Version 2.0 (the "License"); -// you may not use this file except in compliance with the License. -// You may obtain a copy of the License at -// -// http://www.apache.org/licenses/LICENSE-2.0 -// -// Unless required by applicable law or agreed to in writing, software -// distributed under the License is distributed on an "AS IS" BASIS, -// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -// See the License for the specific language governing permissions and -// limitations under the License. - -syntax = "proto3"; - -package google.api; - -import "google/protobuf/descriptor.proto"; - -option go_package = "google.golang.org/genproto/googleapis/api/annotations;annotations"; -option java_multiple_files = true; -option java_outer_classname = "FieldBehaviorProto"; -option java_package = "com.google.api"; -option objc_class_prefix = "GAPI"; - -extend google.protobuf.FieldOptions { - // A designation of a specific field behavior (required, output only, etc.) - // in protobuf messages. - // - // Examples: - // - // string name = 1 [(google.api.field_behavior) = REQUIRED]; - // State state = 1 [(google.api.field_behavior) = OUTPUT_ONLY]; - // google.protobuf.Duration ttl = 1 - // [(google.api.field_behavior) = INPUT_ONLY]; - // google.protobuf.Timestamp expire_time = 1 - // [(google.api.field_behavior) = OUTPUT_ONLY, - // (google.api.field_behavior) = IMMUTABLE]; - repeated google.api.FieldBehavior field_behavior = 1052 [packed = false]; -} - -// An indicator of the behavior of a given field (for example, that a field -// is required in requests, or given as output but ignored as input). -// This **does not** change the behavior in protocol buffers itself; it only -// denotes the behavior and may affect how API tooling handles the field. -// -// Note: This enum **may** receive new values in the future. -enum FieldBehavior { - // Conventional default for enums. Do not use this. - FIELD_BEHAVIOR_UNSPECIFIED = 0; - - // Specifically denotes a field as optional. - // While all fields in protocol buffers are optional, this may be specified - // for emphasis if appropriate. - OPTIONAL = 1; - - // Denotes a field as required. - // This indicates that the field **must** be provided as part of the request, - // and failure to do so will cause an error (usually `INVALID_ARGUMENT`). - REQUIRED = 2; - - // Denotes a field as output only. - // This indicates that the field is provided in responses, but including the - // field in a request does nothing (the server *must* ignore it and - // *must not* throw an error as a result of the field's presence). - OUTPUT_ONLY = 3; - - // Denotes a field as input only. - // This indicates that the field is provided in requests, and the - // corresponding field is not included in output. - INPUT_ONLY = 4; - - // Denotes a field as immutable. - // This indicates that the field may be set once in a request to create a - // resource, but may not be changed thereafter. - IMMUTABLE = 5; - - // Denotes that a (repeated) field is an unordered list. - // This indicates that the service may provide the elements of the list - // in any arbitrary order, rather than the order the user originally - // provided. Additionally, the list's order may or may not be stable. - UNORDERED_LIST = 6; - - // Denotes that this field returns a non-empty default value if not set. - // This indicates that if the user provides the empty value in a request, - // a non-empty value will be returned. The user will not be aware of what - // non-empty value to expect. - NON_EMPTY_DEFAULT = 7; - - // Denotes that the field in a resource (a message annotated with - // google.api.resource) is used in the resource name to uniquely identify the - // resource. For AIP-compliant APIs, this should only be applied to the - // `name` field on the resource. - // - // This behavior should not be applied to references to other resources within - // the message. - // - // The identifier field of resources often have different field behavior - // depending on the request it is embedded in (e.g. for Create methods name - // is optional and unused, while for Update methods it is required). Instead - // of method-specific annotations, only `IDENTIFIER` is required. - IDENTIFIER = 8; -} \ No newline at end of file diff --git a/sigstore-java/src/main/proto/google/api/http.proto b/sigstore-java/src/main/proto/google/api/http.proto deleted file mode 100644 index afa00aed..00000000 --- a/sigstore-java/src/main/proto/google/api/http.proto +++ /dev/null @@ -1,379 +0,0 @@ -// Copyright 2024 Google LLC -// -// Licensed under the Apache License, Version 2.0 (the "License"); -// you may not use this file except in compliance with the License. -// You may obtain a copy of the License at -// -// http://www.apache.org/licenses/LICENSE-2.0 -// -// Unless required by applicable law or agreed to in writing, software -// distributed under the License is distributed on an "AS IS" BASIS, -// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -// See the License for the specific language governing permissions and -// limitations under the License. - -syntax = "proto3"; - -package google.api; - -option cc_enable_arenas = true; -option go_package = "google.golang.org/genproto/googleapis/api/annotations;annotations"; -option java_multiple_files = true; -option java_outer_classname = "HttpProto"; -option java_package = "com.google.api"; -option objc_class_prefix = "GAPI"; - -// Defines the HTTP configuration for an API service. It contains a list of -// [HttpRule][google.api.HttpRule], each specifying the mapping of an RPC method -// to one or more HTTP REST API methods. -message Http { - // A list of HTTP configuration rules that apply to individual API methods. - // - // **NOTE:** All service configuration rules follow "last one wins" order. - repeated HttpRule rules = 1; - - // When set to true, URL path parameters will be fully URI-decoded except in - // cases of single segment matches in reserved expansion, where "%2F" will be - // left encoded. - // - // The default behavior is to not decode RFC 6570 reserved characters in multi - // segment matches. - bool fully_decode_reserved_expansion = 2; -} - -// # gRPC Transcoding -// -// gRPC Transcoding is a feature for mapping between a gRPC method and one or -// more HTTP REST endpoints. It allows developers to build a single API service -// that supports both gRPC APIs and REST APIs. Many systems, including [Google -// APIs](https://github.com/googleapis/googleapis), -// [Cloud Endpoints](https://cloud.google.com/endpoints), [gRPC -// Gateway](https://github.com/grpc-ecosystem/grpc-gateway), -// and [Envoy](https://github.com/envoyproxy/envoy) proxy support this feature -// and use it for large scale production services. -// -// `HttpRule` defines the schema of the gRPC/REST mapping. The mapping specifies -// how different portions of the gRPC request message are mapped to the URL -// path, URL query parameters, and HTTP request body. It also controls how the -// gRPC response message is mapped to the HTTP response body. `HttpRule` is -// typically specified as an `google.api.http` annotation on the gRPC method. -// -// Each mapping specifies a URL path template and an HTTP method. The path -// template may refer to one or more fields in the gRPC request message, as long -// as each field is a non-repeated field with a primitive (non-message) type. -// The path template controls how fields of the request message are mapped to -// the URL path. -// -// Example: -// -// service Messaging { -// rpc GetMessage(GetMessageRequest) returns (Message) { -// option (google.api.http) = { -// get: "/v1/{name=messages/*}" -// }; -// } -// } -// message GetMessageRequest { -// string name = 1; // Mapped to URL path. -// } -// message Message { -// string text = 1; // The resource content. -// } -// -// This enables an HTTP REST to gRPC mapping as below: -// -// HTTP | gRPC -// -----|----- -// `GET /v1/messages/123456` | `GetMessage(name: "messages/123456")` -// -// Any fields in the request message which are not bound by the path template -// automatically become HTTP query parameters if there is no HTTP request body. -// For example: -// -// service Messaging { -// rpc GetMessage(GetMessageRequest) returns (Message) { -// option (google.api.http) = { -// get:"/v1/messages/{message_id}" -// }; -// } -// } -// message GetMessageRequest { -// message SubMessage { -// string subfield = 1; -// } -// string message_id = 1; // Mapped to URL path. -// int64 revision = 2; // Mapped to URL query parameter `revision`. -// SubMessage sub = 3; // Mapped to URL query parameter `sub.subfield`. -// } -// -// This enables a HTTP JSON to RPC mapping as below: -// -// HTTP | gRPC -// -----|----- -// `GET /v1/messages/123456?revision=2&sub.subfield=foo` | -// `GetMessage(message_id: "123456" revision: 2 sub: SubMessage(subfield: -// "foo"))` -// -// Note that fields which are mapped to URL query parameters must have a -// primitive type or a repeated primitive type or a non-repeated message type. -// In the case of a repeated type, the parameter can be repeated in the URL -// as `...?param=A¶m=B`. In the case of a message type, each field of the -// message is mapped to a separate parameter, such as -// `...?foo.a=A&foo.b=B&foo.c=C`. -// -// For HTTP methods that allow a request body, the `body` field -// specifies the mapping. Consider a REST update method on the -// message resource collection: -// -// service Messaging { -// rpc UpdateMessage(UpdateMessageRequest) returns (Message) { -// option (google.api.http) = { -// patch: "/v1/messages/{message_id}" -// body: "message" -// }; -// } -// } -// message UpdateMessageRequest { -// string message_id = 1; // mapped to the URL -// Message message = 2; // mapped to the body -// } -// -// The following HTTP JSON to RPC mapping is enabled, where the -// representation of the JSON in the request body is determined by -// protos JSON encoding: -// -// HTTP | gRPC -// -----|----- -// `PATCH /v1/messages/123456 { "text": "Hi!" }` | `UpdateMessage(message_id: -// "123456" message { text: "Hi!" })` -// -// The special name `*` can be used in the body mapping to define that -// every field not bound by the path template should be mapped to the -// request body. This enables the following alternative definition of -// the update method: -// -// service Messaging { -// rpc UpdateMessage(Message) returns (Message) { -// option (google.api.http) = { -// patch: "/v1/messages/{message_id}" -// body: "*" -// }; -// } -// } -// message Message { -// string message_id = 1; -// string text = 2; -// } -// -// -// The following HTTP JSON to RPC mapping is enabled: -// -// HTTP | gRPC -// -----|----- -// `PATCH /v1/messages/123456 { "text": "Hi!" }` | `UpdateMessage(message_id: -// "123456" text: "Hi!")` -// -// Note that when using `*` in the body mapping, it is not possible to -// have HTTP parameters, as all fields not bound by the path end in -// the body. This makes this option more rarely used in practice when -// defining REST APIs. The common usage of `*` is in custom methods -// which don't use the URL at all for transferring data. -// -// It is possible to define multiple HTTP methods for one RPC by using -// the `additional_bindings` option. Example: -// -// service Messaging { -// rpc GetMessage(GetMessageRequest) returns (Message) { -// option (google.api.http) = { -// get: "/v1/messages/{message_id}" -// additional_bindings { -// get: "/v1/users/{user_id}/messages/{message_id}" -// } -// }; -// } -// } -// message GetMessageRequest { -// string message_id = 1; -// string user_id = 2; -// } -// -// This enables the following two alternative HTTP JSON to RPC mappings: -// -// HTTP | gRPC -// -----|----- -// `GET /v1/messages/123456` | `GetMessage(message_id: "123456")` -// `GET /v1/users/me/messages/123456` | `GetMessage(user_id: "me" message_id: -// "123456")` -// -// ## Rules for HTTP mapping -// -// 1. Leaf request fields (recursive expansion nested messages in the request -// message) are classified into three categories: -// - Fields referred by the path template. They are passed via the URL path. -// - Fields referred by the [HttpRule.body][google.api.HttpRule.body]. They -// are passed via the HTTP -// request body. -// - All other fields are passed via the URL query parameters, and the -// parameter name is the field path in the request message. A repeated -// field can be represented as multiple query parameters under the same -// name. -// 2. If [HttpRule.body][google.api.HttpRule.body] is "*", there is no URL -// query parameter, all fields -// are passed via URL path and HTTP request body. -// 3. If [HttpRule.body][google.api.HttpRule.body] is omitted, there is no HTTP -// request body, all -// fields are passed via URL path and URL query parameters. -// -// ### Path template syntax -// -// Template = "/" Segments [ Verb ] ; -// Segments = Segment { "/" Segment } ; -// Segment = "*" | "**" | LITERAL | Variable ; -// Variable = "{" FieldPath [ "=" Segments ] "}" ; -// FieldPath = IDENT { "." IDENT } ; -// Verb = ":" LITERAL ; -// -// The syntax `*` matches a single URL path segment. The syntax `**` matches -// zero or more URL path segments, which must be the last part of the URL path -// except the `Verb`. -// -// The syntax `Variable` matches part of the URL path as specified by its -// template. A variable template must not contain other variables. If a variable -// matches a single path segment, its template may be omitted, e.g. `{var}` -// is equivalent to `{var=*}`. -// -// The syntax `LITERAL` matches literal text in the URL path. If the `LITERAL` -// contains any reserved character, such characters should be percent-encoded -// before the matching. -// -// If a variable contains exactly one path segment, such as `"{var}"` or -// `"{var=*}"`, when such a variable is expanded into a URL path on the client -// side, all characters except `[-_.~0-9a-zA-Z]` are percent-encoded. The -// server side does the reverse decoding. Such variables show up in the -// [Discovery -// Document](https://developers.google.com/discovery/v1/reference/apis) as -// `{var}`. -// -// If a variable contains multiple path segments, such as `"{var=foo/*}"` -// or `"{var=**}"`, when such a variable is expanded into a URL path on the -// client side, all characters except `[-_.~/0-9a-zA-Z]` are percent-encoded. -// The server side does the reverse decoding, except "%2F" and "%2f" are left -// unchanged. Such variables show up in the -// [Discovery -// Document](https://developers.google.com/discovery/v1/reference/apis) as -// `{+var}`. -// -// ## Using gRPC API Service Configuration -// -// gRPC API Service Configuration (service config) is a configuration language -// for configuring a gRPC service to become a user-facing product. The -// service config is simply the YAML representation of the `google.api.Service` -// proto message. -// -// As an alternative to annotating your proto file, you can configure gRPC -// transcoding in your service config YAML files. You do this by specifying a -// `HttpRule` that maps the gRPC method to a REST endpoint, achieving the same -// effect as the proto annotation. This can be particularly useful if you -// have a proto that is reused in multiple services. Note that any transcoding -// specified in the service config will override any matching transcoding -// configuration in the proto. -// -// Example: -// -// http: -// rules: -// # Selects a gRPC method and applies HttpRule to it. -// - selector: example.v1.Messaging.GetMessage -// get: /v1/messages/{message_id}/{sub.subfield} -// -// ## Special notes -// -// When gRPC Transcoding is used to map a gRPC to JSON REST endpoints, the -// proto to JSON conversion must follow the [proto3 -// specification](https://developers.google.com/protocol-buffers/docs/proto3#json). -// -// While the single segment variable follows the semantics of -// [RFC 6570](https://tools.ietf.org/html/rfc6570) Section 3.2.2 Simple String -// Expansion, the multi segment variable **does not** follow RFC 6570 Section -// 3.2.3 Reserved Expansion. The reason is that the Reserved Expansion -// does not expand special characters like `?` and `#`, which would lead -// to invalid URLs. As the result, gRPC Transcoding uses a custom encoding -// for multi segment variables. -// -// The path variables **must not** refer to any repeated or mapped field, -// because client libraries are not capable of handling such variable expansion. -// -// The path variables **must not** capture the leading "/" character. The reason -// is that the most common use case "{var}" does not capture the leading "/" -// character. For consistency, all path variables must share the same behavior. -// -// Repeated message fields must not be mapped to URL query parameters, because -// no client library can support such complicated mapping. -// -// If an API needs to use a JSON array for request or response body, it can map -// the request or response body to a repeated field. However, some gRPC -// Transcoding implementations may not support this feature. -message HttpRule { - // Selects a method to which this rule applies. - // - // Refer to [selector][google.api.DocumentationRule.selector] for syntax - // details. - string selector = 1; - - // Determines the URL pattern is matched by this rules. This pattern can be - // used with any of the {get|put|post|delete|patch} methods. A custom method - // can be defined using the 'custom' field. - oneof pattern { - // Maps to HTTP GET. Used for listing and getting information about - // resources. - string get = 2; - - // Maps to HTTP PUT. Used for replacing a resource. - string put = 3; - - // Maps to HTTP POST. Used for creating a resource or performing an action. - string post = 4; - - // Maps to HTTP DELETE. Used for deleting a resource. - string delete = 5; - - // Maps to HTTP PATCH. Used for updating a resource. - string patch = 6; - - // The custom pattern is used for specifying an HTTP method that is not - // included in the `pattern` field, such as HEAD, or "*" to leave the - // HTTP method unspecified for this rule. The wild-card rule is useful - // for services that provide content to Web (HTML) clients. - CustomHttpPattern custom = 8; - } - - // The name of the request field whose value is mapped to the HTTP request - // body, or `*` for mapping all request fields not captured by the path - // pattern to the HTTP body, or omitted for not having any HTTP request body. - // - // NOTE: the referred field must be present at the top-level of the request - // message type. - string body = 7; - - // Optional. The name of the response field whose value is mapped to the HTTP - // response body. When omitted, the entire response message will be used - // as the HTTP response body. - // - // NOTE: The referred field must be present at the top-level of the response - // message type. - string response_body = 12; - - // Additional HTTP bindings for the selector. Nested bindings must - // not contain an `additional_bindings` field themselves (that is, - // the nesting may only be one level deep). - repeated HttpRule additional_bindings = 11; -} - -// A custom pattern is used for defining custom HTTP verb. -message CustomHttpPattern { - // The name of this custom HTTP verb. - string kind = 1; - - // The path matched by this custom verb. - string path = 2; -} From b382199de37d9900101091317b5d5e557fe46c8e Mon Sep 17 00:00:00 2001 From: Rafael Winterhalter Date: Sat, 15 Aug 2026 16:19:01 +0200 Subject: [PATCH 3/3] Generate the DSSE envelope into dev.sigstore.proto.dsse envelope.proto sets go_package and ruby_package but no java_package, so protoc emitted Envelope and Signature into io.intoto, a namespace sigstore does not own, and sigstore-java shipped those nine classes in its own jar. Since 0.3.2 protobuf-specs publishes protos only, with no compiled classes, so these are generated here rather than consumed from upstream. That makes the Java package a local choice: add the java_package option upstream omits, following the convention the sibling protos already use, where package dev.sigstore.X maps to java_package dev.sigstore.proto.X. The option has to live in the proto, and the proto arrives inside an artifact, so carry a copy in src/main/proto next to fulcio.proto. It takes precedence on the --proto_path, and protoc refuses an input it has shadowed, so the extracted copy is dropped from the source set while staying on the include path. Only Java codegen moves. The proto package stays io.intoto, so the descriptor is still io.intoto.Envelope, Bundle.dsse_envelope still points at it, and the wire and JSON encodings are byte for byte what they were. Signed bundles remain valid and interoperable. This is a breaking change for Java callers: Bundle.getDsseEnvelope() and friends now return dev.sigstore.proto.dsse.EnvelopeOuterClass.Envelope. The jar now contains only packages sigstore owns, so dev.sigstore no longer exports a foreign package to everyone who requires it. --- sigstore-java/build.gradle.kts | 9 +++ .../dev/sigstore/bundle/BundleWriter.java | 4 +- sigstore-java/src/main/proto/envelope.proto | 60 +++++++++++++++++++ 3 files changed, 71 insertions(+), 2 deletions(-) create mode 100644 sigstore-java/src/main/proto/envelope.proto diff --git a/sigstore-java/build.gradle.kts b/sigstore-java/build.gradle.kts index f01feae7..6c124e56 100644 --- a/sigstore-java/build.gradle.kts +++ b/sigstore-java/build.gradle.kts @@ -71,6 +71,15 @@ dependencies { testRuntimeOnly("io.github.netmikey.logunit:logunit-jul:2.0.0") } +// src/main/proto/envelope.proto shadows the copy extracted from protobuf-specs, adding the +// java_package that upstream omits. Both sit at the same path relative to their --proto_path +// root, and protoc refuses an input it has shadowed, so drop the extracted one from the +// inputs. It stays on the include path, where src/main/proto is searched first, leaving +// imports of "envelope.proto" resolving to our copy. +sourceSets.main.get().extensions.getByName("proto").exclude { + it.file.name == "envelope.proto" && "extracted-protos" in it.file.path +} + protobuf { protoc { artifact = "com.google.protobuf:protoc:4.35.1" diff --git a/sigstore-java/src/main/java/dev/sigstore/bundle/BundleWriter.java b/sigstore-java/src/main/java/dev/sigstore/bundle/BundleWriter.java index a565f4fe..ccbcd667 100644 --- a/sigstore-java/src/main/java/dev/sigstore/bundle/BundleWriter.java +++ b/sigstore-java/src/main/java/dev/sigstore/bundle/BundleWriter.java @@ -28,13 +28,13 @@ import dev.sigstore.proto.common.v1.MessageSignature; import dev.sigstore.proto.common.v1.RFC3161SignedTimestamp; import dev.sigstore.proto.common.v1.X509Certificate; +import dev.sigstore.proto.dsse.EnvelopeOuterClass.Envelope; import dev.sigstore.proto.rekor.v1.Checkpoint; import dev.sigstore.proto.rekor.v1.InclusionPromise; import dev.sigstore.proto.rekor.v1.InclusionProof; import dev.sigstore.proto.rekor.v1.KindVersion; import dev.sigstore.proto.rekor.v1.TransparencyLogEntry; import dev.sigstore.rekor.client.RekorEntry; -import io.intoto.EnvelopeOuterClass.Envelope; import java.security.cert.CertificateEncodingException; import java.util.Base64; import java.util.List; @@ -118,7 +118,7 @@ static dev.sigstore.proto.bundle.v1.Bundle.Builder createBundleBuilder(Bundle bu .setPayloadType(dsseEnvelope.getPayloadType()); for (var sig : dsseEnvelope.getSignatures()) { envelopeBuilder.addSignatures( - io.intoto.EnvelopeOuterClass.Signature.newBuilder() + dev.sigstore.proto.dsse.EnvelopeOuterClass.Signature.newBuilder() .setSig(ByteString.copyFrom(sig.getSig())) .build()); } diff --git a/sigstore-java/src/main/proto/envelope.proto b/sigstore-java/src/main/proto/envelope.proto new file mode 100644 index 00000000..f90b46ad --- /dev/null +++ b/sigstore-java/src/main/proto/envelope.proto @@ -0,0 +1,60 @@ +// https://raw.githubusercontent.com/secure-systems-lab/dsse/9c813476bd36de70a5738c72e784f123ecea16af/envelope.proto + +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// http://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. + +// This is a copy of the envelope.proto carried by dev.sigstore:protobuf-specs, which +// takes precedence over the copy extracted from that artifact. It differs only by the +// java_package option below: upstream sets go_package and ruby_package but no Java +// equivalent, so protoc would otherwise emit these classes into io.intoto, a namespace +// sigstore does not own. The proto package is deliberately left alone, so the wire +// format and the io.intoto.Envelope descriptor name are unchanged. + +syntax = "proto3"; + +package io.intoto; + +option go_package = "github.com/sigstore/protobuf-specs/gen/pb-go/dsse"; +option ruby_package = "Sigstore::DSSE"; +option java_package = "dev.sigstore.proto.dsse"; + +// An authenticated message of arbitrary type. +message Envelope { + // Message to be signed. (In JSON, this is encoded as base64.) + // REQUIRED. + bytes payload = 1; + + // String unambiguously identifying how to interpret payload. + // REQUIRED. + string payloadType = 2; + + // Signature over: + // PAE(type, payload) + // Where PAE is defined as: + // PAE(type, payload) = "DSSEv1" + SP + LEN(type) + SP + type + SP + LEN(payload) + SP + payload + // + = concatenation + // SP = ASCII space [0x20] + // "DSSEv1" = ASCII [0x44, 0x53, 0x53, 0x45, 0x76, 0x31] + // LEN(s) = ASCII decimal encoding of the byte length of s, with no leading zeros + // REQUIRED (length >= 1). + repeated Signature signatures = 3; +} + +message Signature { + // Signature itself. (In JSON, this is encoded as base64.) + // REQUIRED. + bytes sig = 1; + + // *Unauthenticated* hint identifying which public key was used. + // OPTIONAL. + string keyid = 2; +}