Skip to content

fix(seal): drop the xml-sec fork, pin the signer - #448

Open
LKSNDRTMLKV wants to merge 1 commit into
mainfrom
fix/seal-xml-sec-release
Open

LKSNDRTMLKV wants to merge 1 commit into
mainfrom
fix/seal-xml-sec-release

Conversation

@LKSNDRTMLKV

@LKSNDRTMLKV LKSNDRTMLKV commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

Summary

The workspace carried a fork of xml-sec to raise one constant: the 65 536-entry node-set ceiling that the French, Czech, Italian and Spanish trusted lists exceed. Upstream raised it in 0.1.17 (structured-world/xml-sec#158). This drops the fork and requires xml-sec 0.1.20 from crates.io.

0.1.18 changed key trust: xml-sec no longer verifies with a key just because the document carries it. So the verifier now hands it the one certificate this node already decided to trust, as an exact pin. For the LOTL, that is the certificate the Official Journal anchor authorises; for a national list, the one its LOTL pointer names. The signature is then checked against that key and no other, by xml-sec itself. Before, xml-sec picked its own key from the document, and the two agreed only because a ds:KeyInfo with more than one certificate was refused first. That refusal stays, as the earlier and better-named of two locks.

Changes

  • Cargo.toml: the [patch.crates-io] stanza is gone. Its "accepting a pre-release dependency" reasoning moved beside the dependency in crates/dpp-seal/Cargo.toml and was updated (0.1.18 changed trust semantics under a patch version, so a bump is a real change).
  • deny.toml: allow-git is empty again. The fork was its only entry, and this was the exit condition written there.
  • trustlist/verify.rs: verify_signature_with pins the vetted certificate (KeyResolverConfig::trusted_certs) for both the LOTL and national lists. A national certificate that is not valid base64 is now Malformed rather than decoded to nothing.
  • The guard on the resolved dependency (the_patched_xml_sec_is_the_one_that_resolved) becomes xml_sec_is_a_release_with_the_raised_node_set_ceiling: it fails on a release before 0.1.17 or a git source. CI runs it; the over-ceiling documents are too large to commit.
  • tests/xml_sec_fork.rs is renamed tests/large_trusted_lists.rs and reworded. The docs that described the fork (trustlist/mod.rs, fetch.rs, tests/fixtures/local/README.md) say what is true now.

Dependencies

xml-sec 0.1.16 (fork) → 0.1.20 (crates.io). It is on an untrusted-input path: it canonicalises and verifies trusted-list XML fetched from 30 national servers. Failing closed is unchanged. The lock gains ed448, ed448-goldilocks, x25519-dalek, hash2curve, sha3, keccak, shake, sponge-cursor, pkcs12 and a second cms, all pulled in by xml-sec's XML-encryption and key-import features, which this crate does not call. It loses sxd-document-no-unsafe, sxd-xpath-no-unsafe, syn 0.15, backtrace and their trees. Duplicated crate names go from 72 to 68. cargo deny check bans licenses sources and cargo audit --deny yanked --deny unmaintained are both clean.

How this was checked

  • just check green, 1 488 unit tests.
  • Italy's and France's published lists (git-ignored, see the fixtures README) verify end to end on 0.1.20 with no fork: a_list_over_the_old_node_set_ceiling_verifies.
  • Against 0.1.20 with the old resolver, every trusted-list test failed with verification requires an authorized key. With the pin, all pass, including the tamper tests (a changed service status, a changed SigningTime, a changed SignatureValue).
  • New: the_signature_is_checked_only_against_the_pinned_certificate. Finland's genuine list verifies with its own certificate pinned and is refused with the LOTL's. It fails if the verifier goes back to trusting the document's key (checked by swapping in CryptographicOnly).

Not in this PR

  • Germany still does not verify. Its list tripped a different ceiling, 100 000 XML nodes per document, which the fork never touched and which is still hard-coded in 0.1.20. Not re-measured since 2026-09-15.

Summary by CodeRabbit

  • Bug Fixes
    • Trusted-list signatures are now verified only with certificates authorized by the relevant trust anchor or LOTL, preventing a document from supplying its own trusted signing key.
    • Updated XML security support handles larger trusted lists, including lists that exceeded the previous node-set limit. Germany’s list remains unsupported due to a separate document-size limit.
    • Malformed certificate data is now rejected rather than treated as empty data.
  • Chores
    • Updated the XML security dependency and no longer use a Git-based fork.

@LKSNDRTMLKV LKSNDRTMLKV added the review-ready Opt this PR into a CodeRabbit review label Oct 7, 2026
@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: odal-node/dpp-engine/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 85e0b18e-1bde-4e85-9cea-30e4f355bbd0
📥 Commits

Reviewing files that changed from the base of the PR and between 6e59383 and eac570a.

⛔ Files ignored due to path filters (1)
  • Cargo.lock is excluded by !**/*.lock, !Cargo.lock
📒 Files selected for processing (11)
  • CHANGELOG.md
  • Cargo.toml
  • crates/dpp-seal/Cargo.toml
  • crates/dpp-seal/src/trustlist/chain_tests.rs
  • crates/dpp-seal/src/trustlist/fetch.rs
  • crates/dpp-seal/src/trustlist/mod.rs
  • crates/dpp-seal/src/trustlist/verify.rs
  • crates/dpp-seal/src/trustlist/verify_tests.rs
  • crates/dpp-seal/tests/fixtures/local/README.md
  • crates/dpp-seal/tests/large_trusted_lists.rs
  • deny.toml
💤 Files with no reviewable changes (1)
  • Cargo.toml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The change replaces the workspace xml-sec fork with a released dependency, verifies trusted lists using the certificate authorized by the trust chain, and updates the release guard and large-list documentation and tests.

Changes

Trusted-list verification

Layer / File(s) Summary
Use and guard the released xml-sec dependency
Cargo.toml, crates/dpp-seal/Cargo.toml, crates/dpp-seal/src/trustlist/chain_tests.rs, deny.toml, crates/dpp-seal/tests/fixtures/local/README.md
The workspace Git override is removed, and dpp-seal uses xml-sec 0.1.20. The lockfile test requires a crates.io release at version 0.1.17 or later, and deny.toml disallows Git dependencies.
Verify with the authorized certificate
crates/dpp-seal/src/trustlist/verify.rs, crates/dpp-seal/src/trustlist/verify_tests.rs, crates/dpp-seal/src/trustlist/chain_tests.rs, CHANGELOG.md
LOTL and national-list verification pass the accepted certificate as the sole trusted certificate. Invalid national-list certificate base64 returns Malformed. Tests check verification with the list certificate and rejection with the EU LOTL certificate.
Document and test large-list limits
crates/dpp-seal/src/trustlist/fetch.rs, crates/dpp-seal/src/trustlist/mod.rs, crates/dpp-seal/tests/fixtures/local/README.md, crates/dpp-seal/tests/large_trusted_lists.rs
Comments and tests describe the released node-set ceiling and lists that exceed the old limit. They also describe Germany’s separate 100,000-node limit and retain real-list verification coverage.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Bug fix

Sequence Diagram(s)

sequenceDiagram
  participant TrustListVerification
  participant verify_signature_with
  participant DefaultKeyResolver
  participant XMLDSigVerifier
  TrustListVerification->>verify_signature_with: Pass the accepted certificate and signed XML
  verify_signature_with->>DefaultKeyResolver: Configure the accepted certificate as the sole trusted certificate
  verify_signature_with->>XMLDSigVerifier: Verify the signed XML
  XMLDSigVerifier-->>verify_signature_with: Return verification status or error
  verify_signature_with-->>TrustListVerification: Return success or rejection
Loading

Merge Risk: ⚪ Minimal · up to eac57

No actionable issue is established that would block merging. The reported verification results remain subject to normal checks.

🚥 Pre-merge checks | ✅ 7
✅ Passed checks (7 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 10 functions across 6 files. (4 skipped: 4…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Publication Boundary ✅ Passed PASS. The diff and pull-request description contain no ADR reference, pricing, quote, contract term, rate, vendor lead time, or negotiation status. The structured-world/xml-sec#158 references are up…
New Dependency Is Justified ✅ Passed PASS: The pull request adds no new direct dependency to a Cargo.toml. It changes the existing direct xml-sec dependency in crates/dpp-seal/Cargo.toml from 0.1.16 to 0.1.20 and removes the work…
Title check ✅ Passed The title clearly identifies the two main changes: removing the xml-sec fork and pinning the signer.
Description check ✅ Passed The description is detailed and covers the summary, main changes, dependency updates, verification behavior, tests, and known limitations. It omits the Related issue section and does not reproduce the…
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

review-ready Opt this PR into a CodeRabbit review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant