Skip to content

fix: reliable GitLab commit verification when the CLI runs through Dagger - #3550

Merged
javirln merged 3 commits into
mainfrom
javirln/gitlab-author-verification
Oct 7, 2026
Merged

javirln merged 3 commits into
mainfrom
javirln/gitlab-author-verification

Conversation

@javirln

@javirln javirln commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

Summary

Makes GitLab commit author verification work when the CLI runs through the Chainloop Dagger module on a self-managed GitLab server.

  • Deterministic runner discovery. Runners are discovered in a fixed order, with the Dagger runner first. The Dagger module passes the parent GitLab CI context to the CLI container, so the Dagger and GitLab runners both matched, and the selected runner changed from run to run (since fix: return early in DiscoverRunner on first match #2871). When the GitLab runner was selected, attestation init failed on missing GitLab variables.
  • GitLab API token. Commit verification sends GITLAB_TOKEN (read_api scope) as PRIVATE-TOKEN. The GitLab commit signature API does not accept job tokens, so commits of private and internal projects could not be verified.
  • Correct 404 handling. Only a 404 Signature Not Found response marks a commit as unsigned. 404 Project Not Found and 404 Commit Not Found now give an unavailable status with the GitLab message, instead of "Commit is not signed".
  • GitLab-signed commits. Signatures with the verified_system status, which GitLab creates for web UI and merge commits, are reported as verified.
  • Signature algorithm. The signature.algorithm annotation of the git head subject falls back to the type of the commit signature when the platform does not report it.
  • Visible failure reason. The reason of an unavailable verification is logged as a warning.
  • Dagger module options. init accepts --gitlab-token, and --gitlab-ca for self-managed GitLab servers that use a certificate from a private CA.
  • CLI image. The scratch-based CLI image now has a writable /tmp, which the PR/MR metadata collector needs.

Refs PFM-7635

AI disclosure

This change was developed with assistance from Claude Code.

View guided diff

@chainloop-platform

chainloop-platform Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

PR validation — ✅ 3 passing

Status Policy Material Messages
✅ Passed pr-min-approvals pr-info -
✅ Passed pr-description-required pr-info -
✅ Passed pr-user-story-linked pr-info -

View attestation ↗

AI Session Checks — 🟢 90% · ✅ 0 failing

Avg score Sessions Failing policies Attribution Files Lines Total Duration
🟢 90% 1 ✅ 0 100% AI / 0% Human 15 +629 / -33 5h54m38s

🟢 90% — 100% AI — ✅ All policies passing

Oct 7, 2026 14:09 UTC · 5h54m38s · $81.65 · 1.1k in / 723.6k out · claude-code 2.1.292 (claude-opus-5-5)

View session details ↗

Change Summary

  • Makes runner discovery deterministic for Dagger and GitLab overlap and improves GitLab commit verification handling.
  • Adds renderer fallback for signature.algorithm, Dagger GitLab token/CA options, and a writable /tmp in the CLI image.
  • Covers the changes with new unit tests, golden updates, and a local end-to-end repro.

AI Session Overall Score

🟢 90% — Verified root-cause fix, with only planning weaker than the task breadth.

AI Session Analysis Breakdown

🟢 95% · solution-quality

🟢 The AI used probes and mutation checks instead of masking the bug. · High Impact

🟢 94% · verification

🟢 The AI added failing tests for the core fixes and reran them green. · High Impact

🟢 92% · alignment

No notes.

🟢 88% · scope-discipline

🟢 The later platform /tmp fix was split into a separate PR. · High Impact

🟢 88% · user-trust-signal

No notes.

🟡 72% · context-and-planning

🟠 The session tackled a broad multi-file fix without a visible plan or TODO. · Medium Severity

💡 Before editing across repo layers, write a short plan naming files, risks, and checks.


File Attribution

████████████████████ 100% AI / 0% Human

Status Attribution File Lines
created ai pkg/attestation/crafter/runners/commitverification/gitlab_test.go +210 / -0
created ai pkg/attestation/crafter/runner_test.go +158 / -0
modified ai pkg/attestation/crafter/runners/commitverification/gitlab.go +77 / -7
modified ai pkg/attestation/renderer/chainloop/v02_test.go +69 / -0
modified ai pkg/attestation/crafter/runner.go +31 / -3
modified ai extras/dagger/main.go +25 / -2
modified ai extras/dagger/README.md +21 / -0
modified ai pkg/attestation/renderer/chainloop/v02.go +11 / -3
modified ai pkg/attestation/crafter/runners/daggerpipeline.go +5 / -5
modified ai pkg/attestation/crafter/runners/gitlabpipeline.go +5 / -5
modified ai pkg/attestation/crafter/crafter.go +7 / -2
modified ai pkg/attestation/crafter/runners/commitverification/github.go +3 / -3
modified ai app/cli/Dockerfile.goreleaser +3 / -1
modified ai pkg/attestation/renderer/chainloop/testdata/attestation.output-2.v0.2.json +2 / -1
modified ai pkg/attestation/renderer/chainloop/testdata/attestation.output-2.v2.json +2 / -1

Policies (4)

Status Policy Material Messages
✅ Passed ai-config-ai-agents-allowed ai-coding-session-38d0eb -
✅ Passed ai-config-no-dangerous-commands ai-coding-session-38d0eb -
✅ Passed ai-config-no-secrets ai-coding-session-38d0eb -
✅ Passed ai-config-mcp-servers-allowed ai-coding-session-38d0eb -

Security Checks — ✅ 6 passing

✅ secret-scan

Status Policy Messages
✅ Passed secrets-detection -

✅ sast-scan

Status Policy Messages
✅ Passed owasp-top10-2025 -
✅ Passed sast -
✅ Passed cwe-top25 -
✅ Passed cwe-top26-40-cusp -

✅ iac-scan

Status Policy Messages
✅ Passed iac-misconfiguration -
Scans not applied (2)
Scan Reason
vulnerability-scan no manifest/lockfile changed
github-actions-scan no workflow files changed

View attestation ↗

Security context

This change touches code with 4 recorded security-fix advisories. These are pointers to what past fixes established, not findings in this diff, and they never fail the check.

View in Chainloop ↗ · How this works ↗


Powered by Chainloop and Chainloop Trace

@javirln
javirln marked this pull request as ready for review October 7, 2026 15:40
migmartri
migmartri previously approved these changes Oct 7, 2026
- Discover runners in a fixed order with the Dagger runner first. The
  Chainloop Dagger module passes the parent GitLab CI context to the CLI
  container, so the Dagger and GitLab runners both matched and map
  iteration picked one at random. When the GitLab runner won,
  attestation init failed on missing GitLab variables.
- Send GITLAB_TOKEN (read_api scope) as PRIVATE-TOKEN. The GitLab commit
  signature API does not accept job tokens.
- Only a "404 Signature Not Found" response marks the commit as unsigned.
  "Project Not Found" and "Commit Not Found" now give an unavailable
  status with the GitLab message.
- Report verified_system signatures (made by GitLab) as verified.
- Take signature.algorithm from the commit signature when the platform
  does not report it.
- Log the reason of an unavailable verification as a warning.

Assisted-by: Claude Code
Signed-off-by: Javier Rodriguez <javier@chainloop.dev>

Chainloop-Trace-Sessions: 38d0eb57-8573-4185-8a52-f49f140d0ea8
Add --gitlab-token, passed to the CLI as GITLAB_TOKEN, to verify commits
of private and internal projects, and --gitlab-ca to trust the CA of a
self-managed Gitlab server through SSL_CERT_DIR.

Assisted-by: Claude Code
Signed-off-by: Javier Rodriguez <javier@chainloop.dev>

Chainloop-Trace-Sessions: 38d0eb57-8573-4185-8a52-f49f140d0ea8
The CLI image is scratch-based and had no /tmp, so collectors that write
temporary files, such as the PR/MR metadata collector, failed.

Assisted-by: Claude Code
Signed-off-by: Javier Rodriguez <javier@chainloop.dev>

Chainloop-Trace-Sessions: 38d0eb57-8573-4185-8a52-f49f140d0ea8
@javirln
javirln force-pushed the javirln/gitlab-author-verification branch from 080da79 to 260c3ad Compare October 7, 2026 20:03
@javirln
javirln requested a review from a team October 7, 2026 20:04
@javirln
javirln merged commit 351f741 into main Oct 7, 2026
17 checks passed
@javirln
javirln deleted the javirln/gitlab-author-verification branch October 7, 2026 21:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants