verification: Run sig verification even without a policy #2026
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What does this pull request do? Explain your changes. (required)
At the moment, signature verification for results returned by an orchestrators will only run if a verification policy is specified which is only the case if
-localVerify=true
. As a result, if-localVerify=false
when running a broadcaster, signature verification is skipped.This PR ensures that signature verification is always run regardless of the value of
-localVerify
because the broadcaster should always verify signatures returned by an orchestrator.Specific updates (required)
See commit history.
How did you test each of these updates (required)
Added unit tests.
Does this pull request close any open issues?
N/A
Checklist:
make
runs successfully./test.sh
pass