Skip to content

confidentialrelay: forward vault public key through GetRawSecrets, bind into hash - #2429

Merged
prashantkumar1982 merged 2 commits into
mainfrom
relay-secrets-response-public-key
Sep 30, 2026
Merged

prashantkumar1982 merged 2 commits into
mainfrom
relay-secrets-response-public-key

Conversation

@prashantkumar1982

Copy link
Copy Markdown
Contributor

Motivation

Follow-up to the Vault reshare zero-downtime PublicKey work. The Vault GetSecrets response carries raw_vault_public_key (the key of the DKG instance that produced the shares) so decrypt-side callers verify/aggregate against the live key. That already reaches the enclave on the initial compute request, but runtime secret reads in confidential workflows go through the confidential-relay path, which dropped the key: GetRawSecrets returned only []*vault.SecretResponse, and SecretsResponseResult had no public-key field. After a reshare, runtime getSecret receives shares from the new DKG but the enclave verifies them with its stale configured key, so aggregation fails.

Change

  • ExecutionHelperWithRawSecrets.GetRawSecrets now returns the full *vault.GetSecretsResponse, so the top-level RawVaultPublicKey survives to the relay handler. The restriction wrapper repackages the filtered responses plus the key.
  • SecretsResponseResult gains RawVaultPublicKey and it is bound into Hash(), so the enclave can trust the forwarded key as authorization-covered.
  • Regenerated the ExecutionHelperWithRawSecrets mock and updated affected tests.

Downstream

Prerequisite for:

Because the key is bound into the signed hash, the relay signer (chainlink) and the enclave verifier (conf-compute) must ship together.

@github-actions

Copy link
Copy Markdown
Contributor

👋 prashantkumar1982, thanks for creating this pull request!

To help reviewers, please consider creating future PRs as drafts first. This allows you to self-review and make any final changes before notifying the team.

Once you're ready, you can mark it as "Ready for review" to request feedback. Thanks!

@github-actions

github-actions Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ API Diff Results - github.com/smartcontractkit/chainlink-common

⚠️ Breaking Changes (1)

pkg/workflows/host.ExecutionHelperWithRawSecrets (1)
  • GetRawSecretsResponse — ➕ Added

✅ Compatible Changes (4)

pkg/capabilities/v2/actions/confidentialrelay.SecretsResponseResult (1)
  • RawVaultPublicKey — ➕ Added
pkg/workflows/host/mocks (1)
  • MockExecutionHelperWithRawSecrets_GetRawSecretsResponse_Call — ➕ Added
pkg/workflows/host/mocks.(*MockExecutionHelperWithRawSecrets) (1)
  • GetRawSecretsResponse — ➕ Added
pkg/workflows/host/mocks.(*MockExecutionHelperWithRawSecrets_Expecter) (1)
  • GetRawSecretsResponse — ➕ Added

📄 View full apidiff report

@jmank88 jmank88 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we find a way to do this without making a breaking API change?

@prashantkumar1982

Copy link
Copy Markdown
Contributor Author

Can we find a way to do this without making a breaking API change?

Ahh thanks @jmank88, sorry i missed the breaking change part. Yes, we shouldn't make a breaking API change. Fixing it now.

@prashantkumar1982
prashantkumar1982 force-pushed the relay-secrets-response-public-key branch from 22e1de1 to 77faf1d Compare September 30, 2026 15:54
@prashantkumar1982
prashantkumar1982 added this pull request to the merge queue Sep 30, 2026
Merged via the queue into main with commit 9016164 Sep 30, 2026
36 of 39 checks passed
@prashantkumar1982
prashantkumar1982 deleted the relay-secrets-response-public-key branch September 30, 2026 17:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants