Commit ec9ede3
committed
doc/plans: Update OCI sealing spec (kernel sigs, flattened layers)
The biggest goal here is support for Linux kernel-native fsverity
signatures to be attached to layers, which enables integration with
IPE.
Add support for a fully separate OCI "composefs signature" artifact
which can be attached to an image.
Add standardized-erofs-meta.md as a placeholder document outlining the
goal of standardizing composefs EROFS serialization across implementations
(canonical model: tar -> dumpfile -> EROFS).
Assisted-by: OpenCode (Claude Opus 4.5)
Signed-off-by: Colin Walters <walters@verbum.org>1 parent 8359fbf commit ec9ede3
2 files changed
Lines changed: 520 additions & 85 deletions
0 commit comments