Skip to content

Commit ec9ede3

Browse files
committed
doc/plans: Update OCI sealing spec (kernel sigs, flattened layers)
The biggest goal here is support for Linux kernel-native fsverity signatures to be attached to layers, which enables integration with IPE. Add support for a fully separate OCI "composefs signature" artifact which can be attached to an image. Add standardized-erofs-meta.md as a placeholder document outlining the goal of standardizing composefs EROFS serialization across implementations (canonical model: tar -> dumpfile -> EROFS). Assisted-by: OpenCode (Claude Opus 4.5) Signed-off-by: Colin Walters <walters@verbum.org>
1 parent 8359fbf commit ec9ede3

2 files changed

Lines changed: 520 additions & 85 deletions

File tree

0 commit comments

Comments
 (0)