Require the selected subject's confined mesh to match recorded bytes.
The saved source path is provenance only, never an input to file access.
Source code in tit/mesh_identity.py
| def verify_subject_mesh(pm, subject: str, expected_sha256: str) -> Path:
"""Require the selected subject's confined mesh to match recorded bytes.
The saved source path is provenance only, never an input to file access.
"""
if not isinstance(expected_sha256, str) or not re.fullmatch(
r"[0-9a-f]{64}", expected_sha256
):
raise ValueError("Recorded head mesh SHA-256 is invalid.")
try:
path = Path(
resolve_within(
pm.project_dir, str(Path(pm.m2m(subject)) / f"{subject}.msh")
)
)
except ValueError as exc:
raise ValueError("Replay head mesh escapes the selected project.") from exc
if not path.is_file():
raise ValueError("The recorded candidate's subject head mesh is missing.")
if sha256_file(path) != expected_sha256:
raise ValueError(
"The subject head mesh has changed since candidate recording; replay is refused."
)
return path
|