From 3017f50de68c70c8f9f298f3eb1b5e257bda5a3e Mon Sep 17 00:00:00 2001 From: Zhengchao An Date: Sat, 5 Sep 2026 12:45:19 +0800 Subject: [PATCH] fix(connect): restore signature validation order --- rustfs/src/connect/offline/enrollment.rs | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/rustfs/src/connect/offline/enrollment.rs b/rustfs/src/connect/offline/enrollment.rs index 9fcc04e97..b767d272c 100644 --- a/rustfs/src/connect/offline/enrollment.rs +++ b/rustfs/src/connect/offline/enrollment.rs @@ -380,6 +380,12 @@ impl OfflineEnrollment { return Err(EnrollmentError::MalformedDocument); } let issued_at = parse_timestamp(&routing.issued_at)?; + + // The frozen decision order classifies the top-level signature before + // parsing any trust-link routing fields. Otherwise a malformed first + // link could mask a malformed artifact signature with DOCUMENT_MALFORMED. + let signature = decode_signature(&envelope.signature)?; + let first = routing.trust_chain.first().ok_or(EnrollmentError::MalformedDocument)?; let first_bytes = decode_document_bytes(&first.bytes)?; let first_routing: TrustLinkRouting = @@ -388,10 +394,6 @@ impl OfflineEnrollment { return Err(EnrollmentError::MalformedDocument); } - // Only after the document can route verification do we classify the - // top-level signature spelling and algorithm. - let signature = decode_signature(&envelope.signature)?; - // Steps 3 to 5. let connect_key = verify_trust_chain( &routing.trust_chain,