feat: signature enforcement, strict ed25519, and self-update TOCTOU fix#50
Merged
Conversation
Four hardening items closing the trust story: - Manifests can declare '"signed": true': a missing .sig then ABORTS the install instead of falling back to the legacy unsigned path - closing the hole where a compromised repository simply omits signatures. Every Project-Colony app has signed releases as of today, so the flag is safe to adopt ecosystem-wide. - ed25519 verification uses verify_strict (rejects malleable and non-canonical signatures - the recommended verifier for update contexts). - apply_launcher_update wrote the update by re-COPYING the staged file after verifying bytes read earlier: a swap between read and copy would install bytes the signature check never saw. It now writes the exact verified buffer. - Release-asset downloads no longer attach the OAuth token: they are public endpoints, and credentials should not be presented where none are needed (API calls keep using the token for rate limits).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Durcissement final de la chaîne de confiance (autonomie validée par Lin)
"signed": truedans le manifest - une signature manquante ABORTE l'install au lieu du fallback legacy non-signé. Ferme le trou « repo compromis qui omet les signatures ». Toutes les apps de l'org ont des releases signées depuis aujourd'hui → adoption sans risque.verify_strict- rejette les signatures malléables/non-canoniques (verifier recommandé pour les contextes d'update).Validation
105 tests verts (nouveau test du parse
signed), clippy 0, fmt OK.