Skip to content

fix(desktop): verify signed native runtime libraries - #170

Merged
WellDunDun merged 1 commit into
mainfrom
codex/signed-native-runtime
Sep 2, 2026
Merged

WellDunDun merged 1 commit into
mainfrom
codex/signed-native-runtime

Conversation

@WellDunDun

Copy link
Copy Markdown
Collaborator

Cause

Signed macOS release smoke reached recovery because code signing rewrites the DuckDB native libraries and report-worker executable, while the runtime manifest allowed only the main sidecar to change.

Fix

Use one explicit allowlist in manifest generation and validation for bundled native executables and DuckDB libraries. Keep verified signed-bundle trust, exact hashes for other files, executable permissions, and byte-identical source-to-installed-copy checks. No release security gates are disabled.

Verification

  • Reproduced recovery in a locally Developer ID-signed app; technical detail confirmed an invalid runtime manifest.
  • Compared pre-signing hashes with signed files to identify every changed artifact.
  • Added regression coverage for native-library/report-worker signing changes, unsigned rejection, copy tampering, and ordinary-code exclusion.
  • Desktop tests/typecheck and full source lint/format checks pass.
  • Full local signed packaged smoke is running; release notarization and both Mac architecture gates remain required.

@coderabbitai

coderabbitai Bot commented Sep 2, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 18 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Team

Run ID: 2b548b73-74d9-4c5a-b3e1-ebb87bc288ec

📥 Commits

Reviewing files that changed from the base of the PR and between d11e80f and 0cfab26.

📒 Files selected for processing (4)
  • .changeset/signed-native-runtime.md
  • apps/desktop/scripts/build-sidecar.ts
  • apps/desktop/src/main/runtime-install.test.ts
  • apps/desktop/src/main/runtime-integrity.ts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@WellDunDun

Copy link
Copy Markdown
Collaborator Author

Local signed verification is now complete: the full packaged smoke passed against a Developer ID-signed, hardened-runtime macOS app. Deep/strict codesign verification passed. The actual signed runtime fails an untrusted pre-signing hash check and passes only with verified signing trust, as intended. Desktop suite: 110 tests, 0 failures; typecheck and full source lint/format passed. Local diagnostic notarization was disabled only in an untracked diagnostic build config; the committed release pipeline still requires notarization and both signed Mac smoke jobs.

@WellDunDun
WellDunDun merged commit e95078c into main Sep 2, 2026
14 checks passed
@WellDunDun
WellDunDun deleted the codex/signed-native-runtime branch September 2, 2026 12:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant