Repository navigation
fix(desktop): verify signed native runtime libraries - #170
Conversation
|
Warning Review limit reachedNext included review available in 18 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Team Run ID: 📒 Files selected for processing (4)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Local signed verification is now complete: the full packaged smoke passed against a Developer ID-signed, hardened-runtime macOS app. Deep/strict codesign verification passed. The actual signed runtime fails an untrusted pre-signing hash check and passes only with verified signing trust, as intended. Desktop suite: 110 tests, 0 failures; typecheck and full source lint/format passed. Local diagnostic notarization was disabled only in an untracked diagnostic build config; the committed release pipeline still requires notarization and both signed Mac smoke jobs. |
Cause
Signed macOS release smoke reached recovery because code signing rewrites the DuckDB native libraries and report-worker executable, while the runtime manifest allowed only the main sidecar to change.
Fix
Use one explicit allowlist in manifest generation and validation for bundled native executables and DuckDB libraries. Keep verified signed-bundle trust, exact hashes for other files, executable permissions, and byte-identical source-to-installed-copy checks. No release security gates are disabled.
Verification