Skip to content

Remove interop code as much as possible - #164

Open
virzak wants to merge 1 commit into
vcsjones:mainfrom
virzak:CsWin32
Open

virzak wants to merge 1 commit into
vcsjones:mainfrom
virzak:CsWin32

Conversation

@virzak

@virzak virzak commented Jul 5, 2022 •

Copy link
Copy Markdown

Replaces most of the hand-written P/Invoke declarations in AzureSign.Core with CsWin32-generated ones (NativeMethods.txt). Interop/crypt32.cs is gone, and Interop/mssign32.cs shrinks to the pieces the Win32 metadata still lacks: SIGNER_SIGN_EX3_PARAMS, APPX_SIP_CLIENT_DATA and the managed sign callback delegate. None of those structures is declared in the Windows SDK headers either (see microsoft/win32metadata#2307).

Notable details

  • SignerSignEx3 is called through CsWin32's raw extern, so the ASCII timestamp OID is pinned once and the same pointer goes to both the call and the Appx SIP parameters. SIGNER_SIGN_EX3_PARAMS stays blittable, which the Appx SIP path depends on.
  • SIGNER_DIGEST_SIGN_INFO uses the generated (V2) layout with cbSize = sizeof(...) and dwDigestSignChoice = SIGNER_DIGEST_SIGN, replacing the hand-written V1 struct.
  • MemoryCertificateStore holds an HCERTSTORE. CA1416 is suppressed in that file because CsWin32 marks the crypt32 store APIs Windows-only, and this library is Windows-only.

Testing

  • New MSIX signing tests (signtarget.msix, RSA and ECDSA, with and without an RFC 3161 timestamp) cover the Appx SIP path, which previously had no tests.
  • dotnet test passes on x64 (56/56). CI only covers x64 and ARM64, so I also ran the core tests as x86 (dotnet test -a x86, 53/53).
  • Signed packages carry the signer and a DigiCert timestamp, and verify the same way as packages signed by upstream main.

Generated with Claude Code

Comment thread test/AzureSign.Core.Tests/AlgorithmTranslatorTests.cs
@virzak
virzak force-pushed the CsWin32 branch 5 times, most recently from 771ffd4 to ae57a25 Compare February 7, 2025 17:45
@virzak

virzak commented Feb 7, 2025

Copy link
Copy Markdown
Author

Rebased

@virzak
virzak force-pushed the CsWin32 branch 2 times, most recently from 7bebc71 to 488e3bb Compare September 11, 2026 22:14
Generate the crypt32 and mssign32 P/Invokes with CsWin32 instead of
declaring them by hand. Interop/crypt32.cs is removed. mssign32.cs
keeps only SIGNER_SIGN_EX3_PARAMS, APPX_SIP_CLIENT_DATA and the
managed sign callback delegate, which the Win32 metadata lacks.

- Call the raw SignerSignEx3 extern and pin the ASCII timestamp OID
  once, so the same pointer reaches both the call and the Appx SIP
  parameters. SIGNER_SIGN_EX3_PARAMS must stay blittable: a managed
  field changes its in-memory layout and breaks every Appx/MSIX
  signature.
- Use the generated V2 SIGNER_DIGEST_SIGN_INFO with cbSize = sizeof
  and dwDigestSignChoice = SIGNER_DIGEST_SIGN, which is also correct
  on x86.
- Keep an HCERTSTORE in MemoryCertificateStore and suppress CA1416
  there, since the library is Windows-only.
- Add MSIX signing tests so the Appx SIP path has coverage.

Generated with Claude Code
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant