Skip to content

SSMS installer: the VSIX signature check has no tests #618

Description

@erikdarlingdata

Claude posting for Erik Darling

The Claude review of #612 skipped while the PR was open, because the review gate was down (fixed by #617). The review ran after the merge and found no blocking problems. It found one gap: no test covers the VSIX signature check.

CheckVsix and FindUncovered in src/PlanViewer.Ssms.Installer/Program.cs decide whether a signed installer accepts a VSIX. The only end-to-end check is the --verify-only run in release.yml, and that run covers only a VSIX with a real SignPath signature that passes.

Cases that need a test:

  • a VSIX with an extra entry that the signature does not cover
  • a VSIX signed with a different certificate
  • an unsigned VSIX
  • a VSIX with a part that changed after signing
  • ZIP entry names that differ only in case
  • unsigned relationship parts, extra certificate parts, and the origin-relationship exception

The installer targets .NET Framework 4.7.2, and tests/PlanViewer.Core.Tests targets .NET 10. A test needs a small .NET Framework test project, or a script that builds these packages with System.IO.Packaging.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions