Sign the executables Velopack generates - #621
Merged
Merged
Conversation
vpk pack generates Setup.exe, and the launcher (PerformanceStudio.exe) and Update.exe at the root of Portable.zip. They did not exist when the App signing request ran, so every release through v1.28.0 shipped them unsigned while the app payload was signed. release.yml now packs before the release is created, sends the three generated executables to SignPath in one more request (the new SignTemplate artifact configuration), writes the signed files back, and fails the job if any .exe in the Velopack output is still unsigned. The two .nupkg members stay unsigned, because releases.win.json pins the .nupkg's SHA256 and the delta is built against it. The scripts come from PerformanceMonitor (its #3288), with only the docstrings, usage text and --repo default changed. release-signatures.yml runs their self-tests on any PR that touches them, as in PerformanceMonitor. Also write SHA256SUMS.txt with LF line endings and no BOM, in release.yml and nightly.yml. Out-File wrote CRLF, and sha256sum -c and shasum -c then report every file as missing. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019tS6P95Dtzs4aeMpb1xqzX
|
Reviewed the workflow changes and skimmed the two Python scripts. I found nothing blocking.
Minor: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
vpk packcreates three executables:PerformanceStudio-win-Setup.exe, and the launcher (PerformanceStudio.exe) andUpdate.exeat the root ofPerformanceStudio-win-Portable.zip. The App signing request runs beforevpk pack, so it never sees them. Every release through v1.28.0 shipped these three files unsigned. New Windows users can get an "unknown publisher" warning when they run the installer.This PR signs them after packing, the same way PerformanceMonitor does (its #3288). PerformanceMonitor shipped this in v3.7.1 and v3.8.0.
Before the next release, add the
SignTemplateartifact configuration to the PerformanceStudio project on signpath.io. It is the same XML that PerformanceMonitor uses:**/*.exeand**/*.dllwithmin-matches="0", Authenticode. If the configuration is missing, the new signing step fails, and the release stops before anything is published.A release run now waits for three SignPath approvals: the App, then these three files, then the SSMS files.
Changes
.github/workflows/release.ymlvpk packnow runs beforeCreate release, right after the App signing. The GitHub release is still created only after all signing is done.vpk packdo four things:SignTemplateconfiguration..exein the Velopack output is unsigned.SHA256SUMS.txtis now written with LF line endings and no BOM (see below)..github/scripts/postpack_signing.py(new):collectstagesSetup.exeand every.exeat the root ofPortable.zip.applyreplacesSetup.exe, and rebuildsPortable.zipentry by entry. Every entry it does not replace keeps its original bytes..github/scripts/verify_release_signatures.py(new):--verify-diris the release guard. It also has a tag mode that checks a published release, and reads only the byte ranges it needs.Squirrel.exeinside a.nupkg.releases.win.jsonrecords each.nupkg's SHA256, and the delta is built against those bytes. So the.nupkgmust not change after packing..github/workflows/release-signatures.yml(new):.github/workflows/nightly.yml: the sameSHA256SUMS.txtfix.Both scripts are copied from PerformanceMonitor. Only their docstrings, usage text, issue references and the
--repodefault changed. The workflow comes from PerformanceMonitor too. It pinsactions/checkoutto the same SHA as the other Studio workflows.The checksum file
Out-Filewrites CRLF on Windows.sha256sum -candshasum -cthen read the\ras part of each file name, and report every file as missing. I reproduced this locally with GNUsha256sum8.32 andshasum: a CRLF line fails with "No such file or directory", and the same line with LF passes. The v1.28.0 file is 572 bytes: the 6 lines add up to 560 characters plus 12 line-end bytes, so it uses CRLF. The new line in both workflows writes LF, and both tools accept the result.Test Plan
Setup.exe,Portable.zip, both 1.28.0 packages, and the 1.27.0 full package thatvpk downloadleaves in the folder.Setup.exe,PerformanceStudio.exeandUpdate.exe. It allows the 2 members in each.nupkg.collectstages those 3 files.applythen wrote them back: "Setup.exesigned", and "Portable.ziprebuilt with 2 signed member(s), 441 entries preserved".applyfails and leavesPortable.zipbyte-for-byte unchanged.Portable.zipwith .NET'sZipFile. Both have 441 files. OnlyPerformanceStudio.exeandUpdate.exediffer.Setup.exeand launchers as signed.release-signaturespasses on this PR.SignTemplateon signpath.io before the next release.Setup.exe,PerformanceStudio.exeandUpdate.exeare signed: run the "Release signatures" workflow by hand with the new tag.A pull request cannot test the SignPath request itself, or how the real signatures get written back and uploaded. Only a release run does those things. PerformanceMonitor's v3.7.1 and v3.8.0 went through the same steps, with the same SignPath configuration.
Generated with Claude Code
https://claude.ai/code/session_019tS6P95Dtzs4aeMpb1xqzX