fix(release): separate macOS integrity boundaries - #536
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #498
Why
The release archive hash and the installed macOS binary hash represent different trust boundaries. The installer verifies
SHA256SUMSbefore extraction, then macOS may mutate the binary through quarantine clearing and ad-hoc re-signing. Acceptance must verify archive integrity before extraction and signature validity after installation without treating byte equality as a stable signature-validity boundary.What changed
ocsourceable for the harness while preserving direct execution behaviorEvidence
bash script/oc-install-boundary.test.sh→ 9 passed, 0 failedbash script/oc-macos-acceptance.test.sh→ 6 passed, 0 failedbash -n oc script/oc-install-boundary.test.sh script/oc-macos-acceptance.test.shgit diff --checkb48fc5610e77de4978328f3361b44d7be6ff7658d9fb5ff6b69f8738967f0694Checklist
codesign --verify --strict