Skip to content

v0.6.1

Choose a tag to compare

@ripsline ripsline released this 04 Jun 23:34
· 72 commits to main since this release
v0.6.1
cf1d36b

Signature Verification Hardening

The previous verification code downloaded the correct signing keys and GPG did verify signatures against them, so installed software was genuine. But the verification logic had two gaps: signatures were accepted from any key in the shared keyring (not just the intended signer), and the fingerprint checks only confirmed the key was downloaded, not that it was used to sign the release. This release closes both gaps.

  • All three verification paths (self-update, Bitcoin Core, LND) now use a shared helper with ephemeral GPG keyrings, VALIDSIG primary-fingerprint matching, and distinct-signer counting
  • The GPG exit code is no longer trusted on any path
  • 5 signing-key fingerprints corrected to primary-key values
  • Download pipelines use random working directories instead of fixed /tmp paths
  • 6-case test suite covering pinned-key acceptance, tampered file rejection, unpinned-key rejection, duplicate-signer deduplication, multi-signer threshold, and subkey-to-primary resolution

What's Changed

Full Changelog: v0.6.0...v0.6.1