v0.6.1
Signature Verification Hardening
The previous verification code downloaded the correct signing keys and GPG did verify signatures against them, so installed software was genuine. But the verification logic had two gaps: signatures were accepted from any key in the shared keyring (not just the intended signer), and the fingerprint checks only confirmed the key was downloaded, not that it was used to sign the release. This release closes both gaps.
- All three verification paths (self-update, Bitcoin Core, LND) now use a shared helper with ephemeral GPG keyrings, VALIDSIG primary-fingerprint matching, and distinct-signer counting
- The GPG exit code is no longer trusted on any path
- 5 signing-key fingerprints corrected to primary-key values
- Download pipelines use random working directories instead of fixed
/tmppaths - 6-case test suite covering pinned-key acceptance, tampered file rejection, unpinned-key rejection, duplicate-signer deduplication, multi-signer threshold, and subkey-to-primary resolution
What's Changed
Full Changelog: v0.6.0...v0.6.1