Repository navigation
Commit 5da84f0
committed
build: the app ships the signature verifier — installed, checked, and asked directly
The module from the previous commit does nothing until a built app can load
it. scripts/extension-signature.mjs puts it there, and proves it works.
install <app-code-folder>
Copies three files to node_modules/@vscode/vsce-sign in the BUILT app: the
name the editor imports. Nothing in the editor's source is patched, so there
is nothing to re-apply on a Code-OSS bump — the same move as
strip-proprietary.mjs. build-macos.sh passes --replace: the checkout decides
what a build ships. make-dmg.sh does not: an app that already carries a
LevelCode verifier keeps it, because the keys an app trusts are its build's
and not the signer's. A module of that name that is not ours is an error.
check <app-code-folder>
Fails unless the built editor still names @vscode/vsce-sign, the name
resolves to our module from the very bundles that name it, and the module —
imported by that name from those folders, in a process of its own — accepts
a real Open VSX package and refuses it with one byte changed. Both
build-macos.sh and make-dmg.sh run it: an upstream change that would bring
"not executed" back fails the build, and an app that cannot verify is not
signed.
smoke <LevelCode.app>
Asks the app. Its own command line installs one four-kilobyte extension into
throwaway folders, as a command-line process with no window, and the app's
log must say the signature verified. release.yml runs it on each arch after
the build. It fails only on the app's own words; a registry that cannot be
reached is a warning.
registry
The watch that pinning needs. The day Open VSX signs with another key, every
LevelCode already installed refuses what the new key signs, until a release
carries it. This asks the registry which key its newest extensions name and
verifies some of them for real. Exit 1 is evidence: a key that is not pinned,
signatures that stopped verifying, or no signatures at all. Not reaching the
registry is a warning, or exit 2 with --strict. release.yml runs it in the
test gate, before the hour of macOS build.
docs/EXTENSION-SIGNATURES.md is the whole account: what a pass means, what a
user sees for each refusal, how the pinned key was checked, and the runbook for
the two days this will need attention — Open VSX changing its key, and a
Code-OSS bump. The limits are listed there: "Install Anyway" and
extensions.verifySignature are still upstream's; the dialog shows only the
result code, with the reason in the log at trace level; its "Learn More" still
opens Microsoft's page.
Checked against the real thing, short of a rebuild. The code folder of the
shipped 1.3.1 app was copied and run by the installed executable:
as shipped check fails; smoke fails with "not executed" — the bug
after install check passes; smoke passes; Claude Code, EditorConfig
and GitLens install, each with "Success. Executed: true"
in the app's own log
another key pinned check fails; smoke fails with 'Untrusted'; nothing is
installed
and `registry` against open-vsx.org itself: all 30 newest extensions name the
pinned key, and two were downloaded and verified.
NOT checked: a gulp build with this step in it, and the smoke step on a GitHub
runner. The step fails a build only when the app itself reports a signature
failure; anything else it cannot make sense of is a warning.
Tests: the suite goes from 31 to 56 cases. The app, the registry and the
network are stand-ins there, and what the script does with their answers is
what is pinned. 63 mutations of the script, the two shell scripts, the
workflow, the fixtures and the runbook's heading: each fails a case. 50 suites
pass on macOS (Node 24) and in a Linux container (Node 18).1 parent a57e99f commit 5da84f0
10 files changed
Lines changed: 1271 additions & 10 deletions
File tree
- .github/workflows
- docs
- modules/extension-signature/test
- scripts
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
41 | 41 | | |
42 | 42 | | |
43 | 43 | | |
44 | | - | |
| 44 | + | |
| 45 | + | |
45 | 46 | | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
46 | 54 | | |
47 | 55 | | |
48 | 56 | | |
| |||
85 | 93 | | |
86 | 94 | | |
87 | 95 | | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
88 | 102 | | |
89 | 103 | | |
90 | 104 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
18 | 18 | | |
19 | 19 | | |
20 | 20 | | |
| 21 | + | |
21 | 22 | | |
22 | 23 | | |
23 | 24 | | |
| |||
39 | 40 | | |
40 | 41 | | |
41 | 42 | | |
| 43 | + | |
42 | 44 | | |
43 | | - | |
| 45 | + | |
44 | 46 | | |
45 | 47 | | |
46 | 48 | | |
| |||
82 | 84 | | |
83 | 85 | | |
84 | 86 | | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
85 | 112 | | |
86 | 113 | | |
87 | 114 | | |
| |||
189 | 216 | | |
190 | 217 | | |
191 | 218 | | |
192 | | - | |
| 219 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
34 | 34 | | |
35 | 35 | | |
36 | 36 | | |
| 37 | + | |
37 | 38 | | |
38 | 39 | | |
39 | 40 | | |
| |||
59 | 60 | | |
60 | 61 | | |
61 | 62 | | |
62 | | - | |
| 63 | + | |
63 | 64 | | |
64 | 65 | | |
65 | 66 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
15 | 20 | | |
16 | 21 | | |
17 | 22 | | |
| |||
25 | 30 | | |
26 | 31 | | |
27 | 32 | | |
28 | | - | |
| 33 | + | |
| 34 | + | |
29 | 35 | | |
30 | 36 | | |
0 commit comments