Repository navigation
feat: glaze/signing — Ed25519 artifact signing for self-updating apps - #11
Merged
Merged
Conversation
The Tauri-updater trust property for Glaze apps: the update artifact is signed with an Ed25519 key whose private half never lives on the distribution server, and the public half is pinned inside the installed app — a compromised release server can serve stale/corrupt artifacts but never an accepted malicious update. - glaze/signing: keygen (optional AES-256-CBC private-key encryption), sign-file (Ed25519 over 'sha256:<hex>' of the artifact — streaming- friendly for large files), verify-signature (never raises on a bad signature), sha256-file/string, public-key fingerprint — all via the system openssl CLI, zero compiled dependencies - CLI: raco glaze updater-keygen / update-sign / update-verify - 14 tests: roundtrip (incl. empty artifact), tamper, wrong-key, expected-sha256 gate, encrypted-keygen roundtrip Note: OpenSSL 3.x key encryption uses pkcs8 -topk8 -v2 <cipher>; the public key is derived from the unencrypted temp key before encryption (deriving it from the encrypted PEM would need -passin on every later use).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Tauri-updater trust property for Glaze apps, as a standalone module: the
update artifact is signed with an Ed25519 key whose private half never
lives on the distribution server, and the public half is pinned inside
the installed app — a compromised release server or CDN can serve stale
or corrupted artifacts, but never an accepted malicious update.
glaze/signing(openssl CLI, zero compiled deps, same approach asglaze/license):signing-keygen(optional AES-256-CBC private-keyencryption),
sign-file(Ed25519 over"sha256:<hex>"of the artifact— streaming-friendly for large files),
verify-signature(returns #f,never raises on a bad signature), plus sha256 helpers and fingerprints.
raco glaze updater-keygen/update-sign/update-verify.rejection, expected-sha256 gate, encrypted-keygen roundtrip.
Companion to the gptp-studio in-app self-updater (downloads the new deb,
verifies this signature against the pinned public key, then hands off to
apt/pkexec).
Test plan
raco test glaze-test/— 248 passed (14 new)INVALID (exit 1)
pkcs8 -topk8 -v2 <cipher>(
pkey -aes-256-cbcrejects combined cipher+pass on 3.5)