Skip to content

feat: glaze/signing — Ed25519 artifact signing for self-updating apps - #11

Merged
turinglambdaai merged 1 commit into
mainfrom
feat/self-update-signing
Sep 29, 2026
Merged

turinglambdaai merged 1 commit into
mainfrom
feat/self-update-signing

Conversation

@turinglambdaai

Copy link
Copy Markdown
Owner

Summary

Tauri-updater trust property for Glaze apps, as a standalone module: the
update artifact is signed with an Ed25519 key whose private half never
lives on the distribution server, and the public half is pinned inside
the installed app — a compromised release server or CDN can serve stale
or corrupted artifacts, but never an accepted malicious update.

  • glaze/signing (openssl CLI, zero compiled deps, same approach as
    glaze/license): signing-keygen (optional AES-256-CBC private-key
    encryption), sign-file (Ed25519 over "sha256:<hex>" of the artifact
    — streaming-friendly for large files), verify-signature (returns #f,
    never raises on a bad signature), plus sha256 helpers and fingerprints.
  • CLI: raco glaze updater-keygen / update-sign / update-verify.
  • 14 tests: roundtrip (incl. empty artifact), tamper, wrong-key
    rejection, expected-sha256 gate, encrypted-keygen roundtrip.

Companion to the gptp-studio in-app self-updater (downloads the new deb,
verifies this signature against the pinned public key, then hands off to
apt/pkexec).

Test plan

  • raco test glaze-test/ — 248 passed (14 new)
  • CLI roundtrip: keygen → sign → verify VALID; tampered artifact →
    INVALID (exit 1)
  • OpenSSL 3.x key encryption via pkcs8 -topk8 -v2 <cipher>
    (pkey -aes-256-cbc rejects combined cipher+pass on 3.5)

The Tauri-updater trust property for Glaze apps: the update artifact is
signed with an Ed25519 key whose private half never lives on the
distribution server, and the public half is pinned inside the installed
app — a compromised release server can serve stale/corrupt artifacts
but never an accepted malicious update.

- glaze/signing: keygen (optional AES-256-CBC private-key encryption),
  sign-file (Ed25519 over 'sha256:<hex>' of the artifact — streaming-
  friendly for large files), verify-signature (never raises on a bad
  signature), sha256-file/string, public-key fingerprint — all via the
  system openssl CLI, zero compiled dependencies
- CLI: raco glaze updater-keygen / update-sign / update-verify
- 14 tests: roundtrip (incl. empty artifact), tamper, wrong-key,
  expected-sha256 gate, encrypted-keygen roundtrip

Note: OpenSSL 3.x key encryption uses pkcs8 -topk8 -v2 <cipher>; the
public key is derived from the unencrypted temp key before encryption
(deriving it from the encrypted PEM would need -passin on every later
use).
@turinglambdaai
turinglambdaai merged commit 00f11e2 into main Sep 29, 2026
9 checks passed
@turinglambdaai
turinglambdaai deleted the feat/self-update-signing branch September 29, 2026 15:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant