Repository navigation
updates: Authenticate signed releases - #223
BenWestgate wants to merge 1 commit into
Conversation
This comment has been minimized.
This comment has been minimized.
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f656e2cfa3
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
f656e2c to
db7e7a2
Compare
This comment has been minimized.
This comment has been minimized.
db7e7a2 to
117b9d4
Compare
This comment has been minimized.
This comment has been minimized.
BenWestgate
left a comment
There was a problem hiding this comment.
AI-generated review (Claude), posted at the maintainer's request.
Concept ACK 117b9d4. Needs a release plan before merge.
- No
v*tags exist on the remote. Once merged, "Update CipherStick" always fails closed, and the README no longer gives new users any install path. Publish a signedv*tag as part of landing this. - Key expiry: the pinned key expires 2028-01-29.
git verify-tagrejects EXPKEYSIG, so every install stops updating then unless a release before that date ships the key with extended expiry (same fingerprint, so the pin still holds). - The script checks the tag name against the object's
tagheader, uses an isolated GNUPGHOME anddpkg --compare-versions, and only records state after success. All good. - Conflicts with #202, #226 and #230 (
b/README).
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c97d759336
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
c97d759 to
53f2ff3
Compare
This comment has been minimized.
This comment has been minimized.
BenWestgate
left a comment
There was a problem hiding this comment.
Current-head security re-review: NACK 53f2ff3 on the existing prerelease-ordering P2. The earlier signed-tag alias and premature release-state findings are fixed: the ref name is bound to the signed tag header, and b --update waits for the persistent copy before state advances. Bootstrap docs also need the first-release transition handled as noted in-thread.
This comment has been minimized.
This comment has been minimized.
1 similar comment
This comment has been minimized.
This comment has been minimized.
BenWestgate
left a comment
There was a problem hiding this comment.
Codex current-head review at 6ac875d: no findings. The bootstrap guidance now matches the pre-release reality, and signed prerelease/final ordering is consistent across selection and rollback checks.
Replace mutable-branch self-updates with signed annotated release tags verified against the pinned CipherStick release key in an isolated keyring. Preserve the current Tails 7 Console launcher, clone command fix, and current installation requirements while replaying the focused update hardening onto current master. Closes #206
6ac875d to
8d63dc2
Compare
This comment has been minimized.
This comment has been minimized.
BenWestgate
left a comment
There was a problem hiding this comment.
Codex current-head review at 8d63dc2: no findings in the authenticated-update scope. Signed annotated tags are bound to their tag names, verified in an isolated keyring against the pinned release key, ordered consistently, and executed from the authenticated archive. First-install bootstrap authentication is intentionally outside this PR and is now tracked by #325.
BenWestgate
left a comment
There was a problem hiding this comment.
AI-assisted current-head security verification: ACK 8d63dc2 for issue #206. The menu no longer clones/executes a mutable default branch. update-cipherstick imports only the installed release key into a fresh 0700 GnuPG home, requires its primary fingerprint to equal the pinned 40-hex fingerprint, considers only annotated v* tags whose embedded tag name matches the ref and whose signature verifies in that isolated keyring, selects the highest authenticated version, archives that exact tag, and advances persisted downgrade state only after the authenticated payload succeeds. The installed-script version and persisted authenticated state are both considered when refusing rollback. Exact-head Lint CI, Dependency Review, and CodeQL are green; no review threads are unresolved. The distinct first-install trust bootstrap is correctly left to #325/#327 and is not a remaining #206 update-path bypass. No blocker found.
What
Replace the mutable-branch updater with signed annotated release tags verified against a pinned release key in an isolated GnuPG home. Reject unsigned tags and downgrades, and execute only the authenticated tag archive. The review follow-up uses the newer of the installed script version and persisted authenticated release state for downgrade protection.
Why
Updating by cloning and immediately executing a mutable branch does not authenticate the exact code being installed.
Closes #206. The separate first-install bootstrap boundary is tracked by #325.
Testing
git diff --checkbash -n bails/.local/bin/update-cipherstick bails/.local/bin/bails-menu89E6BEF5A4F51B71CA8FAA35A9ACCFC9F87CB111