Skip to content

updates: Authenticate signed releases - #223

Open
BenWestgate wants to merge 1 commit into
masterfrom
206-authenticated-updates
Open

BenWestgate wants to merge 1 commit into
masterfrom
206-authenticated-updates

Conversation

@BenWestgate

@BenWestgate BenWestgate commented Sep 19, 2026 •

Copy link
Copy Markdown
Owner

What

Replace the mutable-branch updater with signed annotated release tags verified against a pinned release key in an isolated GnuPG home. Reject unsigned tags and downgrades, and execute only the authenticated tag archive. The review follow-up uses the newer of the installed script version and persisted authenticated release state for downgrade protection.

Why

Updating by cloning and immediately executing a mutable branch does not authenticate the exact code being installed.

Closes #206. The separate first-install bootstrap boundary is tracked by #325.

Testing

  • git diff --check
  • bash -n bails/.local/bin/update-cipherstick bails/.local/bin/bails-menu
  • release-key file fingerprint matches 89E6BEF5A4F51B71CA8FAA35A9ACCFC9F87CB111
  • version-selection check preserves the newer recorded release version

@chatgpt-codex-connector

This comment has been minimized.

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

crACK f656e2c

Comment thread bails/.local/bin/update-cipherstick
@BenWestgate

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f656e2cfa3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread bails/.local/bin/update-cipherstick Outdated
Comment thread bails/.local/bin/update-cipherstick
Comment thread bails/.local/bin/update-cipherstick
@BenWestgate
BenWestgate force-pushed the 206-authenticated-updates branch from f656e2c to db7e7a2 Compare September 21, 2026 08:33
@chatgpt-codex-connector

This comment has been minimized.

@BenWestgate
BenWestgate force-pushed the 206-authenticated-updates branch from db7e7a2 to 117b9d4 Compare September 21, 2026 09:03
@chatgpt-codex-connector

This comment has been minimized.

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI-generated review (Claude), posted at the maintainer's request.

Concept ACK 117b9d4. Needs a release plan before merge.

  • No v* tags exist on the remote. Once merged, "Update CipherStick" always fails closed, and the README no longer gives new users any install path. Publish a signed v* tag as part of landing this.
  • Key expiry: the pinned key expires 2028-01-29. git verify-tag rejects EXPKEYSIG, so every install stops updating then unless a release before that date ships the key with extended expiry (same fingerprint, so the pin still holds).
  • The script checks the tag name against the object's tag header, uses an isolated GNUPGHOME and dpkg --compare-versions, and only records state after success. All good.
  • Conflicts with #202, #226 and #230 (b/README).

Comment thread README.md Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c97d759336

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread bails/.local/bin/update-cipherstick Outdated
@BenWestgate
BenWestgate force-pushed the 206-authenticated-updates branch from c97d759 to 53f2ff3 Compare October 1, 2026 09:45
@chatgpt-codex-connector

This comment has been minimized.

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current-head security re-review: NACK 53f2ff3 on the existing prerelease-ordering P2. The earlier signed-tag alias and premature release-state findings are fixed: the ref name is bound to the signed tag header, and b --update waits for the persistent copy before state advances. Bootstrap docs also need the first-release transition handled as noted in-thread.

@chatgpt-codex-connector

This comment has been minimized.

1 similar comment
@chatgpt-codex-connector

This comment has been minimized.

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Codex current-head review at 6ac875d: no findings. The bootstrap guidance now matches the pre-release reality, and signed prerelease/final ordering is consistent across selection and rollback checks.

Replace mutable-branch self-updates with signed annotated release tags verified against the pinned CipherStick release key in an isolated keyring. Preserve the current Tails 7 Console launcher, clone command fix, and current installation requirements while replaying the focused update hardening onto current master.

Closes #206
@BenWestgate
BenWestgate force-pushed the 206-authenticated-updates branch from 6ac875d to 8d63dc2 Compare October 6, 2026 10:58
@chatgpt-codex-connector

This comment has been minimized.

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Codex current-head review at 8d63dc2: no findings in the authenticated-update scope. Signed annotated tags are bound to their tag names, verified in an isolated keyring against the pinned release key, ordered consistently, and executed from the authenticated archive. First-install bootstrap authentication is intentionally outside this PR and is now tracked by #325.

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI-assisted current-head security verification: ACK 8d63dc2 for issue #206. The menu no longer clones/executes a mutable default branch. update-cipherstick imports only the installed release key into a fresh 0700 GnuPG home, requires its primary fingerprint to equal the pinned 40-hex fingerprint, considers only annotated v* tags whose embedded tag name matches the ref and whose signature verifies in that isolated keyring, selects the highest authenticated version, archives that exact tag, and advances persisted downgrade state only after the authenticated payload succeeds. The installed-script version and persisted authenticated state are both considered when refusing rollback. Exact-head Lint CI, Dependency Review, and CodeQL are green; no review threads are unresolved. The distinct first-install trust bootstrap is correctly left to #325/#327 and is not a remaining #206 update-path bypass. No blocker found.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Authenticate CipherStick releases before update

1 participant