Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
68 commits
Select commit Hold shift + click to select a range
a264084
Add package broker policy inspector
CBenoit Aug 17, 2026
f51a63d
fix: validate broker policy response semantics
CBenoit Aug 18, 2026
608ada6
fix: avoid duplicate inspector heading
CBenoit Aug 18, 2026
55a3ec7
style: organize policy inspector imports
CBenoit Aug 18, 2026
ac7cd76
fix: consume published policy packages
CBenoit Sep 4, 2026
dca772f
fix: enforce boolean match cardinality
CBenoit Sep 4, 2026
5bae8c0
fix: preserve whitespace policy values
CBenoit Sep 4, 2026
fc1aadd
fix: distinguish structured policy not found
CBenoit Sep 4, 2026
fdc2560
fix: tighten policy validation and announcements
CBenoit Sep 4, 2026
3f40ca7
fix: adopt policy contract 2026.9.15
CBenoit Sep 15, 2026
bae8a9c
fix: adopt policy contract 2026.9.17
CBenoit Sep 17, 2026
4449b89
Add package policy editor
CBenoit Aug 29, 2026
4d15afa
Refresh policy contract packages
CBenoit Sep 3, 2026
f853796
Adopt renamed policy serializers
CBenoit Sep 3, 2026
c601b8a
Refresh final policy contract packages
CBenoit Sep 3, 2026
be0be57
Refresh hardened policy contract packages
CBenoit Sep 3, 2026
a8a01e3
Refresh policy draft schema contract
CBenoit Sep 3, 2026
39cfcc6
Refresh policy contract packages
CBenoit Sep 3, 2026
862a742
Harden package policy editor
CBenoit Sep 4, 2026
74e131a
Address policy editor review findings
CBenoit Sep 4, 2026
659f928
Harden policy editor draft tracking
CBenoit Sep 4, 2026
54f2fa1
Fix policy editor restart review findings
CBenoit Sep 4, 2026
602e043
Harden policy replacement contract mapping
CBenoit Sep 4, 2026
6b1c0d3
Harden policy replacement size limits
CBenoit Sep 4, 2026
01d0ef5
Fix elevated helper preflight boundary
CBenoit Sep 4, 2026
dd4d693
Keep localization fixture out of source sync
CBenoit Sep 4, 2026
4ffcfe1
Harden policy identity and finding presentation
CBenoit Sep 4, 2026
f5377f0
Guard invalid policy replacement identities
Copilot Sep 4, 2026
4484c69
Harden policy write eligibility
CBenoit Sep 4, 2026
448c2b7
Clarify policy acknowledgement framing
CBenoit Sep 4, 2026
c6ff54b
Bound post-ack helper exit wait
CBenoit Sep 4, 2026
1bcc713
Preserve initiating user across elevation
CBenoit Sep 4, 2026
39b4072
Fix policy elevation file information ABI
CBenoit Sep 4, 2026
2bef886
Announce policy write outcomes accessibly
CBenoit Sep 4, 2026
25a5649
Harden executable verification leases
CBenoit Sep 4, 2026
20d1c62
Harden policy write cancellation boundaries
CBenoit Sep 4, 2026
44b4194
Correct policy availability and missing-state UI
CBenoit Sep 15, 2026
6b37066
Clarify policy write availability
CBenoit Sep 15, 2026
1286db9
Unify policy inspector refresh
CBenoit Sep 15, 2026
1f23b26
Make policy editor guidance actionable
CBenoit Sep 15, 2026
06e332a
Migrate policy editor to format version contract
CBenoit Sep 15, 2026
8fec23b
Address final policy editor review
CBenoit Sep 15, 2026
e0e1206
Address final Copilot rereview
CBenoit Sep 15, 2026
6ea4ebb
Unify package policy management status
CBenoit Sep 16, 2026
e17a71d
Refine package policy editor guidance
CBenoit Sep 16, 2026
4c63f18
Correct new policy rule defaults
CBenoit Sep 16, 2026
0178db1
Clarify advanced Audit mode behavior
CBenoit Sep 16, 2026
20046be
Audit package policy administrator help
CBenoit Sep 16, 2026
4892391
Clarify package policy rule semantics
CBenoit Sep 17, 2026
f6022cb
Streamline policy editor validation layout
CBenoit Sep 17, 2026
0ef90bd
Refine policy advisories and validity controls
CBenoit Sep 17, 2026
8200648
Fix policy validity controls
CBenoit Sep 17, 2026
df113b3
Adopt final package policy contract
CBenoit Sep 17, 2026
eda425a
Preserve guarded bundle navigation
CBenoit Sep 17, 2026
e295135
Fix policy finding focus navigation
CBenoit Sep 17, 2026
55d81ef
Preserve policy editor input focus
CBenoit Sep 17, 2026
495b4b4
Harden final policy editor boundaries
CBenoit Sep 17, 2026
3266ff2
Close final policy boundary gaps
CBenoit Sep 17, 2026
03dd66b
Finish policy security review
CBenoit Sep 17, 2026
643bc5e
Resolve translation catalog overlap
CBenoit Sep 17, 2026
7e23746
Remove policy repair UI and refine write diagnostics
CBenoit Sep 18, 2026
c140dcf
Show policy warnings inline
CBenoit Sep 18, 2026
7e33f21
Keep policy warnings inline
CBenoit Sep 18, 2026
71f837c
Respect layered policy deny rules
CBenoit Sep 18, 2026
f0d4f66
Explain causal policy warnings
CBenoit Sep 19, 2026
e47280d
Adopt Policy 2026.9.19
CBenoit Sep 19, 2026
05cdf5a
Default new Allow rules safely
CBenoit Sep 20, 2026
88b7aa5
Align helper policy contract
CBenoit Sep 20, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 15 additions & 0 deletions .github/workflows/build-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -219,6 +219,13 @@ jobs:
throw "Windows app host was not produced at unigetui_bin/UniGetUI.exe"
}
# The elevated policy-write helper is authenticated by exact path at runtime, and it must
# be present here so the code-signing step below signs it and the integrity tree that is
# generated afterwards covers it.
if (-not (Test-Path "unigetui_bin/Assets/Utilities/UniGetUI.PolicyElevator.exe")) {
throw "Elevated policy helper was not staged at unigetui_bin/Assets/Utilities/UniGetUI.PolicyElevator.exe"
}
$MaxShippedPdbSizeBytes = 1MB
$PdbsToRemove = Get-ChildItem "unigetui_bin" -Filter "*.pdb" -File -Recurse | Where-Object {
$_.Length -gt $MaxShippedPdbSizeBytes
Expand Down Expand Up @@ -250,6 +257,14 @@ jobs:
-CertificateName '${{ secrets.CODE_SIGNING_CERTIFICATE_NAME }}' `
-TimestampServer '${{ vars.CODE_SIGNING_TIMESTAMP_SERVER }}'
# The helper is the one binary whose signature is checked at runtime by the host before
# it is elevated, so an unsigned helper must fail the release rather than ship.
$HelperPath = Join-Path $PWD "unigetui_bin/Assets/Utilities/UniGetUI.PolicyElevator.exe"
$HelperSignature = Get-AuthenticodeSignature $HelperPath
if ($HelperSignature.Status -ne "Valid") {
throw "Elevated policy helper is not validly signed (status: $($HelperSignature.Status))."
}
- name: Build installer
shell: pwsh
run: |
Expand Down
8 changes: 8 additions & 0 deletions UniGetUI.iss
Original file line number Diff line number Diff line change
Expand Up @@ -130,6 +130,8 @@ begin
// Elevator (gsudo cache) and pinget live in {app} and lock their own files.
TaskKillWait('UniGetUI Elevator.exe');
TaskKillWait('pinget.exe');
// The elevated policy helper is short-lived, but it lives in {app} and can hold a file lock.
TaskKillWait('UniGetUI.PolicyElevator.exe');
Sleep(1000); // let the OS release file handles before copying
end;
Expand Down Expand Up @@ -346,3 +348,9 @@ Filename: "{app}\{#MyAppExeName}"; Parameters: "--migrate-wingetui-to-unigetui";
Filename: {sys}\taskkill.exe; Parameters: "/f /im WingetUI.exe"; Flags: skipifdoesntexist runhidden; RunOnceId: "KillWingetUI"
Filename: {sys}\taskkill.exe; Parameters: "/f /im UniGetUI.exe"; Flags: skipifdoesntexist runhidden; RunOnceId: "KillUniGetUI"
Filename: {sys}\taskkill.exe; Parameters: "/f /im UniGetUI.Avalonia.exe"; Flags: skipifdoesntexist runhidden; RunOnceId: "KillUniGetUIAvalonia"
Filename: {sys}\taskkill.exe; Parameters: "/f /im UniGetUI.PolicyElevator.exe"; Flags: skipifdoesntexist runhidden; RunOnceId: "KillUniGetUIPolicyElevator"

[UninstallDelete]
; The elevated policy helper is authenticated by exact path, so a leftover copy must never
; survive an uninstall.
Type: files; Name: "{app}\Assets\Utilities\UniGetUI.PolicyElevator.exe"
7 changes: 7 additions & 0 deletions scripts/build.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -96,6 +96,13 @@ if (-not (Test-Path $WindowsAppHostPath)) {
throw "Windows app host was not produced at $WindowsAppHostPath"
}

# The elevated policy-write helper is authenticated by exact path at runtime, so a missing or
# misplaced helper must fail the build rather than silently ship an install that cannot elevate.
$PolicyElevatorPath = Join-Path $BinDir "Assets\Utilities\UniGetUI.PolicyElevator.exe"
if (-not (Test-Path $PolicyElevatorPath)) {
throw "Elevated policy helper was not staged at $PolicyElevatorPath"
}

# Keep smaller symbols for useful local crash source information, and prune oversized ones.
$MaxShippedPdbSizeBytes = 1MB

Expand Down
599 changes: 597 additions & 2 deletions src/Languages/lang_en.json

Large diffs are not rendered by default.

Loading
Loading