Skip to content

Harden plugin catalog validation and release signing - #1

Merged
krotname merged 1 commit into
masterfrom
agent/harden-plugin-list-validation
Jul 14, 2026
Merged

krotname merged 1 commit into
masterfrom
agent/harden-plugin-list-validation

Conversation

@krotname

Copy link
Copy Markdown
Owner

What changed

  • split deterministic offline manifest checks from package-download validation
  • reject duplicate JSON keys, schema drift, wrong architecture metadata, unsafe folder names and case-insensitive duplicate plugin fields
  • constrain downloads to public HTTPS endpoints with manually validated redirects, bounded time/size, and SHA-256 verification
  • inspect ZIP metadata safely and reject traversal paths, links, encryption, duplicate DLL names and archive expansion abuse
  • extract only the expected root DLL into an automatically cleaned temporary directory
  • make generated documentation escaped, deterministic and atomically written
  • replace the text-corrupting PowerShell sorter with the validated deterministic sorter
  • add regression tests for manifest, URL, redirect, archive and workflow failure modes
  • pin workflow actions, Python 3.12 and hashed dependencies; add bounded jobs and offline gates
  • isolate OIDC signing from builds and external package validation, require an exact Sign CLI version, and sign only the matrix DLL
  • correct the catalog binary resource type from application to DLL

Why

The previous validator coupled duplicate checks to successful external downloads, continued after schema failures, deleted persistent architecture-named directories, and processed unbounded archives. The release workflow then signed a recursive DLL glob while downloaded third-party DLLs remained in the workspace. A crafted catalog or archive could therefore bypass local checks, consume excessive resources, traverse paths, or place third-party binaries in the signing scope.

Impact

Offline review is now deterministic and does not contact package hosts. Online CI retains URL, package hash and DLL version validation while failing safely on hostile responses. The three plugin catalog JSON files are unchanged; documentation changes only escape catalog text safely.

Validation

  • py -3.12 -m unittest discover -s tests -v: 29 passed
  • python validator.py all --offline: passed for 431 entries
  • ruff check, ruff format --check, Bandit, Python compile, JSON Schema, YAML, PowerShell and MSBuild XML checks: passed
  • Release MSBuild for Win32, x64 and ARM64: passed with warnings treated as errors
  • resulting PE files report x86/x64/ARM64, DLL type and version 1.9.6.0
  • all manifest package URLs are HTTPS and all local SHA-256 fields have valid shape and are unique per architecture

External package availability, current remote bytes and manifest hash freshness were intentionally not re-fetched during the local audit; the online architecture jobs remain responsible for those checks.

@krotname
krotname marked this pull request as ready for review July 14, 2026 10:58
@krotname
krotname merged commit 68c0824 into master Jul 14, 2026
10 checks passed
@krotname
krotname deleted the agent/harden-plugin-list-validation branch July 29, 2026 21:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant