Skip to content

fix: the macOS installer verifies against the checksum published beside the zip - #394

Merged
sepehr-safari merged 1 commit into
mainfrom
the-macos-installer-reads-the-published-checksum
Sep 25, 2026
Merged

sepehr-safari merged 1 commit into
mainfrom
the-macos-installer-reads-the-published-checksum

Conversation

@sepehr-safari

Copy link
Copy Markdown
Contributor

Part of #361. v0.24.0 is the first release carrying Plaza-vX.Y.Z-macos.zip.sha256, so the installer can read it now.

  • install-macos.sh fetches <zip url>.sha256 and compares it with the download, the same way install-linux.sh reads its tarball's. The JSON digest parsing is deleted.
  • It fails closed: a missing, empty or malformed .sha256, or a mismatch, stops the install. It used to print "skipping verification" and install anyway when it found no digest.
  • scripts/check-macos-installer.sh tested the JSON parsing and is removed, as the issue planned. Its CI step becomes a guard that both installers stay pure ASCII (they run under macOS's bash 3.2 via curl | bash) and parse.

Verified with copies of the installer that stop right after verification, run with /bin/bash 3.2 against the live v0.24.0 release:

case result
as published downloads v0.24.0, SHA-256 verified.
.sha256 missing (404) refuses: could not fetch the published SHA-256
download altered by one byte refuses: checksum mismatch, both digests printed
.sha256 holding other text refuses: empty or malformed

The ASCII guard catches a planted non-ASCII byte. shellcheck is clean.

Notary's installer gets the same change once a Notary release carries its .sha256; the release side is already merged there (zig-nostr/notary#105).

…de the zip

Releases now carry Plaza-vX.Y.Z-macos.zip.sha256, and v0.24.0 is the first. The installer fetches it by the zip's own name, as the Linux installer does with its tarball, instead of picking a digest out of the release JSON; that parsing is gone, and with it the one way this check has failed before, a Linux asset's digest taken for the zip's.

It also refuses to install without a verified checksum. When no digest was found it used to say it was skipping verification and install anyway; now a missing, empty or malformed .sha256, or a mismatch, stops it before anything is installed, which is what the Linux installer already did.

check-macos-installer.sh existed to test the JSON parsing and goes with it. Its CI step becomes a check that both installers, which are served over curl | bash, stay pure ASCII and parse.
@sepehr-safari
sepehr-safari merged commit cb3629a into main Sep 25, 2026
6 checks passed
@sepehr-safari
sepehr-safari deleted the the-macos-installer-reads-the-published-checksum branch September 25, 2026 09:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant