fix: the macOS installer verifies against the checksum published beside the zip - #394
Merged
sepehr-safari merged 1 commit intoSep 25, 2026
Merged
Conversation
…de the zip Releases now carry Plaza-vX.Y.Z-macos.zip.sha256, and v0.24.0 is the first. The installer fetches it by the zip's own name, as the Linux installer does with its tarball, instead of picking a digest out of the release JSON; that parsing is gone, and with it the one way this check has failed before, a Linux asset's digest taken for the zip's. It also refuses to install without a verified checksum. When no digest was found it used to say it was skipping verification and install anyway; now a missing, empty or malformed .sha256, or a mismatch, stops it before anything is installed, which is what the Linux installer already did. check-macos-installer.sh existed to test the JSON parsing and goes with it. Its CI step becomes a check that both installers, which are served over curl | bash, stay pure ASCII and parse.
sepehr-safari
deleted the
the-macos-installer-reads-the-published-checksum
branch
September 25, 2026 09:42
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of #361. v0.24.0 is the first release carrying
Plaza-vX.Y.Z-macos.zip.sha256, so the installer can read it now.install-macos.shfetches<zip url>.sha256and compares it with the download, the same wayinstall-linux.shreads its tarball's. The JSON digest parsing is deleted..sha256, or a mismatch, stops the install. It used to print "skipping verification" and install anyway when it found no digest.scripts/check-macos-installer.shtested the JSON parsing and is removed, as the issue planned. Its CI step becomes a guard that both installers stay pure ASCII (they run under macOS's bash 3.2 viacurl | bash) and parse.Verified with copies of the installer that stop right after verification, run with
/bin/bash3.2 against the live v0.24.0 release:SHA-256 verified..sha256missing (404).sha256holding other textThe ASCII guard catches a planted non-ASCII byte. shellcheck is clean.
Notary's installer gets the same change once a Notary release carries its
.sha256; the release side is already merged there (zig-nostr/notary#105).