Skip to content

Restore full signed-update regression coverage after Windows MVP split #2001

Description

@integry

Objective

Restore and separate the retained macOS signed-update verification suite after #1972 removes the deferred Windows native authority from the MVP package.

Context

The bounded Windows pivot on #1972 removes signed-updates.test.ts because its large fixture is coupled to windows-update-authority. Exact parent head 0a37eccc475447b400033379559577233b009574 ran that suite green, and the MVP delta keeps the macOS implementation materially unchanged while adding explicit early Windows unsupported guards. The smaller replacement policy suite proves the platform boundary and a macOS happy path, so this coverage repair is not a first-package merge blocker, but the retained security behavior should not remain without dedicated regression coverage.

Scope

  • Rebuild platform-neutral/macOS tests for signed manifest/signature parsing, target/version/architecture binding, download size/hash checks, signer mismatch, cache freshness, quarantine bounds, cleanup, cancellation, concurrency and TOCTOU defenses.
  • Remove all dependency on the deferred Windows native authority from those tests.
  • Keep Windows check/apply zero-network, zero-cache, zero-authority and fixed unsupported assertions.
  • Preserve secret-free PR execution and do not re-enable Windows update installation; Complete verified Windows update installation after MVP desktop packaging #2000 owns that work.

Dependency and integration

Start after #1972 is integrated into the Electron runtime epic. Add the AI label and current runtime descendant base label then. Require exact-head review and macOS/Linux CI. Never target or merge directly to main.

Part of #1950, #1952, #1957, #1962, and #2000.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions