Skip to content

fix(hidi): retain signed assembly in official tool package - #903

Open
Gavin Barron (gavinbarron) wants to merge 2 commits into
mainfrom
gavinbarron-hidi-signed-pack-correction
Open

Gavin Barron (gavinbarron) wants to merge 2 commits into
mainfrom
gavinbarron-hidi-signed-pack-correction

Conversation

@gavinbarron

Copy link
Copy Markdown
Contributor

Root cause

Official publish-disabled build 248625 succeeded at DLL/exe and NuGet signing, but its packaged Hidi DLL was NotSigned: SHA256 802BF99693EC73418790E0FA1EAC5F730854355FAA4AE6E8A2C7F8597100E42F exactly matched the pre-signing DLL. The SDK's no-build tool pack runs Publish, selects IntermediateAssembly from obj into ResolvedFileToPublish, then packages PublishDir. Overwriting bin therefore does not select the signed payload.

Correction

  • Opt-in HidiSignedAssemblyPath replaces only the uniquely selected Hidi publish item after ComputeFilesToPublish, using the exact ESRP staging DLL and CopyToPublishDirectory=Always. Missing or ambiguous inputs fail closed; normal local/Docker builds remain unchanged.
  • Official packing supplies the absolute staging path, without recompilation, cache mutation, or ZIP rewriting.
  • Before NuGet signing, a fail-closed verifier requires the unique exact tool DLL entry, staging SHA256 equality, and valid Microsoft Corporation Authenticode signatures on both staging and packaged DLLs.
  • Add 21 isolated Pester provenance/error cases and extend existing measured Sonar coverage to both helpers; document the signing contract.

Validation

  • Fresh branch from main 28b6c5136dfb133009122761a31df57e0779f836; Hidi 3.10.2 / OData 3.2.1 / core+YamlReader 3.10.2 unchanged.
  • Actual SDK 10.0.401 build and no-build pack with isolated session output: distinct bin overlay ignored by normal pack; opt-in package DLL exactly matches synthetic staging SHA256, while original obj stays unchanged. All other nupkg and snupkg entry bytes match; Hidi/OData portable PDBs retained.
  • Missing staging and zero/duplicate publish inputs fail closed. Production verifier rejects equal synthetic unsigned bytes and the original official 248625 unsigned DLL. Synthetic files explicitly remain NotSigned; no claim of real local signing.
  • Hidi 107/107 and OData 1279/1279 pass using separate runners. Pester 45/45; exact Sonar workflow block produces 100% measured helper line coverage (38/38 + 26/26).
  • Self-contained Windows publish, --help, and ZIP/exe hash equality pass; opt-in target skips PackAsTool=false.
  • Both YAML documents parse; unchanged ESRP 6 (@6) tasks/identities, akari (@14) release, publish/preview disabled flags, tags/version floor, artifact selectors, feeds/connections/environments/pools, public-only Docker staging, and release-please configuration verified.

Readiness boundary

Normal review/merge only; no auto-merge, package/container publication, release-PR merge, or resource grants. This corrects packing but does not establish final signed-artifact readiness: the coordinator must run a fresh publish-disabled official build after normal merge and verify downloaded nupkg DLL signing/provenance, NuGet/exe signatures, ZIP bytes, symbols, and public-only Docker context. Support/v2 has a separate corrective PR.

Replace the SDK tool publish input with the exact ESRP-signed staging assembly and verify payload provenance before NuGet signing.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 61e122e7-9a38-4455-8cb1-343245120242
@gavinbarron
Gavin Barron (gavinbarron) requested a review from a team as a code owner October 9, 2026 23:52
Use the workflow-provided token for the existing metadata GET to avoid shared runner anonymous API-rate-limit failures, without changing branch outputs, permissions or publishing conditions.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 61e122e7-9a38-4455-8cb1-343245120242
@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant