Repository navigation
fix(hidi): preserve ESRP-signed DLL in v2 tool packages - #904
Open
Gavin Barron (gavinbarron) wants to merge 2 commits into
Open
Gavin Barron (gavinbarron) wants to merge 2 commits into
Gavin Barron (gavinbarron) wants to merge 2 commits into
Conversation
Replace the tool publish assembly input with the ESRP staging DLL and verify its packaged hash and Microsoft Authenticode signature before NuGet signing. Cover fail-closed validation through the existing measured Pester workflow. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: ca73667e-f3d5-4518-b76d-1bf49dc7da23
Use the workflow-provided GitHub token only for the existing Data gatherer repository GET to avoid anonymous API rate limiting. Preserve request count, metadata output, workflow conditions and permissions. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: ca73667e-f3d5-4518-b76d-1bf49dc7da23
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Defect and root cause
The publish-disabled official Hidi build 248624 produced a signed NuGet container and a valid Microsoft-signed executable, but its packaged
Microsoft.OpenApi.Hidi.dllwasNotSigned(76,800 bytes; strong-name token3f5743946376f042).Actual SDK 10.0.401 MSBuild output and real
dotnet pack --no-buildreproduced the cause:ComputeResolvedFilesToPublishListselects@(IntermediateAssembly)fromobj, andPackAsToolpacks the publish output. Copying the ESRP DLL intobindoes not change that input.Correction
HidiSignedAssemblyPathto replace only the HidiResolvedFileToPublishitem afterComputeFilesToPublish. Missing signing input or an unexpected assembly-item count fails explicitly.CopyToPublishDirectory=Alwayshandles an older staging timestamp without copying into SDK intermediate caches.tools/net8.0/any/Microsoft.OpenApi.Hidi.dll, SHA256 equality with staging, and valid Microsoft Corporation Authenticode signatures on both files. Fail closed on missing, mismatched, unsigned, unverifiable, or incorrectly signed payloads.Validation
254E356A72E3F77F3750C3517DB6014FBFFAA2961A2A159D7367D46357FF7293.0E6D3B2799E9C5B7FA916B69DB2B66FA5A7FC2F884E3B2CE1AE31C0854D695D6, including a staging timestamp predating publish output. All other 69 package entries unchanged; two portable PDBs retained; no compiler invocation during pack.Controlled bytes are not signed; mocked unit-test certificate responses and local checks do not prove Microsoft ESRP readiness. After normal approved merge, the existing official pipeline 759 must be run with publication still disabled and its actual packaged DLL, NuGet signature, executable/ZIP, symbols, and public Docker context verified.
Scope and safety
Preserves current Hidi 2.13.0/OData 2.2.1/core+Yaml 2.12.2 versions,
hidi-v2tag/floor guards, ESRP signing Yuriy Semchyshyn (@5) and NuGet release akari (@14), identity/resources/feed/pools/environments, executable/ZIP/Docker paths, and all publishing-disabled gates. Root OData pack configuration and imported shared history are untouched. No grants, publication, release/version-PR merge, private keys, local certificates, NuGet post-sign modification, policy bypass, or auto-merge.