Skip to content

fix(hidi): preserve ESRP-signed DLL in v2 tool packages - #904

Open
Gavin Barron (gavinbarron) wants to merge 2 commits into
support/v2from
gavinbarron-hidi-v2-signed-pack-correction
Open

Gavin Barron (gavinbarron) wants to merge 2 commits into
support/v2from
gavinbarron-hidi-v2-signed-pack-correction

Conversation

@gavinbarron

Copy link
Copy Markdown
Contributor

Defect and root cause

The publish-disabled official Hidi build 248624 produced a signed NuGet container and a valid Microsoft-signed executable, but its packaged Microsoft.OpenApi.Hidi.dll was NotSigned (76,800 bytes; strong-name token 3f5743946376f042).

Actual SDK 10.0.401 MSBuild output and real dotnet pack --no-build reproduced the cause: ComputeResolvedFilesToPublishList selects @(IntermediateAssembly) from obj, and PackAsTool packs the publish output. Copying the ESRP DLL into bin does not change that input.

Correction

  • Add opt-in HidiSignedAssemblyPath to replace only the Hidi ResolvedFileToPublish item after ComputeFilesToPublish. Missing signing input or an unexpected assembly-item count fails explicitly. CopyToPublishDirectory=Always handles an older staging timestamp without copying into SDK intermediate caches.
  • Pass the exact ESRP staging DLL into the existing no-build tool pack, replacing the ineffective bin copy.
  • Before NuGet signing, require exactly one DLL at tools/net8.0/any/Microsoft.OpenApi.Hidi.dll, SHA256 equality with staging, and valid Microsoft Corporation Authenticode signatures on both files. Fail closed on missing, mismatched, unsigned, unverifiable, or incorrectly signed payloads.
  • Add 21 guard cases and extend the existing Pester/Sonar measured coverage path to both helpers; document the tool-pack/signature boundary.

Validation

  • Existing Hidi suite: 91 passed. Existing/new helper cases: 45 passed. Exact updated workflow block produced measured 100% command coverage and 38/38 + 26/26 covered helper lines, converted from genuine JaCoCo data.
  • Real default pack ignored controlled bin bytes and matched unsigned obj SHA256 254E356A72E3F77F3750C3517DB6014FBFFAA2961A2A159D7367D46357FF7293.
  • Corrected real pack retained controlled staging SHA256 0E6D3B2799E9C5B7FA916B69DB2B66FA5A7FC2F884E3B2CE1AE31C0854D695D6, including a staging timestamp predating publish output. All other 69 package entries unchanged; two portable PDBs retained; no compiler invocation during pack.
  • Production guard rejected actual unsigned controlled input. Missing staged file and missing assembly publish item failed explicitly. Ordinary pack, packaged CLI help, and Windows single-file publish/help succeeded.
  • Changed YAML/project XML parse; official pipeline structured comparison confirms only its signed-pack step changed.

Controlled bytes are not signed; mocked unit-test certificate responses and local checks do not prove Microsoft ESRP readiness. After normal approved merge, the existing official pipeline 759 must be run with publication still disabled and its actual packaged DLL, NuGet signature, executable/ZIP, symbols, and public Docker context verified.

Scope and safety

Preserves current Hidi 2.13.0/OData 2.2.1/core+Yaml 2.12.2 versions, hidi-v2 tag/floor guards, ESRP signing Yuriy Semchyshyn (@5) and NuGet release akari (@14), identity/resources/feed/pools/environments, executable/ZIP/Docker paths, and all publishing-disabled gates. Root OData pack configuration and imported shared history are untouched. No grants, publication, release/version-PR merge, private keys, local certificates, NuGet post-sign modification, policy bypass, or auto-merge.

Replace the tool publish assembly input with the ESRP staging DLL and verify its packaged hash and Microsoft Authenticode signature before NuGet signing. Cover fail-closed validation through the existing measured Pester workflow.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: ca73667e-f3d5-4518-b76d-1bf49dc7da23
@gavinbarron
Gavin Barron (gavinbarron) requested a review from a team as a code owner October 9, 2026 23:53
Use the workflow-provided GitHub token only for the existing Data gatherer repository GET to avoid anonymous API rate limiting. Preserve request count, metadata output, workflow conditions and permissions.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: ca73667e-f3d5-4518-b76d-1bf49dc7da23
@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant