Skip to content

Harden autoupdater trust, downgrade, and recovery boundaries #172

Description

@rowkav09

Goal

Harden the Windows autoupdater against untrusted release metadata, rollback/downgrade attacks, unsafe redirects and partial-install recovery before the next testable prerelease.

Bounded scope

  • require HTTPS GitHub release endpoints and reject cross-origin redirects for metadata and assets
  • validate every downloaded asset against the release's expected filename, size and SHA-256 before install
  • reject stable downgrades and channel-crossing updates unless the user explicitly chooses that channel
  • keep bearer credentials and private URLs out of updater errors, diagnostics and logs
  • cap response size, redirects, timeouts and retry/backoff behavior
  • preserve the existing staged install, version check, backup and rollback path
  • add deterministic hostile fixtures: bad digest, oversized body, redirect, stale release, channel mismatch and interrupted replacement

Done when

  • updater cannot install bytes that were not bound to the selected release metadata
  • downgrade/channel changes are explicit instead of automatic
  • no secret or private URL is emitted in any failure object
  • recovery leaves either the previous working version or the fully verified new version
  • tests cover all hostile fixtures on supported Node versions and the Windows bundle workflow

Refs #119 #120 #127 #141

Activity

  1. rowkav09 commented on Sep 23, 2026

    @rowkav09
    MemberAuthor

    Status:

  2. moved this to Todo in nowplayingon Sep 23, 2026
  3. rowkav09 commented on Sep 24, 2026

    @rowkav09
    MemberAuthor

    Status: everything in "Done when" is covered now.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions