Repository navigation
Harden autoupdater trust, downgrade, and recovery boundaries #172
Copy link
Copy link
Closed
Description
Activity
- added a commit that references this issue
on Sep 22, 2026 Status:
- Done: untrusted redirects rejected (fix: reject untrusted updater redirects #174), prerelease ordering preserved (fix: preserve updater prerelease ordering #178)
- Remaining from the checklist: explicit opt-in for downgrade/channel changes, response and retry caps, and the full set of hostile fixtures (bad digest, oversized body, interrupted replacement) in the Windows workflow. Rechecking each item against the current updater before closing.
- added 16 commits that reference this issue
on Sep 23, 2026 Status: everything in "Done when" is covered now.
- Only bytes bound to the release get installed: archive and SHA256SUMS must both be in the selected release, the archive is size-capped, and its exact SHA-256 entry is checked before the staged swap. Hostile fixtures for this are in test(updater): hostile install fixtures, keep the archive name inside the work folder (#172) #306.
- Redirects are rejected (fix: reject untrusted updater redirects #174). Prerelease ordering is fixed (fix: preserve updater prerelease ordering #178). The update-check ReDoS is fixed (fix(updater): linear-time version parsing, skip malformed release tags (#172) #310).
- Downgrades and channel changes: only versions higher than the installed one are ever offered, channels never cross, and there's no default channel, so the caller has to choose stable or beta (fix(updater): require an explicit update channel (#172) #323).
- Caps: the release list is limited to 4 MB with a 30 s timeout, the archive to 100 MB and the checksum file to 64 KB with a 5 min timeout, and redirects are refused. There's no retry loop, so retries can't pile up.
- No token or private URL appears in failure objects (covered by the test(updater): hostile install fixtures, keep the archive name inside the work folder (#172) #306 fixtures).
- Recovery leaves either the old install or the fully verified new one. The previous install stays at
.backup, and if the restore also fails, the error names that path. - The fixtures run on Node 22/24 and now also on the Windows runner (ci(windows): run updater hostile fixtures on Windows (#172) #328). That run caught a Linux-only assumption in a test, which is fixed.
Metadata
Metadata
Assignees
Type
Projects
- StatusShow more project fieldsDone
Goal
Harden the Windows autoupdater against untrusted release metadata, rollback/downgrade attacks, unsafe redirects and partial-install recovery before the next testable prerelease.
Bounded scope
Done when
Refs #119 #120 #127 #141