Skip to content

Add the package verifier and run it before release builds - #387

Merged
BunsDev merged 3 commits into
mainfrom
feat/verify-package
Sep 26, 2026
Merged

BunsDev merged 3 commits into
mainfrom
feat/verify-package

Conversation

@BunsDev

@BunsDev BunsDev commented Sep 26, 2026 •

Copy link
Copy Markdown
Member

Refs #356. This does the verifier part of the issue and encodes its decisions. It does not close the issue, because the signing secrets are still needed (decision 4).

What #356 asks

scripts/verify-package.mjs, wired into release.yml before the platform builds.

Decisions (made 2026-09-26, recorded on #356)

  1. Window minimum: 480×520, the implemented and documented contract. The Phase 7 plan's 820×600 is superseded.
  2. Deep-link protocol: deferred past v0.0.1. Nothing handles incoming links yet.
  3. Updater: off for v0.0.1, as docs/releasing.md § 4 already documents.

What the verifier enforces

  • Product name OpenCoven Chat and identifier ai.opencoven.chat.
  • One window, main, with a 1180×780 default and a 480×520 minimum; withGlobalTauri: false.
  • A strict CSP. default-src and script-src are 'self', and object-src, base-uri, form-action and frame-ancestors are 'none'. No unsafe-eval, *, http: or https: source is allowed. connect-src is required and holds only 'self', ipc: and http://ipc.localhost. Repeated directives are rejected.
  • bundle.active, the six installer targets, and the five declared icons, which must exist on disk.
  • The capability files: only the reviewed default.json may exist. It must grant exactly the reviewed allowlist to main, with no remote origins and no shell, fs, opener, http, process, os or dialog permission.
  • No tauri-plugin-shell, -fs, -http, -opener or -process in Cargo.toml.
  • The v0.0.1 decisions: createUpdaterArtifacts: false with no updater config or crate, and no deep-link config or crate. A release that enables either changes that decision in the same change that configures it.

Wiring and docs

  • release.yml, verify-tag job: runs after checkout and before the tag check, so before every platform build, on rehearsal and production paths. release-workflow.test.ts pins the step and its position.
  • docs/releasing.md § 1: the checklist says what it enforces.

Remaining on #356

Decision 4: the Apple Developer ID and notarization credentials and the Windows code-signing certificate in the release-signing environment, which holds no secrets today. Then push a signed v0.0.1 (or -rc.N) tag.

Verification

  • src/verify-package.test.ts, 23 tests. The real configuration passes. Each mutation below fails:
    • product name, identifier, minimum window, a second window, and global Tauri;
    • unsafe-eval, a network origin, a repeated connect-src, and a missing connect-src;
    • a dropped installer target and a missing icon file;
    • a shell permission, an unreviewed core permission, a remote origin, and an extra capability file;
    • a filesystem plugin;
    • updater artifacts, an updater config, and the updater crate;
    • a deep-link scheme and the deep-link crate.
  • release-workflow.test.ts pins the step's position. Biome and typecheck are clean.
  • Pushed over SSH, as the change touches .github/workflows.

🤖 Generated with Claude Code

Issue #356 asks for scripts/verify-package.mjs, wired into release.yml
before the platform builds. It needs product and key-custody decisions
before it can assert everything the Phase 7 plan lists, so it enforces
what the configuration, README and capability guard already agree on and
reports the rest as pending:

- enforced: product name and identifier; the 1180x780 default and the
  documented 480x520 minimum window; withGlobalTauri off; a strict CSP
  with no unsafe-eval, no wildcard or scheme sources and no network
  origin in connect-src; the six installer targets and five icons,
  present on disk; the main window's exact capability allowlist; no
  shell, filesystem, HTTP, opener or process plugin.
- pending (issue #356 decisions 2 and 3): the updater public key with
  updater artifacts on, and the opencoven-chat protocol. --release makes
  them failures for when they are decided; release.yml does not pass it
  yet, since docs/releasing.md documents the updater as opt-in and off.

The minimum window follows the implemented contract (README, responsive
tiers) rather than the plan's older 820x600, per the evidence on #356.
Tests pass the real configuration and fail each of thirteen mutations.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings September 26, 2026 04:06

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Unresolved verifier correctness, capability coverage, documentation, and workflow-test issues remain.

Review effort: Lite
Findings: 2 High severity · 3 Medium severity

Open (5)
What changed in this PR

Adds a Tauri package-contract verifier, tests, release workflow integration, and documentation for pre-build validation.

Changes:

  • Validates configuration, CSP, capabilities, icons, targets, and plugins.
  • Reports updater and deep-link decisions as pending.
  • Adds mutation tests and runs verification before release builds.
  • Documents local verification and release checks.
File Reviewed changes Findings
src/​verify-package.test.ts Adds verifier mutation tests. No findings.
scripts/​verify-package.mjs Implements package-contract validation. Unresolved CSP duplicate handling, missing connect-src, deep-link validation, and incomplete capability-file coverage.
docs/​releasing.md Documents verification and release requirements. Updater checklist requirements contradict the documented opt-in state.
.github/​workflows/​release.yml Runs verification before release builds. Workflow tests do not assert the verifier step or its ordering.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread scripts/verify-package.mjs
Comment thread scripts/verify-package.mjs Outdated
Comment thread .github/workflows/release.yml
Comment thread scripts/verify-package.mjs Outdated
Comment thread scripts/verify-package.mjs Outdated
- A repeated CSP directive is rejected: the first copy stays in force,
  so checking only one could pass a permissive policy.
- connect-src is required, with ipc: and http://ipc.localhost; without
  it default-src 'self' blocks the webview's IPC to its own host.
- Every capability file is read, and any file other than the reviewed
  default.json fails, since Tauri loads them all.
- The protocol counts as registered only at
  plugins.deep-link.desktop.schemes, not wherever the string appears.
- The release workflow test pins the verifier step in verify-tag, after
  checkout and before the tag check, ahead of the build job.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@BunsDev

BunsDev commented Sep 26, 2026

Copy link
Copy Markdown
Member Author

The release owner's decisions on #356 are now recorded there. One affects this PR. The opencoven-chat deep-link protocol is deferred past v0.0.1, so --release should no longer fail on it. Only the updater (decision 3) stays pending, and it waits for the keypair. The 480×520 minimum is confirmed as the contract. I have not touched this branch.

The three open decisions are now made (2026-09-26): the window minimum
stays 480x520, the opencoven-chat protocol is deferred past v0.0.1, and
the updater stays off for v0.0.1. With nothing left pending, the
verifier drops its pending list and --release flag and enforces the
decided state: createUpdaterArtifacts false with no updater config or
crate, and no deep-link config or crate. A release that enables either
changes the decision here in the same change that configures it. The
workflow comment and docs/releasing.md say so.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@BunsDev
BunsDev merged commit d8a70c1 into main Sep 26, 2026
10 checks passed
@BunsDev
BunsDev deleted the feat/verify-package branch September 26, 2026 10:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants