Skip to content

Preserve entitlements in managed Mach-O signer - #116659

Merged
jtschuster merged 23 commits into
dotnet:mainfrom
jtschuster:PreserveEntitlementsInMachSigner
Jul 2, 2025
Merged

Preserve entitlements in managed Mach-O signer#116659
jtschuster merged 23 commits into
dotnet:mainfrom
jtschuster:PreserveEntitlementsInMachSigner

Conversation

@jtschuster

@jtschusterjtschuster commented Jun 13, 2025

Copy link
Copy Markdown
Member

Preserves entitlements in the signature when signing with the managed signer. Works on regular apphost and singlefile apphost.

Adds EntitlementsBlob and DerEntitlementsBlob, and updates relevant code to include these blobs.
Adds an EmbeddedSignatureBlob to signing methods to preserve the entitlements from the previous signature.
Precalculates the maximum length required for the new apphost / bundle and allocates an memory-mapped file in memory, copies / modifies the file, then writes out the final length of the file.
Adds tests to ensure the inode of the apphost changes when CreateAppHost / GenerateBundle creates a new apphost/bundle to ensure the MacOS signature cache is dirtied.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @vitek-karas, @agocke
See info in area-owners.md if you want to be subscribed.

@jtschuster
jtschuster marked this pull request as ready for review June 14, 2025 01:15
CopilotAI review requested due to automatic review settings June 14, 2025 01:15

This comment was marked as outdated.

Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/MachO/MachObjectFile.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
- use explicit types for "using" statements
- Make CodeDirectoryHeader fields private and expose properties that convert them from bigendian
- Reenable codesign hash checks in tests
- improve readability
@jtschuster
jtschuster requested a review from CopilotJune 25, 2025 18:38

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR introduces changes to preserve entitlements in the managed Mach‑O signer for macOS app hosts. Key changes include adjustments in the native CMake build file to conditionally include entitlements‐based signing; modifications to tests and signing utilities (e.g. Codesign, MachObjectFile, and related blobs) to support new EntitlementsBlob and DerEntitlementsBlob; and updates to the bundle and manifest code to accommodate the extended signature structure.

Reviewed Changes

Copilot reviewed 25 out of 25 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
src/native/corehost/apphost/static/CMakeLists.txtAdds conditional invocation of adhoc_sign_with_entitlements on macOS.
src/installer/tests/*Updates tests to use theory/member data for signing and rebundling; ensures signature cache clearing.
src/installer/managed/Microsoft.NET.HostModel/MachO/*Introduces EntitlementsBlob and DerEntitlementsBlob support and updates signature creation logic.
src/installer/managed/Microsoft.NET.HostModel/Bundle/*Adjusts bundle manifest and size calculations for new signature information.
src/installer/managed/Microsoft.NET.HostModel/AppHost/*Updates host rewriting and signing routines to integrate Mach‑O signature updates.
Comments suppressed due to low confidence (3)

src/installer/managed/Microsoft.NET.HostModel/MachO/BinaryFormat/Blobs/CodeDirectoryBlob.cs:153

  • The use of arithmetic on enum values (subtracting 1 from CodeDirectorySpecialSlot.DerEntitlements) to determine the array index may be fragile if the enum values are non‐sequential. Consider introducing an explicit mapping from enum values to array indices to improve maintainability.
 specialSlotHashes[(int)CodeDirectorySpecialSlot.DerEntitlements - 1] = hasher.ComputeHash(derStream.GetBuffer());

src/installer/managed/Microsoft.NET.HostModel/MachO/BinaryFormat/Blobs/CodeDirectoryBlob.cs:161

  • Similarly, computing the array index by subtracting 1 from CodeDirectorySpecialSlot.Entitlements assumes a contiguous indexing scheme. A mapping structure would make the assignment clearer and more robust against future enum changes.
 specialSlotHashes[(int)CodeDirectorySpecialSlot.Entitlements - 1] = hasher.ComputeHash(entStream.GetBuffer());

src/installer/managed/Microsoft.NET.HostModel/MachO/BinaryFormat/Blobs/EmbeddedSignatureBlob.cs:43

  • Consider adding an inline comment to clarify the intended blob ordering and how the additional entitlements blobs are factored into the blob count. This will help maintainers understand how changes to the signature structure affect the overall blob layout.
 int blobCount = 3 + (entitlementsBlob is not null ? 1 : 0) + (derEntitlementsBlob is not null ? 1 : 0);

@build-analysisbuild-analysisBot mentioned this pull request Jun 25, 2025
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/tests/TestUtils/SingleFileTestApp.cs Outdated
Comment threadsrc/installer/tests/AppHost.Bundle.Tests/AppLaunch.cs Outdated
Comment threadsrc/installer/tests/HostActivation.Tests/MachOHostSigningTests.cs Outdated
Comment threadsrc/installer/tests/HostActivation.Tests/MachOHostSigningTests.cs Outdated
Comment threadsrc/installer/tests/Microsoft.NET.HostModel.Tests/AppHost/CreateAppHost.cs Outdated

@agockeagocke left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
- Remove ConditionAttribute on test
- Use File.SetUnixFileMode
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Codesigning the apphost on macOS should preserve entitlements Why it won't work on macOS 15.0

5 participants

@jtschuster@agocke@am11@elinor-fung
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Preserve entitlements in managed Mach-O signer by jtschuster · Pull Request #116659 · dotnet/runtime · GitHub
Skip to content

Preserve entitlements in managed Mach-O signer - #116659

Merged
jtschuster merged 23 commits into
dotnet:mainfrom
jtschuster:PreserveEntitlementsInMachSigner
Jul 2, 2025
Merged

Preserve entitlements in managed Mach-O signer#116659
jtschuster merged 23 commits into
dotnet:mainfrom
jtschuster:PreserveEntitlementsInMachSigner

Conversation

@jtschuster

@jtschusterjtschuster commented Jun 13, 2025

Copy link
Copy Markdown
Member

Preserves entitlements in the signature when signing with the managed signer. Works on regular apphost and singlefile apphost.

Adds EntitlementsBlob and DerEntitlementsBlob, and updates relevant code to include these blobs.
Adds an EmbeddedSignatureBlob to signing methods to preserve the entitlements from the previous signature.
Precalculates the maximum length required for the new apphost / bundle and allocates an memory-mapped file in memory, copies / modifies the file, then writes out the final length of the file.
Adds tests to ensure the inode of the apphost changes when CreateAppHost / GenerateBundle creates a new apphost/bundle to ensure the MacOS signature cache is dirtied.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @vitek-karas, @agocke
See info in area-owners.md if you want to be subscribed.

@jtschuster
jtschuster marked this pull request as ready for review June 14, 2025 01:15
CopilotAI review requested due to automatic review settings June 14, 2025 01:15

This comment was marked as outdated.

Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/MachO/MachObjectFile.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
- use explicit types for "using" statements
- Make CodeDirectoryHeader fields private and expose properties that convert them from bigendian
- Reenable codesign hash checks in tests
- improve readability
@jtschuster
jtschuster requested a review from CopilotJune 25, 2025 18:38

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR introduces changes to preserve entitlements in the managed Mach‑O signer for macOS app hosts. Key changes include adjustments in the native CMake build file to conditionally include entitlements‐based signing; modifications to tests and signing utilities (e.g. Codesign, MachObjectFile, and related blobs) to support new EntitlementsBlob and DerEntitlementsBlob; and updates to the bundle and manifest code to accommodate the extended signature structure.

Reviewed Changes

Copilot reviewed 25 out of 25 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
src/native/corehost/apphost/static/CMakeLists.txtAdds conditional invocation of adhoc_sign_with_entitlements on macOS.
src/installer/tests/*Updates tests to use theory/member data for signing and rebundling; ensures signature cache clearing.
src/installer/managed/Microsoft.NET.HostModel/MachO/*Introduces EntitlementsBlob and DerEntitlementsBlob support and updates signature creation logic.
src/installer/managed/Microsoft.NET.HostModel/Bundle/*Adjusts bundle manifest and size calculations for new signature information.
src/installer/managed/Microsoft.NET.HostModel/AppHost/*Updates host rewriting and signing routines to integrate Mach‑O signature updates.
Comments suppressed due to low confidence (3)

src/installer/managed/Microsoft.NET.HostModel/MachO/BinaryFormat/Blobs/CodeDirectoryBlob.cs:153

  • The use of arithmetic on enum values (subtracting 1 from CodeDirectorySpecialSlot.DerEntitlements) to determine the array index may be fragile if the enum values are non‐sequential. Consider introducing an explicit mapping from enum values to array indices to improve maintainability.
 specialSlotHashes[(int)CodeDirectorySpecialSlot.DerEntitlements - 1] = hasher.ComputeHash(derStream.GetBuffer());

src/installer/managed/Microsoft.NET.HostModel/MachO/BinaryFormat/Blobs/CodeDirectoryBlob.cs:161

  • Similarly, computing the array index by subtracting 1 from CodeDirectorySpecialSlot.Entitlements assumes a contiguous indexing scheme. A mapping structure would make the assignment clearer and more robust against future enum changes.
 specialSlotHashes[(int)CodeDirectorySpecialSlot.Entitlements - 1] = hasher.ComputeHash(entStream.GetBuffer());

src/installer/managed/Microsoft.NET.HostModel/MachO/BinaryFormat/Blobs/EmbeddedSignatureBlob.cs:43

  • Consider adding an inline comment to clarify the intended blob ordering and how the additional entitlements blobs are factored into the blob count. This will help maintainers understand how changes to the signature structure affect the overall blob layout.
 int blobCount = 3 + (entitlementsBlob is not null ? 1 : 0) + (derEntitlementsBlob is not null ? 1 : 0);

@build-analysisbuild-analysisBot mentioned this pull request Jun 25, 2025
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/tests/TestUtils/SingleFileTestApp.cs Outdated
Comment threadsrc/installer/tests/AppHost.Bundle.Tests/AppLaunch.cs Outdated
Comment threadsrc/installer/tests/HostActivation.Tests/MachOHostSigningTests.cs Outdated
Comment threadsrc/installer/tests/HostActivation.Tests/MachOHostSigningTests.cs Outdated
Comment threadsrc/installer/tests/Microsoft.NET.HostModel.Tests/AppHost/CreateAppHost.cs Outdated

@agockeagocke left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
- Remove ConditionAttribute on test
- Use File.SetUnixFileMode
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Codesigning the apphost on macOS should preserve entitlements Why it won't work on macOS 15.0

5 participants

@jtschuster@agocke@am11@elinor-fung
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Preserve entitlements in managed Mach-O signer by jtschuster · Pull Request #116659 · dotnet/runtime · GitHub
Skip to content

Preserve entitlements in managed Mach-O signer - #116659

Merged
jtschuster merged 23 commits into
dotnet:mainfrom
jtschuster:PreserveEntitlementsInMachSigner
Jul 2, 2025
Merged

Preserve entitlements in managed Mach-O signer#116659
jtschuster merged 23 commits into
dotnet:mainfrom
jtschuster:PreserveEntitlementsInMachSigner

Conversation

@jtschuster

@jtschusterjtschuster commented Jun 13, 2025

Copy link
Copy Markdown
Member

Preserves entitlements in the signature when signing with the managed signer. Works on regular apphost and singlefile apphost.

Adds EntitlementsBlob and DerEntitlementsBlob, and updates relevant code to include these blobs.
Adds an EmbeddedSignatureBlob to signing methods to preserve the entitlements from the previous signature.
Precalculates the maximum length required for the new apphost / bundle and allocates an memory-mapped file in memory, copies / modifies the file, then writes out the final length of the file.
Adds tests to ensure the inode of the apphost changes when CreateAppHost / GenerateBundle creates a new apphost/bundle to ensure the MacOS signature cache is dirtied.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @vitek-karas, @agocke
See info in area-owners.md if you want to be subscribed.

@jtschuster
jtschuster marked this pull request as ready for review June 14, 2025 01:15
CopilotAI review requested due to automatic review settings June 14, 2025 01:15

This comment was marked as outdated.

Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/MachO/MachObjectFile.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
- use explicit types for "using" statements
- Make CodeDirectoryHeader fields private and expose properties that convert them from bigendian
- Reenable codesign hash checks in tests
- improve readability
@jtschuster
jtschuster requested a review from CopilotJune 25, 2025 18:38

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR introduces changes to preserve entitlements in the managed Mach‑O signer for macOS app hosts. Key changes include adjustments in the native CMake build file to conditionally include entitlements‐based signing; modifications to tests and signing utilities (e.g. Codesign, MachObjectFile, and related blobs) to support new EntitlementsBlob and DerEntitlementsBlob; and updates to the bundle and manifest code to accommodate the extended signature structure.

Reviewed Changes

Copilot reviewed 25 out of 25 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
src/native/corehost/apphost/static/CMakeLists.txtAdds conditional invocation of adhoc_sign_with_entitlements on macOS.
src/installer/tests/*Updates tests to use theory/member data for signing and rebundling; ensures signature cache clearing.
src/installer/managed/Microsoft.NET.HostModel/MachO/*Introduces EntitlementsBlob and DerEntitlementsBlob support and updates signature creation logic.
src/installer/managed/Microsoft.NET.HostModel/Bundle/*Adjusts bundle manifest and size calculations for new signature information.
src/installer/managed/Microsoft.NET.HostModel/AppHost/*Updates host rewriting and signing routines to integrate Mach‑O signature updates.
Comments suppressed due to low confidence (3)

src/installer/managed/Microsoft.NET.HostModel/MachO/BinaryFormat/Blobs/CodeDirectoryBlob.cs:153

  • The use of arithmetic on enum values (subtracting 1 from CodeDirectorySpecialSlot.DerEntitlements) to determine the array index may be fragile if the enum values are non‐sequential. Consider introducing an explicit mapping from enum values to array indices to improve maintainability.
 specialSlotHashes[(int)CodeDirectorySpecialSlot.DerEntitlements - 1] = hasher.ComputeHash(derStream.GetBuffer());

src/installer/managed/Microsoft.NET.HostModel/MachO/BinaryFormat/Blobs/CodeDirectoryBlob.cs:161

  • Similarly, computing the array index by subtracting 1 from CodeDirectorySpecialSlot.Entitlements assumes a contiguous indexing scheme. A mapping structure would make the assignment clearer and more robust against future enum changes.
 specialSlotHashes[(int)CodeDirectorySpecialSlot.Entitlements - 1] = hasher.ComputeHash(entStream.GetBuffer());

src/installer/managed/Microsoft.NET.HostModel/MachO/BinaryFormat/Blobs/EmbeddedSignatureBlob.cs:43

  • Consider adding an inline comment to clarify the intended blob ordering and how the additional entitlements blobs are factored into the blob count. This will help maintainers understand how changes to the signature structure affect the overall blob layout.
 int blobCount = 3 + (entitlementsBlob is not null ? 1 : 0) + (derEntitlementsBlob is not null ? 1 : 0);

@build-analysisbuild-analysisBot mentioned this pull request Jun 25, 2025
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/tests/TestUtils/SingleFileTestApp.cs Outdated
Comment threadsrc/installer/tests/AppHost.Bundle.Tests/AppLaunch.cs Outdated
Comment threadsrc/installer/tests/HostActivation.Tests/MachOHostSigningTests.cs Outdated
Comment threadsrc/installer/tests/HostActivation.Tests/MachOHostSigningTests.cs Outdated
Comment threadsrc/installer/tests/Microsoft.NET.HostModel.Tests/AppHost/CreateAppHost.cs Outdated

@agockeagocke left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
- Remove ConditionAttribute on test
- Use File.SetUnixFileMode
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Codesigning the apphost on macOS should preserve entitlements Why it won't work on macOS 15.0

5 participants

@jtschuster@agocke@am11@elinor-fung
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Preserve entitlements in managed Mach-O signer by jtschuster · Pull Request #116659 · dotnet/runtime · GitHub
Skip to content

Preserve entitlements in managed Mach-O signer - #116659

Merged
jtschuster merged 23 commits into
dotnet:mainfrom
jtschuster:PreserveEntitlementsInMachSigner
Jul 2, 2025
Merged

Preserve entitlements in managed Mach-O signer#116659
jtschuster merged 23 commits into
dotnet:mainfrom
jtschuster:PreserveEntitlementsInMachSigner

Conversation

@jtschuster

@jtschusterjtschuster commented Jun 13, 2025

Copy link
Copy Markdown
Member

Preserves entitlements in the signature when signing with the managed signer. Works on regular apphost and singlefile apphost.

Adds EntitlementsBlob and DerEntitlementsBlob, and updates relevant code to include these blobs.
Adds an EmbeddedSignatureBlob to signing methods to preserve the entitlements from the previous signature.
Precalculates the maximum length required for the new apphost / bundle and allocates an memory-mapped file in memory, copies / modifies the file, then writes out the final length of the file.
Adds tests to ensure the inode of the apphost changes when CreateAppHost / GenerateBundle creates a new apphost/bundle to ensure the MacOS signature cache is dirtied.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @vitek-karas, @agocke
See info in area-owners.md if you want to be subscribed.

@jtschuster
jtschuster marked this pull request as ready for review June 14, 2025 01:15
CopilotAI review requested due to automatic review settings June 14, 2025 01:15

This comment was marked as outdated.

Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/MachO/MachObjectFile.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
- use explicit types for "using" statements
- Make CodeDirectoryHeader fields private and expose properties that convert them from bigendian
- Reenable codesign hash checks in tests
- improve readability
@jtschuster
jtschuster requested a review from CopilotJune 25, 2025 18:38

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR introduces changes to preserve entitlements in the managed Mach‑O signer for macOS app hosts. Key changes include adjustments in the native CMake build file to conditionally include entitlements‐based signing; modifications to tests and signing utilities (e.g. Codesign, MachObjectFile, and related blobs) to support new EntitlementsBlob and DerEntitlementsBlob; and updates to the bundle and manifest code to accommodate the extended signature structure.

Reviewed Changes

Copilot reviewed 25 out of 25 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
src/native/corehost/apphost/static/CMakeLists.txtAdds conditional invocation of adhoc_sign_with_entitlements on macOS.
src/installer/tests/*Updates tests to use theory/member data for signing and rebundling; ensures signature cache clearing.
src/installer/managed/Microsoft.NET.HostModel/MachO/*Introduces EntitlementsBlob and DerEntitlementsBlob support and updates signature creation logic.
src/installer/managed/Microsoft.NET.HostModel/Bundle/*Adjusts bundle manifest and size calculations for new signature information.
src/installer/managed/Microsoft.NET.HostModel/AppHost/*Updates host rewriting and signing routines to integrate Mach‑O signature updates.
Comments suppressed due to low confidence (3)

src/installer/managed/Microsoft.NET.HostModel/MachO/BinaryFormat/Blobs/CodeDirectoryBlob.cs:153

  • The use of arithmetic on enum values (subtracting 1 from CodeDirectorySpecialSlot.DerEntitlements) to determine the array index may be fragile if the enum values are non‐sequential. Consider introducing an explicit mapping from enum values to array indices to improve maintainability.
 specialSlotHashes[(int)CodeDirectorySpecialSlot.DerEntitlements - 1] = hasher.ComputeHash(derStream.GetBuffer());

src/installer/managed/Microsoft.NET.HostModel/MachO/BinaryFormat/Blobs/CodeDirectoryBlob.cs:161

  • Similarly, computing the array index by subtracting 1 from CodeDirectorySpecialSlot.Entitlements assumes a contiguous indexing scheme. A mapping structure would make the assignment clearer and more robust against future enum changes.
 specialSlotHashes[(int)CodeDirectorySpecialSlot.Entitlements - 1] = hasher.ComputeHash(entStream.GetBuffer());

src/installer/managed/Microsoft.NET.HostModel/MachO/BinaryFormat/Blobs/EmbeddedSignatureBlob.cs:43

  • Consider adding an inline comment to clarify the intended blob ordering and how the additional entitlements blobs are factored into the blob count. This will help maintainers understand how changes to the signature structure affect the overall blob layout.
 int blobCount = 3 + (entitlementsBlob is not null ? 1 : 0) + (derEntitlementsBlob is not null ? 1 : 0);

@build-analysisbuild-analysisBot mentioned this pull request Jun 25, 2025
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/tests/TestUtils/SingleFileTestApp.cs Outdated
Comment threadsrc/installer/tests/AppHost.Bundle.Tests/AppLaunch.cs Outdated
Comment threadsrc/installer/tests/HostActivation.Tests/MachOHostSigningTests.cs Outdated
Comment threadsrc/installer/tests/HostActivation.Tests/MachOHostSigningTests.cs Outdated
Comment threadsrc/installer/tests/Microsoft.NET.HostModel.Tests/AppHost/CreateAppHost.cs Outdated

@agockeagocke left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
- Remove ConditionAttribute on test
- Use File.SetUnixFileMode
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Codesigning the apphost on macOS should preserve entitlements Why it won't work on macOS 15.0

5 participants

@jtschuster@agocke@am11@elinor-fung
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' Preserve entitlements in managed Mach-O signer by jtschuster · Pull Request #116659 · dotnet/runtime · GitHub
Skip to content

Preserve entitlements in managed Mach-O signer - #116659

Merged
jtschuster merged 23 commits into
dotnet:mainfrom
jtschuster:PreserveEntitlementsInMachSigner
Jul 2, 2025
Merged

Preserve entitlements in managed Mach-O signer#116659
jtschuster merged 23 commits into
dotnet:mainfrom
jtschuster:PreserveEntitlementsInMachSigner

Conversation

@jtschuster

@jtschusterjtschuster commented Jun 13, 2025

Copy link
Copy Markdown
Member

Preserves entitlements in the signature when signing with the managed signer. Works on regular apphost and singlefile apphost.

Adds EntitlementsBlob and DerEntitlementsBlob, and updates relevant code to include these blobs.
Adds an EmbeddedSignatureBlob to signing methods to preserve the entitlements from the previous signature.
Precalculates the maximum length required for the new apphost / bundle and allocates an memory-mapped file in memory, copies / modifies the file, then writes out the final length of the file.
Adds tests to ensure the inode of the apphost changes when CreateAppHost / GenerateBundle creates a new apphost/bundle to ensure the MacOS signature cache is dirtied.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @vitek-karas, @agocke
See info in area-owners.md if you want to be subscribed.

@jtschuster
jtschuster marked this pull request as ready for review June 14, 2025 01:15
CopilotAI review requested due to automatic review settings June 14, 2025 01:15

This comment was marked as outdated.

Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/MachO/MachObjectFile.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
- use explicit types for "using" statements
- Make CodeDirectoryHeader fields private and expose properties that convert them from bigendian
- Reenable codesign hash checks in tests
- improve readability
@jtschuster
jtschuster requested a review from CopilotJune 25, 2025 18:38

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR introduces changes to preserve entitlements in the managed Mach‑O signer for macOS app hosts. Key changes include adjustments in the native CMake build file to conditionally include entitlements‐based signing; modifications to tests and signing utilities (e.g. Codesign, MachObjectFile, and related blobs) to support new EntitlementsBlob and DerEntitlementsBlob; and updates to the bundle and manifest code to accommodate the extended signature structure.

Reviewed Changes

Copilot reviewed 25 out of 25 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
src/native/corehost/apphost/static/CMakeLists.txtAdds conditional invocation of adhoc_sign_with_entitlements on macOS.
src/installer/tests/*Updates tests to use theory/member data for signing and rebundling; ensures signature cache clearing.
src/installer/managed/Microsoft.NET.HostModel/MachO/*Introduces EntitlementsBlob and DerEntitlementsBlob support and updates signature creation logic.
src/installer/managed/Microsoft.NET.HostModel/Bundle/*Adjusts bundle manifest and size calculations for new signature information.
src/installer/managed/Microsoft.NET.HostModel/AppHost/*Updates host rewriting and signing routines to integrate Mach‑O signature updates.
Comments suppressed due to low confidence (3)

src/installer/managed/Microsoft.NET.HostModel/MachO/BinaryFormat/Blobs/CodeDirectoryBlob.cs:153

  • The use of arithmetic on enum values (subtracting 1 from CodeDirectorySpecialSlot.DerEntitlements) to determine the array index may be fragile if the enum values are non‐sequential. Consider introducing an explicit mapping from enum values to array indices to improve maintainability.
 specialSlotHashes[(int)CodeDirectorySpecialSlot.DerEntitlements - 1] = hasher.ComputeHash(derStream.GetBuffer());

src/installer/managed/Microsoft.NET.HostModel/MachO/BinaryFormat/Blobs/CodeDirectoryBlob.cs:161

  • Similarly, computing the array index by subtracting 1 from CodeDirectorySpecialSlot.Entitlements assumes a contiguous indexing scheme. A mapping structure would make the assignment clearer and more robust against future enum changes.
 specialSlotHashes[(int)CodeDirectorySpecialSlot.Entitlements - 1] = hasher.ComputeHash(entStream.GetBuffer());

src/installer/managed/Microsoft.NET.HostModel/MachO/BinaryFormat/Blobs/EmbeddedSignatureBlob.cs:43

  • Consider adding an inline comment to clarify the intended blob ordering and how the additional entitlements blobs are factored into the blob count. This will help maintainers understand how changes to the signature structure affect the overall blob layout.
 int blobCount = 3 + (entitlementsBlob is not null ? 1 : 0) + (derEntitlementsBlob is not null ? 1 : 0);

@build-analysisbuild-analysisBot mentioned this pull request Jun 25, 2025
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/tests/TestUtils/SingleFileTestApp.cs Outdated
Comment threadsrc/installer/tests/AppHost.Bundle.Tests/AppLaunch.cs Outdated
Comment threadsrc/installer/tests/HostActivation.Tests/MachOHostSigningTests.cs Outdated
Comment threadsrc/installer/tests/HostActivation.Tests/MachOHostSigningTests.cs Outdated
Comment threadsrc/installer/tests/Microsoft.NET.HostModel.Tests/AppHost/CreateAppHost.cs Outdated

@agockeagocke left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
- Remove ConditionAttribute on test
- Use File.SetUnixFileMode
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Codesigning the apphost on macOS should preserve entitlements Why it won't work on macOS 15.0

5 participants

@jtschuster@agocke@am11@elinor-fung
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Preserve entitlements in managed Mach-O signer by jtschuster · Pull Request #116659 · dotnet/runtime · GitHub
Skip to content

Preserve entitlements in managed Mach-O signer - #116659

Merged
jtschuster merged 23 commits into
dotnet:mainfrom
jtschuster:PreserveEntitlementsInMachSigner
Jul 2, 2025
Merged

Preserve entitlements in managed Mach-O signer#116659
jtschuster merged 23 commits into
dotnet:mainfrom
jtschuster:PreserveEntitlementsInMachSigner

Conversation

@jtschuster

@jtschusterjtschuster commented Jun 13, 2025

Copy link
Copy Markdown
Member

Preserves entitlements in the signature when signing with the managed signer. Works on regular apphost and singlefile apphost.

Adds EntitlementsBlob and DerEntitlementsBlob, and updates relevant code to include these blobs.
Adds an EmbeddedSignatureBlob to signing methods to preserve the entitlements from the previous signature.
Precalculates the maximum length required for the new apphost / bundle and allocates an memory-mapped file in memory, copies / modifies the file, then writes out the final length of the file.
Adds tests to ensure the inode of the apphost changes when CreateAppHost / GenerateBundle creates a new apphost/bundle to ensure the MacOS signature cache is dirtied.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @vitek-karas, @agocke
See info in area-owners.md if you want to be subscribed.

@jtschuster
jtschuster marked this pull request as ready for review June 14, 2025 01:15
CopilotAI review requested due to automatic review settings June 14, 2025 01:15

This comment was marked as outdated.

Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/MachO/MachObjectFile.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
- use explicit types for "using" statements
- Make CodeDirectoryHeader fields private and expose properties that convert them from bigendian
- Reenable codesign hash checks in tests
- improve readability
@jtschuster
jtschuster requested a review from CopilotJune 25, 2025 18:38

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR introduces changes to preserve entitlements in the managed Mach‑O signer for macOS app hosts. Key changes include adjustments in the native CMake build file to conditionally include entitlements‐based signing; modifications to tests and signing utilities (e.g. Codesign, MachObjectFile, and related blobs) to support new EntitlementsBlob and DerEntitlementsBlob; and updates to the bundle and manifest code to accommodate the extended signature structure.

Reviewed Changes

Copilot reviewed 25 out of 25 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
src/native/corehost/apphost/static/CMakeLists.txtAdds conditional invocation of adhoc_sign_with_entitlements on macOS.
src/installer/tests/*Updates tests to use theory/member data for signing and rebundling; ensures signature cache clearing.
src/installer/managed/Microsoft.NET.HostModel/MachO/*Introduces EntitlementsBlob and DerEntitlementsBlob support and updates signature creation logic.
src/installer/managed/Microsoft.NET.HostModel/Bundle/*Adjusts bundle manifest and size calculations for new signature information.
src/installer/managed/Microsoft.NET.HostModel/AppHost/*Updates host rewriting and signing routines to integrate Mach‑O signature updates.
Comments suppressed due to low confidence (3)

src/installer/managed/Microsoft.NET.HostModel/MachO/BinaryFormat/Blobs/CodeDirectoryBlob.cs:153

  • The use of arithmetic on enum values (subtracting 1 from CodeDirectorySpecialSlot.DerEntitlements) to determine the array index may be fragile if the enum values are non‐sequential. Consider introducing an explicit mapping from enum values to array indices to improve maintainability.
 specialSlotHashes[(int)CodeDirectorySpecialSlot.DerEntitlements - 1] = hasher.ComputeHash(derStream.GetBuffer());

src/installer/managed/Microsoft.NET.HostModel/MachO/BinaryFormat/Blobs/CodeDirectoryBlob.cs:161

  • Similarly, computing the array index by subtracting 1 from CodeDirectorySpecialSlot.Entitlements assumes a contiguous indexing scheme. A mapping structure would make the assignment clearer and more robust against future enum changes.
 specialSlotHashes[(int)CodeDirectorySpecialSlot.Entitlements - 1] = hasher.ComputeHash(entStream.GetBuffer());

src/installer/managed/Microsoft.NET.HostModel/MachO/BinaryFormat/Blobs/EmbeddedSignatureBlob.cs:43

  • Consider adding an inline comment to clarify the intended blob ordering and how the additional entitlements blobs are factored into the blob count. This will help maintainers understand how changes to the signature structure affect the overall blob layout.
 int blobCount = 3 + (entitlementsBlob is not null ? 1 : 0) + (derEntitlementsBlob is not null ? 1 : 0);

@build-analysisbuild-analysisBot mentioned this pull request Jun 25, 2025
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/tests/TestUtils/SingleFileTestApp.cs Outdated
Comment threadsrc/installer/tests/AppHost.Bundle.Tests/AppLaunch.cs Outdated
Comment threadsrc/installer/tests/HostActivation.Tests/MachOHostSigningTests.cs Outdated
Comment threadsrc/installer/tests/HostActivation.Tests/MachOHostSigningTests.cs Outdated
Comment threadsrc/installer/tests/Microsoft.NET.HostModel.Tests/AppHost/CreateAppHost.cs Outdated

@agockeagocke left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
- Remove ConditionAttribute on test
- Use File.SetUnixFileMode
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Codesigning the apphost on macOS should preserve entitlements Why it won't work on macOS 15.0

5 participants

@jtschuster@agocke@am11@elinor-fung
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Preserve entitlements in managed Mach-O signer by jtschuster · Pull Request #116659 · dotnet/runtime · GitHub
Skip to content

Preserve entitlements in managed Mach-O signer - #116659

Merged
jtschuster merged 23 commits into
dotnet:mainfrom
jtschuster:PreserveEntitlementsInMachSigner
Jul 2, 2025
Merged

Preserve entitlements in managed Mach-O signer#116659
jtschuster merged 23 commits into
dotnet:mainfrom
jtschuster:PreserveEntitlementsInMachSigner

Conversation

@jtschuster

@jtschusterjtschuster commented Jun 13, 2025

Copy link
Copy Markdown
Member

Preserves entitlements in the signature when signing with the managed signer. Works on regular apphost and singlefile apphost.

Adds EntitlementsBlob and DerEntitlementsBlob, and updates relevant code to include these blobs.
Adds an EmbeddedSignatureBlob to signing methods to preserve the entitlements from the previous signature.
Precalculates the maximum length required for the new apphost / bundle and allocates an memory-mapped file in memory, copies / modifies the file, then writes out the final length of the file.
Adds tests to ensure the inode of the apphost changes when CreateAppHost / GenerateBundle creates a new apphost/bundle to ensure the MacOS signature cache is dirtied.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @vitek-karas, @agocke
See info in area-owners.md if you want to be subscribed.

@jtschuster
jtschuster marked this pull request as ready for review June 14, 2025 01:15
CopilotAI review requested due to automatic review settings June 14, 2025 01:15

This comment was marked as outdated.

Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/MachO/MachObjectFile.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
- use explicit types for "using" statements
- Make CodeDirectoryHeader fields private and expose properties that convert them from bigendian
- Reenable codesign hash checks in tests
- improve readability
@jtschuster
jtschuster requested a review from CopilotJune 25, 2025 18:38

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR introduces changes to preserve entitlements in the managed Mach‑O signer for macOS app hosts. Key changes include adjustments in the native CMake build file to conditionally include entitlements‐based signing; modifications to tests and signing utilities (e.g. Codesign, MachObjectFile, and related blobs) to support new EntitlementsBlob and DerEntitlementsBlob; and updates to the bundle and manifest code to accommodate the extended signature structure.

Reviewed Changes

Copilot reviewed 25 out of 25 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
src/native/corehost/apphost/static/CMakeLists.txtAdds conditional invocation of adhoc_sign_with_entitlements on macOS.
src/installer/tests/*Updates tests to use theory/member data for signing and rebundling; ensures signature cache clearing.
src/installer/managed/Microsoft.NET.HostModel/MachO/*Introduces EntitlementsBlob and DerEntitlementsBlob support and updates signature creation logic.
src/installer/managed/Microsoft.NET.HostModel/Bundle/*Adjusts bundle manifest and size calculations for new signature information.
src/installer/managed/Microsoft.NET.HostModel/AppHost/*Updates host rewriting and signing routines to integrate Mach‑O signature updates.
Comments suppressed due to low confidence (3)

src/installer/managed/Microsoft.NET.HostModel/MachO/BinaryFormat/Blobs/CodeDirectoryBlob.cs:153

  • The use of arithmetic on enum values (subtracting 1 from CodeDirectorySpecialSlot.DerEntitlements) to determine the array index may be fragile if the enum values are non‐sequential. Consider introducing an explicit mapping from enum values to array indices to improve maintainability.
 specialSlotHashes[(int)CodeDirectorySpecialSlot.DerEntitlements - 1] = hasher.ComputeHash(derStream.GetBuffer());

src/installer/managed/Microsoft.NET.HostModel/MachO/BinaryFormat/Blobs/CodeDirectoryBlob.cs:161

  • Similarly, computing the array index by subtracting 1 from CodeDirectorySpecialSlot.Entitlements assumes a contiguous indexing scheme. A mapping structure would make the assignment clearer and more robust against future enum changes.
 specialSlotHashes[(int)CodeDirectorySpecialSlot.Entitlements - 1] = hasher.ComputeHash(entStream.GetBuffer());

src/installer/managed/Microsoft.NET.HostModel/MachO/BinaryFormat/Blobs/EmbeddedSignatureBlob.cs:43

  • Consider adding an inline comment to clarify the intended blob ordering and how the additional entitlements blobs are factored into the blob count. This will help maintainers understand how changes to the signature structure affect the overall blob layout.
 int blobCount = 3 + (entitlementsBlob is not null ? 1 : 0) + (derEntitlementsBlob is not null ? 1 : 0);

@build-analysisbuild-analysisBot mentioned this pull request Jun 25, 2025
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/tests/TestUtils/SingleFileTestApp.cs Outdated
Comment threadsrc/installer/tests/AppHost.Bundle.Tests/AppLaunch.cs Outdated
Comment threadsrc/installer/tests/HostActivation.Tests/MachOHostSigningTests.cs Outdated
Comment threadsrc/installer/tests/HostActivation.Tests/MachOHostSigningTests.cs Outdated
Comment threadsrc/installer/tests/Microsoft.NET.HostModel.Tests/AppHost/CreateAppHost.cs Outdated

@agockeagocke left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
- Remove ConditionAttribute on test
- Use File.SetUnixFileMode
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Codesigning the apphost on macOS should preserve entitlements Why it won't work on macOS 15.0

5 participants

@jtschuster@agocke@am11@elinor-fung
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); Preserve entitlements in managed Mach-O signer by jtschuster · Pull Request #116659 · dotnet/runtime · GitHub
Skip to content

Preserve entitlements in managed Mach-O signer - #116659

Merged
jtschuster merged 23 commits into
dotnet:mainfrom
jtschuster:PreserveEntitlementsInMachSigner
Jul 2, 2025
Merged

Preserve entitlements in managed Mach-O signer#116659
jtschuster merged 23 commits into
dotnet:mainfrom
jtschuster:PreserveEntitlementsInMachSigner

Conversation

@jtschuster

@jtschusterjtschuster commented Jun 13, 2025

Copy link
Copy Markdown
Member

Preserves entitlements in the signature when signing with the managed signer. Works on regular apphost and singlefile apphost.

Adds EntitlementsBlob and DerEntitlementsBlob, and updates relevant code to include these blobs.
Adds an EmbeddedSignatureBlob to signing methods to preserve the entitlements from the previous signature.
Precalculates the maximum length required for the new apphost / bundle and allocates an memory-mapped file in memory, copies / modifies the file, then writes out the final length of the file.
Adds tests to ensure the inode of the apphost changes when CreateAppHost / GenerateBundle creates a new apphost/bundle to ensure the MacOS signature cache is dirtied.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @vitek-karas, @agocke
See info in area-owners.md if you want to be subscribed.

@jtschuster
jtschuster marked this pull request as ready for review June 14, 2025 01:15
CopilotAI review requested due to automatic review settings June 14, 2025 01:15

This comment was marked as outdated.

Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/MachO/MachObjectFile.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
- use explicit types for "using" statements
- Make CodeDirectoryHeader fields private and expose properties that convert them from bigendian
- Reenable codesign hash checks in tests
- improve readability
@jtschuster
jtschuster requested a review from CopilotJune 25, 2025 18:38

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR introduces changes to preserve entitlements in the managed Mach‑O signer for macOS app hosts. Key changes include adjustments in the native CMake build file to conditionally include entitlements‐based signing; modifications to tests and signing utilities (e.g. Codesign, MachObjectFile, and related blobs) to support new EntitlementsBlob and DerEntitlementsBlob; and updates to the bundle and manifest code to accommodate the extended signature structure.

Reviewed Changes

Copilot reviewed 25 out of 25 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
src/native/corehost/apphost/static/CMakeLists.txtAdds conditional invocation of adhoc_sign_with_entitlements on macOS.
src/installer/tests/*Updates tests to use theory/member data for signing and rebundling; ensures signature cache clearing.
src/installer/managed/Microsoft.NET.HostModel/MachO/*Introduces EntitlementsBlob and DerEntitlementsBlob support and updates signature creation logic.
src/installer/managed/Microsoft.NET.HostModel/Bundle/*Adjusts bundle manifest and size calculations for new signature information.
src/installer/managed/Microsoft.NET.HostModel/AppHost/*Updates host rewriting and signing routines to integrate Mach‑O signature updates.
Comments suppressed due to low confidence (3)

src/installer/managed/Microsoft.NET.HostModel/MachO/BinaryFormat/Blobs/CodeDirectoryBlob.cs:153

  • The use of arithmetic on enum values (subtracting 1 from CodeDirectorySpecialSlot.DerEntitlements) to determine the array index may be fragile if the enum values are non‐sequential. Consider introducing an explicit mapping from enum values to array indices to improve maintainability.
 specialSlotHashes[(int)CodeDirectorySpecialSlot.DerEntitlements - 1] = hasher.ComputeHash(derStream.GetBuffer());

src/installer/managed/Microsoft.NET.HostModel/MachO/BinaryFormat/Blobs/CodeDirectoryBlob.cs:161

  • Similarly, computing the array index by subtracting 1 from CodeDirectorySpecialSlot.Entitlements assumes a contiguous indexing scheme. A mapping structure would make the assignment clearer and more robust against future enum changes.
 specialSlotHashes[(int)CodeDirectorySpecialSlot.Entitlements - 1] = hasher.ComputeHash(entStream.GetBuffer());

src/installer/managed/Microsoft.NET.HostModel/MachO/BinaryFormat/Blobs/EmbeddedSignatureBlob.cs:43

  • Consider adding an inline comment to clarify the intended blob ordering and how the additional entitlements blobs are factored into the blob count. This will help maintainers understand how changes to the signature structure affect the overall blob layout.
 int blobCount = 3 + (entitlementsBlob is not null ? 1 : 0) + (derEntitlementsBlob is not null ? 1 : 0);

@build-analysisbuild-analysisBot mentioned this pull request Jun 25, 2025
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/managed/Microsoft.NET.HostModel/Bundle/Bundler.cs Outdated
Comment threadsrc/installer/tests/TestUtils/SingleFileTestApp.cs Outdated
Comment threadsrc/installer/tests/AppHost.Bundle.Tests/AppLaunch.cs Outdated
Comment threadsrc/installer/tests/HostActivation.Tests/MachOHostSigningTests.cs Outdated
Comment threadsrc/installer/tests/HostActivation.Tests/MachOHostSigningTests.cs Outdated
Comment threadsrc/installer/tests/Microsoft.NET.HostModel.Tests/AppHost/CreateAppHost.cs Outdated

@agockeagocke left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Comment threadsrc/installer/managed/Microsoft.NET.HostModel/AppHost/HostWriter.cs Outdated
- Remove ConditionAttribute on test
- Use File.SetUnixFileMode
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Codesigning the apphost on macOS should preserve entitlements Why it won't work on macOS 15.0

5 participants

@jtschuster@agocke@am11@elinor-fung