Commit Graph
179 Commits
Author SHA1 Message Date
Zorg fc4f8cb753 Harden policy on what operations clients are allowed to take
* For the Installer and Downloader XPC Services, if these executables are code signed with an Apple issued Team ID, then the connecting client must also be code signed with a matching Team ID.
* For the Downloader XPC Service, the request URL must be http/https
* For Autoupdate, if stage 1 of installation hasn't been completed yet and this executable is code signed with an Apple issued Team ID, then the connecting client must also be code signed with a matching Team ID. As before, multiple simultaneous connections are still disallowed.
* For Autoupdate, if it's not signed with Apple issued certificate, when installing package updates the bundle being updated must be itself and owned by root on disk (as one expects from a PKG installation)
* The authorization prompt message in the Installer Service is more computed inside the service so the client can't pass a completely arbitrary message
* Add extra nullable checking of parameters coming from XPC endpoints
* Add more thread-safe synchronization for Autoupdate installer
* Add logs for more failure points
2025-09-07 18:06:30 -07:00
Zorg 20e9384fad Fix reserved identifier warnings for static functions in Xcode 26 (#2729) 2025-06-15 20:10:56 -07:00
Zorg aed66df8c7 Fix Sparkle not building when SPARKLE_COPY_LOCALIZATIONS=0 (#2707) 2025-06-15 20:09:51 -07:00
Zorg a6c215cf2a Fix compiler warnings for Xcode 16.3 (#2709)
Also silence project upgrade warnings.
2025-06-15 20:09:33 -07:00
Zorg 62a1908333 Remove SPARKLE_BUILD_DMG_SUPPORT option (#2690) 2025-01-20 20:53:35 -08:00
Zorg 1ca60d5ab6 Add option to verify updates before extraction (#2667)
Adds an opt-in option (SUVerifyUpdateBeforeExtraction) to enforce verifying updates before extracting them for stronger security. EdDSA signing is required to use this option. As fallback in case EdDSA keys are lost, disk image archives's code signatures are validated assuming it's Developer ID signed. Key rotation is still possible.

Apple Archives (aar, yaa) now require using this option.
2024-12-08 16:31:26 -08:00
Zorg 597825d111 Make binary delta version 4 the default (#2668) 2024-12-07 14:46:23 -08:00
Zorg 14ba9efc51 Use crc32 hashes for binary delta version 4 (#2638)
This is more efficient than SHA1.
2024-10-13 16:58:54 -07:00
Zorg 6848a88abc Preserve bundle creation date when creating and applying delta updates (#2583)
This will preserve the file creation date of the new app bundle, but not the file creation date of any of the files inside the new app bundle because tracking those changes is complex/undesirable.

This bumps the major binary delta version to 4. A new test has been added for testing that the new bundle creation date is also preserved.
2024-09-29 18:25:38 -07:00
Zorg 8de8db001e Fix shared classes being defined both in unit tests and Sparkle (#2629)
For the unit tests, we will rename the classes so they don't conflict.
2024-09-16 17:03:59 -07:00
Zorg 661540d088 Improve robustness around dmg passwords (#2627)
* Handle failing to extract password protected disk images even when a decryption password isn't provided.
* Propagate error with more information when hdiutil attach fails.
* Wait for detaching disk images for unit tests (fixes not being able to run tests repeatably).
2024-09-15 06:58:00 -07:00
Zorg 8f86cad4a2 Retry extracting zip file without piping if extraction fails (#2616)
This is to workaround a bug in ditto prior to macOS 15.
2024-09-02 17:21:50 -07:00
Zorg a4badefff2 Skip safe atomic swap if update has custom update security policy (#2593)
Also emit a warning when checking if the updater is configured correctly.
2024-06-29 15:15:30 -07:00
Zorg 1b6565ded5 Require signing validation for apple archives before extraction (#2588) 2024-06-19 23:14:04 -07:00
Zorg dd9374356b Add support for extracting Apple Archives (.aar files) (#2586)
Check `man aa` and https://developer.apple.com/documentation/applearchive for more details. This is an efficient Apple custom archive format available since versions of macOS 10.15.

In macOS 10.15, this utility used to be called yaa.
2024-06-18 20:18:11 -07:00
Zorg 007e9aee61 Randomize the download archive name the installer extracts/executes (#2584) 2024-06-15 18:13:36 -07:00
Zorg c648665724 Remove SUFileManager from BinaryDelta and Sparkle Test App (#2570) 2024-05-27 13:31:39 -07:00
Zorg 27cf3b3650 Skip extracting auxiliary files and improve extraction progress for disk images (#2569) 2024-05-27 13:30:55 -07:00
Zorg 444a537365 Remove old checksum verification checks for dmg archives (#2568)
These are antiquated checks and they can take considerable time to perform. HTTPS or EdDSA verification will validate that an archive isn't corrupt.
2024-05-25 15:32:14 -07:00
Zorg f904466d35 Remove extra writeData: call when unarchiving disk images (#2562) 2024-05-19 20:51:35 -07:00
Zorg 31b462f860 Extract archives in a separate directory from the input archive (#2550) 2024-04-30 21:24:43 +02:00
Viktor Szépe e9989a8ae7 Fix typos (#2537) 2024-04-13 16:12:23 -07:00
Zorg 51ce7108c9 Swap app bundles with APFS atomic swap if team IDs match (#2516) 2024-03-02 17:32:54 -08:00
Zorg 66c198932d Perform Gatekeeper scan to pre-warm app launch (#2505)
This avoids users being a "Verifying..." Dialog when the installed update is (re-)launched.

This scan is only done for macOS 14.4+ onwards (gktool was introduced in macOS 14.0 but had issues).

Also this scan is only done if Autoupdate's team identifier matches the new update's team identifier. Otherwise the OS may think Autoupdate is modifying a bundle which it shouldn't be permitted to (this is a bug).
2024-02-18 12:37:58 -08:00
Zorg b84c1b14ce Don't clean up update directory when Autoupdate receives SIGTERM (#2479)
Under rare circumstances, if Autoupdate receives SIGTERM while the installer queue is installing an update this could cause potential corruption.
2023-12-19 19:49:36 -08:00
Zorg 1e419c8c16 Improve signing error message to developers (#2471)
If we detect the wrong archive is being served (i.e, expected content length differs from archive length) we log this out to developers. If the app version in the archive (if available) also differs, we report this discrepancy as well. If the update archive looks the same but signing validation fails, we tell the developer the update may have not been signed correctly.

I'm not changing the generic error that is reported to users about the update being improperly signed (that would involve propagating this information there and updating bunch of localizations). The extra info is more for the developer than it is for the user.

Fixes #2468
2023-11-18 16:04:44 -08:00
Zorg bd90fb7b18 Filter for archive files in generate_appcast more intelligently (#2448) 2023-10-08 09:38:50 -07:00
Zorg 8125490931 Pre-warm installs before relaunch (#2421)
Move a lot of the installation work to be done during the first phase of installation (when possible), before the target app needs to be terminated. For the common case where the old and new bundles are on the same volume, the final phase of installation requiring a restart is now just an atomic swap.

Also move the termination listener to the agent app which resolves some launch/CI failures we've been seeing.
2023-08-27 22:22:52 -07:00
Zorg 821b0ff37f Improve error for xattr code signing for delta updates (#2408) 2023-07-23 16:47:49 -07:00
Eitot c23d74d8e0 Replace CFUUID* with NSUUID (#2395)
This resolves a nullability warning by the static analyzer.
2023-06-23 22:23:37 -07:00
Zorg 8039288f64 Harden verification of Sparkle update download (#2392) 2023-06-17 17:01:45 -07:00
Zorg 270582b2e7 Pass bookmark data for the downloaded update (#2359)
Also let Xcode 14.3 update the nibs.
2023-04-12 22:23:50 -07:00
Zorg 39495fd562 Remove redundant codesign check (#2341) 2023-03-12 19:44:50 -07:00
Zorg 60568b82ba Don't allow DSA-only updates to pass if DSA is disabled (#2340) 2023-03-12 07:59:03 -07:00
Zorg 9ab2c0d58c Hide impractical compression options only useful for debugging (#2335) 2023-03-04 18:03:45 -08:00
Zorg 06edf5695d Remove unnecessary min macro checks (#2318)
Minimum OS preprocessor checks should only be used when compiler may generate compile warnings for deprecated APIs when the deployment target is raised.
2023-02-11 22:24:56 -08:00
Zorg be7f6952c2 Reduce code size and make codebase more consistent (#2305) 2022-12-27 12:03:03 -08:00
Zorg 1c560652e7 Remove ed25519 git submodule (#2244)
Also allow release scripts to work without git repository and bump the Sparkle versions.
2022-08-27 10:46:29 -07:00
Zorg f5d4ad52ca Allow user to re-try installing/relaunching application (#2234)
If the app termination request is delayed or canceled, the user can check for updates again with the standard user driver and try installing/relaunching again, which will trigger the installer to send another quit event to the running application.

Before the install/relaunch window would close but the check for updates option would still be present but not functional.
2022-08-21 08:54:03 -07:00
Zorg 47f335614a Wait for a threshold amount of time before replying with status info data (#2230)
This also reverts 6a69f26dcc and 4cb6719c6b
2022-08-19 10:40:25 -07:00
Zorg 6a69f26dcc Clean up handling appcast item registration message (#2223) 2022-08-07 17:08:33 -07:00
Zorg 4cb6719c6b Critical update alerts may not show up as promptly as they should when automatically installing them (#2221)
Wait for appcast item registration before finishing automatic update driver.

This fixes a potential race issue where sometimes the automatic update driver on completion would sometimes not trigger to prompt an update alert immediately for critical updates. Note in this case, the update would still be installed on app termination and would still be scheduled to alert the user on the regular update check interval, so this issue is not severe.
2022-08-06 11:28:47 -07:00
Zorg 983d19580b Fix handle applying patches when files aren't writeable (#2216) 2022-07-23 10:37:29 -07:00
Zorg 372f0504a5 Bump minimum deployment target to macOS 10.13 (#2196) 2022-07-17 16:43:24 -07:00
Zorg 14e511f901 Fix memory leaks when using generate_appcast (#2193)
We fix one memory leak when calculating sha's, one memory leak in the xar delta applying path, and avoid creating Bundles for reading the Sparkle framework version.

There are some other small leaks with the xar delta creation/applying code but since it's a legacy implementation and the APIs are undocumented I don't want to touch it too much.

The biggest culprit here is the leak when calculating sha's I believe, if you have many archive items.
2022-07-09 12:22:36 -07:00
Zorg d544d456e0 Synchronize usage of XPC connections to main queue (#2178) 2022-06-25 21:29:44 -07:00
Zorg b1f6c161d1 Use snprintf instead of sprintf to fix compile warning (#2179) 2022-06-25 16:41:32 -07:00
Zorg 2ddef5179e Bump initial installer message timeouts and declare daemon/agents as Interactive (#2162) 2022-06-18 11:40:45 -07:00
Zorg 15e8270291 Silence deprecation warnings when bumping deployment target (#2152) 2022-06-11 13:09:23 -07:00
Zorg d7942768b8 Validate permission bits of Sparkle executable for delta updates (#2151) 2022-06-11 11:21:52 -07:00