Commit Graph
288 Commits
Author SHA1 Message Date
Zorg fc4f8cb753 Harden policy on what operations clients are allowed to take
* For the Installer and Downloader XPC Services, if these executables are code signed with an Apple issued Team ID, then the connecting client must also be code signed with a matching Team ID.
* For the Downloader XPC Service, the request URL must be http/https
* For Autoupdate, if stage 1 of installation hasn't been completed yet and this executable is code signed with an Apple issued Team ID, then the connecting client must also be code signed with a matching Team ID. As before, multiple simultaneous connections are still disallowed.
* For Autoupdate, if it's not signed with Apple issued certificate, when installing package updates the bundle being updated must be itself and owned by root on disk (as one expects from a PKG installation)
* The authorization prompt message in the Installer Service is more computed inside the service so the client can't pass a completely arbitrary message
* Add extra nullable checking of parameters coming from XPC endpoints
* Add more thread-safe synchronization for Autoupdate installer
* Add logs for more failure points
2025-09-07 18:06:30 -07:00
Zorg 62a1908333 Remove SPARKLE_BUILD_DMG_SUPPORT option (#2690) 2025-01-20 20:53:35 -08:00
Zorg 1ca60d5ab6 Add option to verify updates before extraction (#2667)
Adds an opt-in option (SUVerifyUpdateBeforeExtraction) to enforce verifying updates before extracting them for stronger security. EdDSA signing is required to use this option. As fallback in case EdDSA keys are lost, disk image archives's code signatures are validated assuming it's Developer ID signed. Key rotation is still possible.

Apple Archives (aar, yaa) now require using this option.
2024-12-08 16:31:26 -08:00
Zorg d04faabe7d Don't allow removal of signing keys more strictly (#2647)
* Don't allow removal of (Ed)DSA keys for pre-validated updates (delta updates, .aar updates)
* Don't allow removal of code signing identity in new update (at minimum, an adhoc signature can be used)
2024-10-20 18:14:05 -07:00
Zorg 14ba9efc51 Use crc32 hashes for binary delta version 4 (#2638)
This is more efficient than SHA1.
2024-10-13 16:58:54 -07:00
Zorg 6848a88abc Preserve bundle creation date when creating and applying delta updates (#2583)
This will preserve the file creation date of the new app bundle, but not the file creation date of any of the files inside the new app bundle because tracking those changes is complex/undesirable.

This bumps the major binary delta version to 4. A new test has been added for testing that the new bundle creation date is also preserved.
2024-09-29 18:25:38 -07:00
Zorg 661540d088 Improve robustness around dmg passwords (#2627)
* Handle failing to extract password protected disk images even when a decryption password isn't provided.
* Propagate error with more information when hdiutil attach fails.
* Wait for detaching disk images for unit tests (fixes not being able to run tests repeatably).
2024-09-15 06:58:00 -07:00
Zorg 8f86cad4a2 Retry extracting zip file without piping if extraction fails (#2616)
This is to workaround a bug in ditto prior to macOS 15.
2024-09-02 17:21:50 -07:00
Zorg dd9374356b Add support for extracting Apple Archives (.aar files) (#2586)
Check `man aa` and https://developer.apple.com/documentation/applearchive for more details. This is an efficient Apple custom archive format available since versions of macOS 10.15.

In macOS 10.15, this utility used to be called yaa.
2024-06-18 20:18:11 -07:00
Zorg 6e2366255b Add unarchiving test for regular encrypted disk image (#2571) 2024-05-27 14:10:28 -07:00
Zorg 27cf3b3650 Skip extracting auxiliary files and improve extraction progress for disk images (#2569) 2024-05-27 13:30:55 -07:00
Zorg 31b462f860 Extract archives in a separate directory from the input archive (#2550) 2024-04-30 21:24:43 +02:00
Viktor Szépe e9989a8ae7 Fix typos (#2537) 2024-04-13 16:12:23 -07:00
Zorg 1e419c8c16 Improve signing error message to developers (#2471)
If we detect the wrong archive is being served (i.e, expected content length differs from archive length) we log this out to developers. If the app version in the archive (if available) also differs, we report this discrepancy as well. If the update archive looks the same but signing validation fails, we tell the developer the update may have not been signed correctly.

I'm not changing the generic error that is reported to users about the update being improperly signed (that would involve propagating this information there and updating bunch of localizations). The extra info is more for the developer than it is for the user.

Fixes #2468
2023-11-18 16:04:44 -08:00
Zorg 469f423e28 Fix test cases for localized release notes (#2444) 2023-09-28 22:52:32 -07:00
Zorg f6a86f52b3 Default to English for XML nodes when no xml:lang is present (#2440)
This only applies when multiple XML nodes are present with the same name. E.g. multiple description or releaseNoteLink elements with different xml:lang's specified.

Also generate a warning if an language has to be interpreted implicitly when there is no xml:lang explicitly specified and there are multiple node items.
2023-09-28 20:02:29 -07:00
Zorg 39495fd562 Remove redundant codesign check (#2341) 2023-03-12 19:44:50 -07:00
Zorg 60568b82ba Don't allow DSA-only updates to pass if DSA is disabled (#2340) 2023-03-12 07:59:03 -07:00
Zorg ffc203b89a Add support for plain text release notes view (#2315)
This also allows embedded release notes to be plain text using sparkle:format="plain-text" attribute.

Also, Catalyst apps only support plain text release notes (compared to before where release notes weren't supported for Catalyst apps).
2023-02-11 19:34:26 -08:00
Zorg 348c3a9658 Don't construct appcast item if enclosure URL is invalid (#2317) 2023-02-07 20:12:07 -08:00
Zorg be7f6952c2 Reduce code size and make codebase more consistent (#2305) 2022-12-27 12:03:03 -08:00
Zorg 983d19580b Fix handle applying patches when files aren't writeable (#2216) 2022-07-23 10:37:29 -07:00
Zorg 372f0504a5 Bump minimum deployment target to macOS 10.13 (#2196) 2022-07-17 16:43:24 -07:00
Zorg d7942768b8 Validate permission bits of Sparkle executable for delta updates (#2151) 2022-06-11 11:21:52 -07:00
Zorg 9042c8dbd9 Fall back to regular update if delta update fails to download (#2118)
Also log out the download failure when a delta update fails to download (such as a 404 error for example).

Additionally, add a check to make sure that top-level appcast items cannot be delta update items.
2022-05-01 22:58:29 -07:00
Zorg 94719edeb3 Ignore custom icons set via resource forks in delta updates (#2114)
For creation, we will disallow creating delta updates if a custom resource fork icon data is found in either the old or app bundles.

For applying, we will just ignore the icon data when performing hash verification and continue applying the patch.
2022-04-24 00:38:42 -07:00
Zorg 94b48c45e7 Preserve file system compression when applying delta updates (#2084) 2022-01-30 23:37:42 -08:00
Zorg 8ea4d705f5 Add option to ignore skipped upgrades (#2081)
Normally when a major upgrade is skipped, subsequent updates for that major release are skipped. This element however allows publishing updates that ignore the user skipping the major version before a specific sub-release.
2022-01-29 23:02:45 -08:00
Zorg ac2ef612bc Don't let skipping a major version to skip subsequent major versions (#2079) 2022-01-29 10:37:09 -08:00
Zorg 930ea303fd Add sparkle:belowVersion element for informational updates (#2080)
This allows marking all updates below a specific version as informational only.

A new element (sparkle:belowVersion) was introduced this over a new attribute for sparkle:version due to compatibility reasons.
2022-01-29 10:35:24 -08:00
Zorg 05abb2f7e4 Fix version compare not treating '2.1.0' and '2.1' as being equal (#2065) 2022-01-18 00:07:56 -08:00
Zorg 1641371e83 Warn and validate against irregular permissions for delta patches (#2061)
* Only track 0755 permissions for symbolic links

Also warn the user when encountering symbolic links that have a non-standard permission mode.

* Warn users when bad or irregular permissions are encountered
2022-01-15 23:00:59 -08:00
Zorg f6396aecfb Add heuristics for binary delta when files move to other directories (#2053)
We have one heuristic for when a .framework version changes, and another for when a file with the same name moves to another location.

To support this, we added a clone + binary diff command.

Also document and improve the format.
2022-01-08 11:48:27 -08:00
Zorg 71fc8d7b11 Add additional options to delta tools (#2052) 2022-01-04 00:14:45 -08:00
Zorg 23fc577184 Add new version 3 binary delta archive format (#2051)
This new format introduces:

* A new container format which stores metadata in a way that is more efficient for compression, decompression, and size. Creation time can be 2x faster, apply time can be a few seconds faster, size savings can be 500 KB - couple of MB due to metadata alone.
* An array of supported compression formats including lzma, bzip2, zlib and more. We now default to lzma which is as competitive as bzip2 (which we were using in version 2 format) in applying/creation times, but can save several MB on size.
* Tracking of files from an old app being replicated in different locations in the new app. This can track unchanged files being renamed and can result in significant savings if the files are large.

Version 2 format is still the default. To use version 3, pass --version=3 to BinaryDelta when creating a patch. We will switch the default to version 3 later. generate_appcast support is upcoming.
2022-01-02 11:35:51 -08:00
Zorg fc44085602 Isolate xar usage in its own archive type for delta patches (#2047)
Also remove support for creating and applying version 1 delta files. Version 2 delta files have been supported by Sparkle 1.10 and later.
2021-12-29 22:41:08 -08:00
Zorg 1ef42e9d1c Add apfs dmg unarchiving test (#2028) 2021-11-25 15:53:19 -05:00
Zorg c500487077 Improve pipe usage when unarchiving files (#2027) 2021-11-24 19:21:53 -05:00
Zorg acc4674c3e Fix volume detection being wrong in rare cases (#2026) 2021-11-24 11:33:04 -05:00
Zorg 39cedd4092 Fix unarchiving job being blocked when passed bad input (#2023) 2021-11-24 11:16:31 -05:00
Zorg 45956ae5b0 Support relative links for fullReleaseNotesLink and enforce http(s) (#2003) 2021-11-06 01:56:50 -07:00
Zorg a81f8f3d2d Add safer handling for applying binary delta files (#1988) 2021-10-29 12:14:23 -07:00
Mayur Pawashe c6f1cd4e3c Improve API header docs (#1918)
* Don't expose SPUDownloadData initializer publicly

* Make SUAppcast -init unavailable

* Fix documented default user agent string

* Improve header documentation for SUAppcast(Item) and comparators

* Update more API documentation headers

Also allow returning nil in -allowedSystemProfileKeysForUpdater:

* Clarify documentation on -allowedSystemProfileKeysForUpdater:

* Rename willIdleScheduling -> notSchedule for delegate method

* Make minor correctness fix for reading info URL
2021-08-21 11:24:23 -07:00
Zorg 89ab067477 Populate NSError when signature validation or code sign fails 2021-07-26 15:58:20 +01:00
Mayur PawasheandKornel cb9386a4ea Ignore symlink permissions in binary deltas (#1905)
Co-authored-by: Kornel <kornel@geekhood.net>
2021-07-23 17:42:13 -07:00
Mayur Pawashe d9d7e310a5 Pull current date out of appcast filtering and add tests for phased group rollouts (#1889) 2021-07-11 16:47:05 -07:00
Mayur Pawashe 5677ca3f5a Avoid DSA verification if EdDSA verification passes (#1888)
If EdDSA verification passes we don't need to have DSA verification pass, and don't need to require the new update to contain a DSA signature or keys.

Also reject updates if app has EdDSA but no EdDSA signature is provided
2021-07-11 08:59:09 -07:00
Mayur Pawashe e5c63b6369 Set $USER and $HOME variables when running guided pkg installers (#1884)
Set $USER and $HOME variables when running guided pkg installers

This allows pre/post install scripts to reference the user's environment correctly. The standard pkg installer GUI preserves these two variables.
2021-07-07 08:31:33 -07:00
Zorg c329319b0c Merge branch '2.x' into channels 2021-06-27 15:49:00 -07:00
Zorg c968334192 Allow only one channel in appcast feed items 2021-06-27 15:14:37 -07:00